Senior Compliance Analyst
Canada Pharma Campus
Roche
As a pioneer in healthcare, we have been committed to improving lives since the company was founded in 1896 in Basel, Switzerland. Today, Roche creates innovative medicines and diagnostic tests that help millions of patients globally.Roche fosters diversity, equity and inclusion, representing the communities we serve. When dealing with healthcare on a global scale, diversity is an essential ingredient to success. We believe that inclusion is key to understanding people’s varied healthcare needs. Together, we embrace individuality and share a passion for exceptional care. Join Roche, where every voice matters.
The Position
A healthier future. That’s what drives us.
This position will be located in Mississauga (Canada), Madrid or Sant Cugat del Vallès (Spain).
Data security and privacy are key success factors in our digital transformation and essential to reach our ambitions.
You are inspired to contribute to the overall Roche vision by applying end-to-end product security and privacy operations to keep our products and services secure and privacy compliant throughout the entire lifecycle. You believe in the potential of science, technology, data and insights to improve the standard of care for humankind and you are eager to help navigate through unchartered territory to lift this potential.
The opportunity
As a member of the Compliance Product Team, you are given this opportunity in a team with a strong focus on collaboration and teamwork to support the Digital Products domain with state of the art and innovative security and privacy concepts.
You will oversee or consult on technical architecture implementation activities, particularly for new and/or shared solutions. You coordinate compliance activities at a global/regional level.
You help others (like engineers, cross functional team members) interpret laws and regulations (like GDPR, HIPAA, HITRUST and other regulations) correctly and ensure consistent adherence.
In addition, you will:
Help with audit related work internally and externally - check controls compliance, collect evidence and coordinate audit work (like ISO 27001, 27017 and 27018)
Coordinate routine activities like Pen Testing, Disaster Recovery and tasks stemming from them, recording of results in tools like Jira, tracking any findings and remediation work,
Define and implement security and privacy risk management governance and insights,
Assist in drafting new or updated compliance policies and procedures, including specifying actual or potential implications to existing business operations and practices,
Help prepare and deliver communication and training materials/sessions to educate others on the evolving compliance landscape and potential new or updated policies and related changes,
Leverage your working knowledge of controls for cloud security, mobile application security, data privacy laws, AWS architecture and services,
Put in practice your project management skills and ability to manage multiple projects simultaneously to meet objectives and key deadlines
Conduct Risk assessments by analyzing the current risks and identifying potential risks that are affecting the business and product groups
Who you are
5+ years related work experience in Information Security, Privacy & Risk Management with a min Bachelors in a related field.
Conducting or being the subject of security and/or privacy audits
Working with cloud environments required
Expert planner with business process definition experience and a strong IT aptitude
System hardening, analysis and vulnerability management
Understanding of applicable and accepted audit and risk frameworks (such as COBIT, NIST, and ISO), standards (ISO 27000 family, HITRUST) and government guidelines and laws (HIPAA, GDPR)
Clinical workflow solutions or in a clinical environment a plus
Knowledge of AWS and Cloud Security preferred
Relevant certifications like CISA, CISM, CRISC, CISSP preferred
Healthcare software experience is strongly preferred
Relocation benefits are not available for this position.
Who we are
At Roche, more than 100,000 people across 100 countries are pushing back the frontiers of healthcare. Working together, we’ve become one of the world’s leading research-focused healthcare groups. Our success is built on innovation, curiosity and diversity.
Roche Pharma Canada has its office in Mississauga, Ontario and employs over 850 employees. The Mississauga facility is bright, vibrant, fosters collaboration and teamwork, and is reflective of Roche's truly innovative culture.
As of January 4, 2022, Roche requires all new employees who work in Canada to be fully vaccinated against COVID-19 on the date they take office. This requirement is a condition of employment at Roche that applies regardless of whether the position is on a Roche campus or remotely. If you have a valid reason for not being fully immunized, which is limited to certain specific medical reasons or other valid reasons protected by applicable human rights laws, you may request an exemption and / or adaptation measures regarding this vaccination requirement.
Roche is an Equal Opportunity Employer.
* Salary range is an estimate based on our InfoSec / Cybersecurity Salary Index 💰
Tags: Application security Audits AWS CISA CISM CISSP Cloud COBIT Compliance CRISC GDPR Governance HIPAA HITRUST ISO 27000 ISO 27001 Jira NIST Pentesting Privacy Product security Risk assessment Risk management Vulnerability management
Perks/benefits: Relocation support
More jobs like this
Explore more career opportunities
Find even more open roles below ordered by popularity of job title or skills/products/technologies used.