Senior Compliance Analyst

Canada Pharma Campus

Roche

As a pioneer in healthcare, we have been committed to improving lives since the company was founded in 1896 in Basel, Switzerland. Today, Roche creates innovative medicines and diagnostic tests that help millions of patients globally.

View all jobs at Roche

Apply now Apply later

Roche fosters diversity, equity and inclusion, representing the communities we serve. When dealing with healthcare on a global scale, diversity is an essential ingredient to success. We believe that inclusion is key to understanding people’s varied healthcare needs. Together, we embrace individuality and share a passion for exceptional care. Join Roche, where every voice matters.

The Position

A healthier future. That’s what drives us. 

This position will be located in Mississauga (Canada), Madrid or Sant Cugat del Vallès (Spain).

Data security and privacy are key success factors in our digital transformation and essential to reach our ambitions. 

You are inspired to contribute to the overall Roche vision by applying end-to-end product security and privacy operations to keep our products and services secure and privacy compliant throughout the entire lifecycle. You believe in the potential of science, technology, data and insights to improve the standard of care for humankind and you are eager to help navigate through unchartered territory to lift this potential.

The opportunity

As a member of the Compliance Product Team, you are given this opportunity in a team with a strong focus on collaboration and teamwork to support the Digital Products domain with state of the art and innovative security and privacy concepts.

You will oversee or consult on technical architecture implementation activities, particularly for new and/or shared solutions. You coordinate compliance activities at a global/regional level.

You help others (like engineers, cross functional team members) interpret laws and regulations (like GDPR, HIPAA, HITRUST and other regulations) correctly and ensure consistent adherence.

In addition, you will:

  • Help with audit related work internally and externally - check controls compliance, collect evidence and coordinate audit work (like ISO 27001, 27017 and 27018)

  • Coordinate routine activities like Pen Testing, Disaster Recovery and tasks stemming from them, recording of results in tools like Jira, tracking any findings and remediation work,

  • Define and implement security and privacy risk management governance and insights,

  • Assist in drafting new or updated compliance policies and procedures, including specifying actual or potential implications to existing business operations and practices,

  • Help prepare and deliver communication and training materials/sessions to educate others on the evolving compliance landscape and potential new or updated policies and related changes,

  • Leverage your working knowledge of controls for cloud security, mobile application security, data privacy laws, AWS architecture and services,

  • Put in practice your project management skills and ability to manage multiple projects simultaneously to meet objectives and key deadlines

  • Conduct Risk assessments by analyzing the current risks and identifying potential risks that are affecting the business and product groups

Who you are

  • 5+ years related work experience in Information Security, Privacy & Risk Management with a min Bachelors in a related field.

  • Conducting or being the subject of security and/or privacy audits

  • Working with cloud environments required

  • Expert planner with business process definition experience and a strong IT aptitude

  • System hardening, analysis and vulnerability management

  • Understanding of applicable and accepted audit and risk frameworks (such as COBIT, NIST, and ISO), standards (ISO 27000 family, HITRUST) and government guidelines and laws (HIPAA, GDPR)

  • Clinical workflow solutions or in a clinical environment a plus

  • Knowledge of AWS and Cloud Security preferred

  • Relevant certifications like CISA, CISM, CRISC, CISSP preferred

  • Healthcare software experience is strongly preferred

Relocation benefits are not available for this position.

Who we are

At Roche, more than 100,000 people across 100 countries are pushing back the frontiers of healthcare. Working together, we’ve become one of the world’s leading research-focused healthcare groups. Our success is built on innovation, curiosity and diversity.

Roche Pharma Canada has its office in Mississauga, Ontario and employs over 850 employees. The Mississauga facility is bright, vibrant, fosters collaboration and teamwork, and is reflective of Roche's truly innovative culture.

As of January 4, 2022, Roche requires all new employees who work in Canada to be fully vaccinated against COVID-19 on the date they take office. This requirement is a condition of employment at Roche that applies regardless of whether the position is on a Roche campus or remotely. If you have a valid reason for not being fully immunized, which is limited to certain specific medical reasons or other valid reasons protected by applicable human rights laws, you may request an exemption and / or adaptation measures regarding this vaccination requirement.

Roche is an Equal Opportunity Employer.

Apply now Apply later

* Salary range is an estimate based on our InfoSec / Cybersecurity Salary Index 💰

Job stats:  1  0  0

Tags: Application security Audits AWS CISA CISM CISSP Cloud COBIT Compliance CRISC GDPR Governance HIPAA HITRUST ISO 27000 ISO 27001 Jira NIST Pentesting Privacy Product security Risk assessment Risk management Vulnerability management

Perks/benefits: Relocation support

More jobs like this

Explore more career opportunities

Find even more open roles below ordered by popularity of job title or skills/products/technologies used.