Talent Apply
Log in
All jobs
R

IT Strategic Risk & Audit Manager

Roche

About this role

About the Role At Roche, the IT Strategic Risk & Audit Manager role defines and leads the strategic IT risk, audit, and compliance program, partnering with Digital Technology leaders to ensure that our digital evolution—from AI-driven drug discovery to personalized healthcare apps—is built on trust and resilience. The role focuses on strategic foresight and proactive risk management across global portfolios, aligning long-term digital strategy with Roche’s risk appetite to ensure "Compliance by Design". What You'll Do

  • Defines the strategic vision for IT risk, audit, and compliance, and drives strategic initiatives for long-term risk management success.
  • Initiates and leads large, complex projects with a significant impact on the organization.
  • Leads the development of enterprise-wide risk and compliance policies and advises on emerging trends and best practices.
  • Strategic Risk Architecture & Vision: Define and architect the global IT Enterprise Risk Management (ERM) framework (NIST, ISO 27001, COBIT), aligning long-term digital strategy with Roche’s risk appetite to ensure "Compliance by Design" across complex, interconnected global portfolios.
  • Accountability/Problem Solving: Leads the analysis of highly complex business and risk challenges with significant organizational impact, proactively identifying potential strategic issues within your sphere of influence. Develops comprehensive risk management and compliance policies, implements proactive measures to avoid repeated issues, and leads initiatives to anticipate and mitigate future risks. Contributes to framing strategic questions and facilitates strategic decision-making at the executive level.
  • Stakeholder Management: Identifies and engages key stakeholders at the executive level and external partners, analyzing enterprise-wide stakeholder landscapes. Leads enterprise-wide risk, audit, and compliance initiatives, presenting them to executive leadership to secure support and strategic alignment for risk-related investments. Navigates highly complex and politically sensitive landscapes, acting as an organizational trust builder and providing expert counsel on critical strategic decisions.
  • E2E Audit & Compliance Leadership: Lead the full lifecycle of complex IT audits and continuous monitoring programs across infrastructure and applications, ensuring robust coverage and proactive risk management. What We're Looking For
  • Proven ability to define and drive IT risk, audit, and compliance programs, and to translate regulatory requirements into practical, scalable controls.
  • Experience architecting and implementing enterprise IT risk management frameworks (e.g., NIST, ISO 27001, COBIT).
  • Strong analytical and problem-solving skills with a track record of proactively identifying strategic issues and enabling executive decision-making.
  • Excellent stakeholder management at the executive level, with experience navigating complex, politically sensitive environments.
  • Experience leading end-to-end IT audits and continuous monitoring across infrastructure and applications.

Your next opportunity starts here

Prepare, apply, track, interview and get hired — all from one platform, with AI in your corner.

Download app

Or sponsor Premium for someone who's job hunting →