Cyber Security Compliance Intern
5 days ago
Sant Cugat del Vallès
ppBei Roche kannst du ganz du selbst sein und wirst für deine einzigartigen Qualitäten geschätzt. Unsere Kultur fördert persönlichen Ausdruck, offenen Dialog und echte Verbindungen. Hier wirst du für das, was du bist, wertgeschätzt, akzeptiert und respektiert. Dies schafft ein Umfeld, in dem du sowohl persönlich als auch beruflich wachsen kannst. Gemeinsam wollen wir Krankheiten vorbeugen, stoppen und heilen und sicherstellen, dass jeder Zugang zur Gesundheitsversorgung hat – heute und in Zukunft. Werde Teil von Roche, wo jede Stimme zählt. /p h3Die Position /h3 pWe are the global product security and privacy center of Roche Diagnostics worldwide. /p pbOur vision: /b /p ul lipTo build a solid Global Product Security and Privacy Operations function, provide strategic security insight across Roche Diagnostics to ensure our devices are what our regulators require and our patients deserve. /p /li /ul pbOur priorities: /b /p ul lipUnderstanding our customers and Stakeholder needs to deliver effective security on testing solutions /p /li lipDevelop an agile and sustainable operating business model to deploy security concepts that enable confident healthcare decisions. /p /li lipInstitutionalize security role models to provide guidance, education and awareness to maximize the security of Roche Diagnostics solutions and create trust along the patients journeys /p /li /ul pData security and privacy are key success factors in our digital transformation and essential to reach our ambitions. You are inspired to contribute to the overall Roche Diagnostics vision by applying end-to-end Division-wide product security and privacy operations to keep our products and services secure and privacy compliant throughout the entire lifecycle. You believe in the potential of science, technology, data and insights to improve the standard of care for humankind and you are eager to help navigate through unchartered territory to lift this potential. /p pbThe Position /b /p pThe bCyber Security Compliance Intern /bwill: /p ul lipCoordinate and manage product security and privacy compliance activities. /p /li lipAuthor new or updated policies and procedures for internal partner and stakeholder input. /p /li lipCreate and maintain security and privacy relevant documentation in response to legal and regulatory requirements (e.g. HIPAA, GDPR, etc.), manages the documentation and related intranet repositories. /p /li lipPrepare and deliver communication and training to educate Roche teams on the evolving compliance landscape and new or updated policies and related changes /p /li lipSupport Roche Sales, product teams and IT groups, legal and other appropriate parties to address customer questions and needs regarding Roche’s products to ensure customer confidence in data security (e.g. by reviewing contract templates and contributing with architecture specific security and privacy language, supporting completion of customers’ security questionnaires, etc.). /p /li lipWhere observed, escape actual or potential compliance violations or other issues to relevant colleagues or management, according to local, regional and/or global policies and procedures. /p /li lipManage and performs activities related to preparation, execution and remediation of internal and external compliance audits /p /li lipMaintain IT internal controls ensuring that they are designed and operating effectively to meet compliance requirements for in-scope applications. /p /li lipEstablish and promote business compliance implementation process, and ensure the risk convergence and privacy protection technology for business scenarios; /p /li lipUnderstand cybersecurity concepts and be able to communicate it to users that do not come from a security background. /p /li lipReview of key processing activities, data protection impact assessments (DPIA’s), data processing agreements, data retention, data deletion approach, training records, etc. /p /li /ul pbMinimum Qualifications: /b /p ul lipBachelor degree in a field with a strong emphasis on information security, computer, communication, or related majors, master degree as a plus. /p /li lip1+ years cybersecurity and/or privacy program management experience and exposure to large-scale systems in fast-paced environment. /p /li lipAudit and/or compliance related roles experience in multinational environments. /p /li lipExperience in using data and metrics to define business strategy and gain executive support for new visions. /p /li lipPreferable related experience in the healthcare, diagnostics, and / or pharmaceutical industry, preferred. /p /li lipKnowledge of HIPAA, GDPR, and other privacy relevant legislation and regulations /p /li lipExcellent Verbal/Written communication data presentation skills, proved ability to effectively communicate with both business and technical teams. /p /li lipAbility to work in and with globally distributed and multi-cultural teams. /p /li lipBest in class attitude; challenge status constructively and contribute to improvements; results oriented; ability to influence; solution oriented mindset. /p /li /ul pbPreferred Qualifications: /b /p ul lipExperience working in a Software Development environment. /p /li lipValuable certifications: ISO 27001 Lead Auditor, CISA, CISM, CISSP, GIAC, OSCP, SSCP or equivalent certification /p /li lipProven ability to influence change at all levels within an organization /p /li lipExpert planner with business process definition experience and a strong IT aptitude /p /li lipKnowledge of Product Development Life Cycles (PDLC) /p /li lipWorking knowledge or willingness to quickly learn the content and requirements of various laws, regulations, industry guidance, and company compliance policies, particularly related to privacy, data disclosure, and cybersecurity /p /li lipDemonstrate data analytical skills, creativity, and experience working with attention to detail /p /li lipExperience maintaining open, candid, and trusting work relationships /p /li lipAbility to “Zoom Out” (see the big picture and give strategic direction) as well as to “Zoom in” (to provide more granularity when exchanging with a wide range of experts. /p /li lipStrong business acumen; sensitive to business needs; view change as an opportunity; eager to work in a fast-paced environment. /p /li lipStrong organizational skills and ability to prioritize and manage multiple projects simultaneously. /p /li /ul h3Wer wir sind /h3 pEine gesündere Zukunft treibt uns zur Innovation an. Mehr als 100.000 Mitarbeiter weltweit arbeiten gemeinsam daran, wissenschaftliche Fortschritte zu erzielen und sicherzustellen, dass jeder Zugang zur Gesundheitsversorgung hat – heute und für zukünftige Generationen. Durch unser Engagement werden über 26 Millionen Menschen mit unseren Medikamenten behandelt und mehr als 30 Milliarden Tests mit unseren Diagnostik-Produkten durchgeführt. Wir ermutigen uns gegenseitig, neue Möglichkeiten zu erkunden, Kreativität zu fördern und hohe Ziele zu setzen, um lebensverändernde Gesundheitslösungen zu liefern. /p pGemeinsam können wir eine gesündere Zukunft gestalten. /p pbRoche ist ein Arbeitgeber, der die Chancengleichheit fördert. /b /p /p #J-18808-Ljbffr