Risk, policy and third party. Run the information security risk register as a decision-making tool, own the policy lifecycle and exception register, and assess the vendors and partners we integrate with.
Incident response and regulatory notification. Own breach assessment and the notification decision across the jurisdictions we operate in, alongside Legal. In healthcare this is the highest consequence judgement in the role.
Finding what is broken before someone else does. Go looking. Read the infrastructure code, pull the access review output, check that the alert a policy promises is actually configured. When you find a gap, bring it quantified, costed and sequenced.
...
Support Business Operations: Perform data analysis and testing to contribute to affiliate reporting and broader Compliance Projects
Build Relationships: Engage and network with colleagues from various business functions, while effectively escalating complex issues to your RSS Line Manager when required
You are an undergraduate student from a reputable university pursuing a degree in Business, Law, Finance, or a related field
...
Research potential violations and work with operations, customers, and the relevant Government on solutions to problems with Denied Parties and Embargoes shipments
Maintaining the platform rulebook and running amendments through the SC's review routes.
Ensuring the anti-money laundering monitoring allocation is recorded in every partner agreement, and that the partner's monitoring is evidenced rather than assumed.
Owning conflicts of interest, anti-corruption and whistleblowing, and complaints.
...
Provide oversight over the adoption and implementation of Group compliance requirements by business segments, operating companies and corporate functions.
Review existing compliance processes and controls to identify structural gaps, duplication, inconsistencies or opportunities for improvement.
Support periodic review of the effectiveness and maturity of the Group's overall compliance governance arrangements.
...
Driving effective integrity & governance communication programmes (via training, awareness and other forms of communication) for the Group by taking reasonable steps to communicate periodically and in a practical manner its standards and procedures, and other aspects as required.
Overseeing the direction and management of the whistleblowing function, including responding to alleged wrongdoings by evaluating or recommending the initiation of investigative procedures as appropriate, ensuring uniform handling and resolution of such violations.
Prepare and present reports, presentations and briefing materials for Board and Management
...
Manage the end-to-end Corrective and Preventive Action (CAPA) lifecycle, driving root cause analysis (RCA) and ensuring on-time remediation of audit findings and IT deviations
Ensure all regulated ERP systems comply with Roche Computerized System Validation (CSV) policies, GxP Data Integrity (ALCOA++), Annex 11, 21 CFR Part 11, GAMP standards, and AI validation SOPs
Maintain and monitor IT General Controls (ITGCs) across User Access & Authorizations, Change Management (SolMan/ChaRM), IT Operations, Segregation of Duties (SoD), and emergency firefighter access
...
Performs other relevant support activities as and when required (e.g. support in validating/ performing data analysis/testing which contributes to the reporting to affiliates/ Compliance Projects )
Escalates issues to superior/RSS Line Manager (where required)
Engages in networking with colleagues from other business functions when required to
...
Escalates issues and recommend resolution plans in a timely manner to the RSS Line Manager and Affiliate (where required)
Support the preparation of reports and training material on a periodic basis to address updates to the compliance monitoring process
As part of day-to-day operations work collaboratively with the team to identify opportunities to improve compliance documentations (e.g. review manuals, return reason coding etc)
...
Performs other relevant support activities as and when required (e.g. support in validating/ performing data analysis/testing which contributes to the reporting to affiliates/ Compliance Projects )
Escalates issues to superior/RSS Line Manager (where required)
Engages in networking with colleagues from other business functions when required to
...
Collect all relevant information for raised issues, analyze root cause and propose solution to 2nd Level Support if needed. Raising requests to 2nd Level Support for user creation / unlocking / change of user parameters
Contribute to the continuous improvement processes which also reflects your personal mindset. High commitment to maintain / improve service levels. Develop a comprehensive understanding of the overall Internal Controls organization and broader business. Problem solving root causes collaboratively. Critical thinking and problem solving that result in process improvements
First point of contact for key stakeholders, ensure collaborative relationship. Regular operational reviews with stakeholders for own area. Contribute to develop Customer Satisfaction on a cross-functional level
...
Review designs, renovations, method statement and fit-out works for compliance with applicable codes and corporate standards.
Audit and ensure compliance with Uniform Building By-Laws (UBBL), BOMBA (Fire Services Act, fire safety requirements), DOSH-OSHA 1994 and Other relevant authorities (local councils, ST, CIDB)
Conduct regular safety inspections, incident investigations, and root cause analyses and liaison with intra/inter dept and external stakeholders
...
Support Knowledge & Reporting: Assist in preparing periodic compliance reports and training materials to keep teams aligned on process updates
Advance Process Improvement: Collaborate with global and regional peers to refine compliance documentation, streamline review manuals, and enhance operational workflows
Participate in Strategic Projects: Contribute your expertise to global compliance programs, audit initiatives, and continuous improvement activities
...