Talent.com
Manager, IT Risk and Compliance
Manager, IT Risk and ComplianceGilead Sciences, Inc. • Foster City, CA, United States
Manager, IT Risk and Compliance

Manager, IT Risk and Compliance

Gilead Sciences, Inc. • Foster City, CA, United States
11 hours ago
Job type
  • Full-time
Job description

Gilead's mission is to discover, develop, and deliver therapies that will improve the lives of patients with life‑threatening illnesses worldwide. The Manager, IT Risk and Compliance is a key member of the Security Risk Compliance (SRC) - DP team and works closely with the legal Privacy & Data Ethics (P&DE) team, and other IT teams to ensure privacy program and controls are in place. They will serve as a subject matter expert on Information Security and Privacy principles; company policies and standards; and regulatory requirements as they pertain to data privacy. The person in this position will be required to understand and communicate the reporting requirements as defined by company policy and interpret and apply the concepts and requirements when processing and managing privacy and security incidents.

Key Responsibilities

  • Develop / update / maintain data related privacy policies, standards and documentation.
  • Contribute directly to the data privacy program strategy and roadmap.
  • Be responsible for working on and leading Data Privacy related projects, project tasks and deliverables.
  • Serve as an initial point of contact & escalation for other team members, operational teams & works relating to Data Privacy (i.e. PIAs / Vendor Security Assessments and contract reviews and security rider updates) and escalate when appropriate.
  • Provide assessor / manager related lead activities for Data Privacy Incidents (DPIs) & work collaboratively with the Cybersecurity / SOC team for interactions between DPIs and SOC Security incidents.
  • Lead inputs for Data Privacy related assessments providing review / approval for resultant reports.
  • Participate in requirements for and reviews of vendor proposals.
  • Support the Privacy Champions group by delivering awareness and education beyond IT to other Gilead business units.
  • Drive continual improvements for the creation and delivery of Data Privacy educational, training and orientation programs for all employees, contractors and other appropriate third parties.
  • Maintain current knowledge of application U.S and EU and global data protection laws and accreditation standards.
  • Builds and develops strategic working relationships across business groups and provide lead coverage on more complex issues.
  • Review system‑related information security plans throughout the practice / organization’s network to ensure alignment between security and privacy practices.
  • Provide support and conduct reviews of contracts, service level and evaluation agreements.
  • Collaborates within various business groups to analyze and evaluate reported potential privacy incidents to determine whether a loss of sensitive data, protection health information, policy violation, and / or cyber or other threat to the enterprise has occurred.
  • Analyses and identifies trends from privacy and security reportable issues.
  • Define and creates privacy and security reportable issues metrics and reports.
  • Participate in other activities relating to security and privacy incident management.

Basic Qualifications

  • Bachelor's Degree and Six Years' Experience OR Masters' Degree and Four Years' Experience AND progressively responsible IT experience including experience in information security / privacy & risk management and being responsible for leading a team / service provider function.
  • Experience developing and implementing compliance monitoring processes and procedures.
  • In depth experience with formal project planning and risk assessment methodologies.
  • Strong knowledge of information systems security concepts and current information security / privacy trends and practices.
  • Knowledge of EU and global security and privacy‑related regulatory requirements (i.e. U.S Privacy and Security Regulations, GDPR, PIPA, PIPEDA, etc.).
  • Strong business and technical skills in the planning, administration, and management of information systems, operational and technical security controls; and security risk analysis and management.
  • Ability to write and communicate in proper business English (including writing our formal assessment documents), with strong verbal skills and ability to adapt information delivery based on the target audience.
  • Preferred Qualifications

  • Industry appropriate certifications beneficial (CIPP / EU and / or U.S, CIPM, CHP, or other certified privacy or security‑related credentials).
  • In‑depth knowledge and experience of vendor / supplier‑based security and privacy assessments and on‑site audits.
  • Knowledge about medical records and other medical information, patient privacy and confidentiality, and release of information.
  • Experience in appropriately managing confidential and sensitive information.
  • Must be able to prepare formal reports and presentations as needed.
  • Must be detailed oriented and possess the ability to prioritize tasks so work is completed in an accurate, timely manner.
  • Strong Knowledge of Security Frameworks (ISO 27001, NIST 800‑53, etc.).
  • Self‑starter with the ability to work independently, lead others, prioritize, multi‑task, and maintain flexibility in fast‑paced, changing environment. Be proactive, independent and responsive – requires little supervisory attention.
  • Ability to confront conflict and progress difficult issues in a professional, assertive and proactive manner.
  • Ability to build strong working relationships at all levels, internal and / or external to the organization.
  • Prior working experience in a pharmaceutical company is strongly preferred.
  • Highly organized, results‑oriented and attentive to details.
  • People Leader Accountabilities

    Create Inclusion - knowing the business value of diverse teams, modeling inclusion, and embedding the value of diversity in the way they manage their teams.

    Develop Talent - understand the skills, experience, aspirations and potential of their employees and coach them on current performance and future potential. They ensure employees are receiving the feedback and insight needed to grow, develop and realize their purpose.

    Empower Teams - connect the team to the organization by aligning goals, purpose, and organizational objectives, and holding them to account. They provide the support needed to remove barriers and connect their team to the broader ecosystem.

    Share : #J-18808-Ljbffr

    Create a job alert for this search

    Risk Manager • Foster City, CA, United States

    Related jobs
    Senior Manager, Risk and Compliance

    Senior Manager, Risk and Compliance

    California Staffing • San Francisco, CA, US
    Full-time
    Senior Manager, Risk And Compliance.With an "A" health rating and solid year-over-year growth, San Francisco Federal Credit Union's (SFFedCU) membership is now over 43,000 with assets surpassing $1...Show more
    Last updated: 4 days ago • Promoted
    Information Technology (IT) Risk Management, Dir.

    Information Technology (IT) Risk Management, Dir.

    Federal Home Loan Bank of San Francisco • San Francisco, CA, United States
    Full-time
    Information Technology (IT) Risk Management, Dir.Join to apply for the Information Technology (IT) Risk Management, Dir.Federal Home Loan Bank of San Francisco. The Federal Home Loan Bank of San Fra...Show more
    Last updated: 30+ days ago • Promoted
    Senior Cyber Risk Manager

    Senior Cyber Risk Manager

    Avant Digital Inc. • San Francisco, CA, United States
    Temporary
    As the Senior Cyber Risk Manager, you will be responsible for overseeing the identification, assessment, mitigation, and monitoring of technology-related risks within the organization.You will play...Show more
    Last updated: 30+ days ago • Promoted
    Director of Cyber Security / IT Risk

    Director of Cyber Security / IT Risk

    Resources Global Professionals Inc • San Francisco, CA, United States
    Full-time
    We are seeking a Director, IT Risk Assurance, with focus on cybersecurity and data privacy who will be responsible for supporting business development as well as leading, managing and, when necessa...Show more
    Last updated: 12 days ago • Promoted
    Senior Information Systems Manager - HCM & Security

    Senior Information Systems Manager - HCM & Security

    Enterprise for Youth • San Francisco, CA, United States
    Full-time
    A public service organization in San Francisco seeks an Information Systems Manager to oversee the PeopleSoft HCM system, ensuring compliance and managing IT infrastructure.The ideal candidate will...Show more
    Last updated: 5 days ago • Promoted
    Payments Compliance IT Risk Manager - Strategic Controls

    Payments Compliance IT Risk Manager - Strategic Controls

    Jobs via Dice • San Francisco, CA, United States
    Full-time
    A leading technology company is seeking a Manager for IT Financial Risk Management focusing on Payments Compliance.In this hybrid role in San Francisco, you will execute compliance strategies, over...Show more
    Last updated: 6 days ago • Promoted
    Engagement Manager - Risk Infrastructure

    Engagement Manager - Risk Infrastructure

    Inizio Partners Corp • San Francisco, CA, United States
    Full-time
    About the job Engagement Manager - Risk Infrastructure.As the Risk Infrastructure Engagement Manager, you will lead a critical project from onshore for strategy implementation in.This role requires...Show more
    Last updated: 30+ days ago • Promoted
    IT Director, Risk Advisory Services

    IT Director, Risk Advisory Services

    BDO Capital Advisors, LLC • San Francisco, CA, United States
    Full-time
    Working under the authority of a Principal, the Assurance Director, Risk Advisory Services is responsible for overseeing and delivering risk advisory services around Information Technology (IT) rel...Show more
    Last updated: 30+ days ago • Promoted
    Senior Manager, Risk and Compliance

    Senior Manager, Risk and Compliance

    San Francisco Federal Credit Union • San Francisco, CA, United States
    Full-time
    With an “A” health rating and solid year-over-year growth, San Francisco Federal Credit Union’s (SFFedCU) membership is now over 43,000 with assets surpassing $1. San Francisco and San Mateo County....Show more
    Last updated: 6 days ago • Promoted
    Strategic IT Security & Compliance Advisor - Hybrid

    Strategic IT Security & Compliance Advisor - Hybrid

    Network Right LLC • San Francisco, CA, United States
    Full-time
    A consultancy firm is seeking a Senior IT Security & Compliance Consultant to help clients establish strong security and compliance programs. The role involves advising high-growth startups and ente...Show more
    Last updated: 5 days ago • Promoted
    Manager, IT Procurement

    Manager, IT Procurement

    Varite • Oakland, CA, US
    Full-time
    Pay rate range : $140000 - 173500 / yr.Department Overview : The Procurement organization is the functional lead for the procurement of materials and services at Client Company.The department collabora...Show more
    Last updated: 30+ days ago • Promoted
    Director of Applications, IT

    Director of Applications, IT

    Cogent Info • San Carlos, CA, US
    Full-time
    The IT Director, Applications, will report to the Chief Information & Technology Officer in the Division of Innovation & Technology. The IT Director's role is to plan, organize, and manage staff and...Show more
    Last updated: 30+ days ago • Promoted
    Head of IT & Security Operations (Hybrid)

    Head of IT & Security Operations (Hybrid)

    Sentry • San Francisco, CA, United States
    Full-time
    A leading software monitoring company is seeking a Head of IT to manage their SaaS technology ecosystem.The role involves vendor management, IT initiatives, and leading a distributed technical team...Show more
    Last updated: 3 days ago • Promoted
    Manager, IT Financial Risk Management - Payments Compliance

    Manager, IT Financial Risk Management - Payments Compliance

    Uber • San Francisco, CA, United States
    Full-time
    Manager, IT Financial Risk Management - Payments Compliance.Must be located in or willing to relocate to San Francisco.The Financial Risk Management Advisory team plays a critical role in safeguard...Show more
    Last updated: 7 days ago • Promoted
    IT Manager

    IT Manager

    TradeJobsWorkForce • 94710 Berkeley, CA, US
    Full-time
    Running regular checks on network and data security Identifying and acting on opportunities to improve and update software and systems Developing and implementing IT policy and best practice guides...Show more
    Last updated: 30+ days ago • Promoted
    Governance, Risk, and Compliance Lead

    Governance, Risk, and Compliance Lead

    xAI • San Francisco, CA, United States
    Full-time
    Governance, Risk, and Compliance Lead.Governance, Risk, and Compliance Lead.Get AI-powered advice on this job and more exclusive features. AI’s mission is to create AI systems that can accurately un...Show more
    Last updated: 30+ days ago • Promoted
    Director of Cyber Security / IT Risk

    Director of Cyber Security / IT Risk

    RGP • San Francisco, CA, United States
    Full-time
    We are seeking a Director, IT Risk Assurance, with focus on cybersecurity and data privacy who will be responsible for supporting business development as well as leading, managing and, when necessa...Show more
    Last updated: 7 days ago • Promoted
    IT Manager-I

    IT Manager-I

    Abacus Service Corporation • San Francisco, CA, US
    Full-time
    Location : HQ, USA, CA, San Francisco, 2nd St.Description : Platform Innovation, Technical Support Lead.About the Team : The Platform Innovation team drives strategy, support, and scaling for one of t...Show more
    Last updated: 30+ days ago • Promoted