Program Lead, Third Party Risk and Resilience Management
F. Hoffmann-La Roche AG
## Program Lead, Third Party Risk and Resilience ManagementApplylocations: Tucsontime type: Full timeposted on: Posted Todayjob requisition id: 202605-113615At Roche you can show up as yourself, embraced for the unique qualities you bring. Our culture encourages personal expression, open dialogue, and genuine connections, where you are valued, accepted and respected for who you are, allowing you to thrive both personally and professionally. This is how we aim to prevent, stop and cure diseases and ensure everyone has access to healthcare today and for generations to come. Join Roche, where every voice matters.### ### The Position A healthier future. It’s what drives us to innovate. To continuously advance science and ensure everyone has access to the healthcare they need today and for generations to come. Creating a world where we all have more time with the people we love. That’s what makes us Roche.The Program Lead for Third Party Risk and Resilience Management establishes and maintains a robust governance framework for all Offshore Development Centers (ODCs), bridging R&D innovation requirements with Global IT security, infrastructure, and compliance standards. This leader ensures ODCs function as strategic extensions of Roche's R&D engine while maintaining zero major IT compliance breaches, and guides vendors during ODC setup to ensure full compliance with Roche Security standards.Compliance of all ODC setups and ongoing operations. Ensure alignment on scope, methodologies, processes at the nexus of R&D organization, Global procurement, and IT. Elimination of governance gaps and friction points between R&D and IT. Implementation of standardized, global ODC management framework across business units Security risks, incidents, and incident/change/problem management processes at ODC sites Strategic positioning of ODCs as value creators rather than cost centers ****The Opportunity***** Determine ODC necessity based on country risk and data sensitivity* Initiate new ODC setups, coordinate vendor office space establishment, and guide vendors on Roche Security standards* Conduct Security Risk Assessment (SRA) and Data Classification Review (DCR) for all services and applications* Identify services unsuitable for external business partners and escalate to product/service owners or DSM for remediation* Create, review, and maintain ODC Manuals, Impact Assessments, and Security Control Tables* Periodically review and update impact assessment documents to remove retired services* Ensure compliance with legal requirements (GDPR, CCPA) and Roche security protocols* Act as the owner for role-specific training curricula* Ensure training compliance for all external personnel by verifying mandatory security and role-specific requirements are met prior to system access.* Accountable for the systematic tracking and enforcement of training completion for vendor resources, leveraging the Roche Training Solution system* Approve all ODC changes including staff assignments, project onboarding, and service modifications* Manage ServiceNow requests for infrastructure (NAS storage, VD/VDI creation/updates, application packaging)* Identify VSA requirements and maintain vendor security/privacy capabilities throughout ODC lifecycle* Ensure security audits completed prior to service commencement and conduct periodic audits* Conduct assessments when major changes occur (new projects with higher security needs)* Track and remediate audit findings with vendors* Ensure mandatory notifications are formally integrated into processes (e.g., GSP) for all new vendor collaborations* Coordinate dedicated VDI planning with Citrix when default environments cannot support daily tasks* Optimize virtual desktop and application virtualization to reduce VDI requirements* Manage port opening for DIA, RDI, VDIs, and coordinate VDI creation* Collaborate with Network, Perimeter, and Citrix teams on connectivity and URL whitelisting* Ensure Business Partner Organization (BPO) approvals for applications, systems, URLs, RDP/SSH access* Populate and verify application inventories, URLs, and RDP/SSH server lists for Smart Web and virtual environments* Add users to ODC groups and implement access restrictions or policies as required* Lead ODC Security Incident Management with timely identification, escalation, and resolution* Promptly escalate security incidents to Roche IT Security Governance* Maintain incident, change, and problem management processes across all ODC operations* Participate in security audits and ensure all identified gaps are promptly closed* Regular evaluation of ODC setups for necessary updates* Document audit findings and track remediation to completion* Ensure execution of Business Continuity Plans and maintain disaster recovery readiness* Coordinate vendor selection, onboarding, and performance monitoring of strategic offshore partners* Work with vendor ODC managers and PICs on service/project onboarding and offboarding* Review periodic ODC compliance reports and resolve conflicts/issues related to readiness* Manage ODC user onboarding, offboarding, travel requests, and work-from-home (teleworking) approvals* Collaborate with vendors and delivery teams on project details and application access requirements* Oversee ODC decommissioning with proper data handling, access revocation, and infrastructure cleanup* Provide guidance on virtual desktop, application, and network challenges* Participate in technical discussions on Citrix, network infrastructure (WAN, firewalls, clients), security, risk, and governance* Coordinate across Vendor ODC managers, Roche IT Security, Network, Perimeter, Citrix, and application teams* Address ad-hoc requests and ODC challenges with quality and compliance focus* Translate complex technical requirements; articulate constraints and propose viable alternatives****Who You Are:***** You have a Bachelor’s or Advanced degree in a technical or business discipline (Computer Science, Information Security, or related field)* You have 8 years in IT/R&D environments* You have 5 years managing large-scale ODCs or captive centers* You have experience with Roche (or other large organization within a highly regulated industry) IT Security standards and compliance frameworks* You have strong compliance understanding to identify and mitigate risks; knowledge of GDPR, CCPA, and data privacy standards* You have experience with regulatory frameworks (GxP, ISO 27001) and audit requirements* You have experience with risk assessment methodologies and vendor security evaluation* You have a background in connectivity / network infrastructure: IT networks, cabling, switches, routers, WAN, firewalls* You have experience with virtual environments: VDI, Citrix platforms, and application virtualization* You have IT operations knowledge: thin/thick clients, servers, and technical documentation ServiceNow and IT Service Management tools* You are familiar with cloud infrastructure (AWS/Azure), DevOps and enterprise security frameworks* You hare experience with ISMS & ITSM implementation and best practices* You have incident management and problem resolution experience* You have a deep understanding of Software Development Lifecycle (SDLC) and R&D workflows* You have an outsourcing engagement models and service delivery operations* Pharmaceutical industry standards and R&D innovation processes ( (or other large organization within a highly regulated industry)****Preferred Qualifications:***** You have a professional security or risk management credentials—such as CISSP, CISM, CRISC, or equivalentRelocation benefits are not available for this posting The expected salary range for this position based on the primary location of Tucson, AZ is 106,400-197,600. Actual pay will be determined based on experience, qualifications, geographic location, and other job-related factors permitted by law. A discretionary annual bonus may be available based on individual and Company performance. This position also qualifies for the benefits detailed at the link provided below. #J-18808-Ljbffr
$107.5k - $204.5k
...The Coyote Missile On‑site Program Quality Lead (PQL) in Land and Air Defense Systems (LADS) supports... ...with ISO 9001 and/or AS9100 Quality Management Systems. Leadership experience in... ...skills with supervisory intervention. Risk mitigation and opportunity management...RiskContract workTemporary workWork experience placementFlexible hours- .... We are seeking a highly motivated Senior Program Quality Lead (PQL) to join our team. In this critical role,... ...health, including technical system evaluations and risk-based quality assessments. Ensure Quality Management System (QMS) processes are properly defined,...RiskCasual work
- ...Job Summary Position: Program Direct‑Support – Obsolescence Integrated Product Team (OIPT... ...designers, contracts, supply chain, and program management. Responsibilities Understand and/or... ...for developmental and production programs. Risk and opportunity business‑case analysis...RiskContract work
- ...Job title - Senior Program Manager Work location - Phoenix / Tucson, AZ Is it Hybrid, onsite... ..., vendor and contractor management, risk and issue tracking, and the preparation... ...of new projects • Collaboration with third-party vendors to oversee project delivery,...RiskContract workFor contractorsWork experience placementImmediate startRemote work
$132.4k - $251.6k
...complex problems. With our three market leading businesses, world-class operations, and... ...Principal Engineer to perform as an Execution Program Manager (PM) on the AMRAAM Obsolescence Program... ...and components to address obsolescence risks to the AMRAAM production and sustainment...RiskContract workTemporary workWork experience placementWork at officeLocal areaRemote workRelocationFlexible hours$132.4k - $251.6k
...day 1. Role: Sr. Principal Avionics Lead in the Advanced Effector Guidance... ...integration with Test Equipment (TE). Manage costs, schedule, and technical risk for design, verification, and... ...and collaborate with Functional and Program management. Work with customers and...RiskTemporary workRelocation packageFlexible hours$132.4k - $251.6k
...transferable) is required before start. Program Excalibur’s Guidance... ...Integrated Product Team (IPT) Lead. The role involves integration... ...I&V and systems engineering. Manage cost, schedule, and Earned Value... ...At Completion). Experience in Risk & Opportunity management....RiskContract workTemporary workInterim roleRelocation packageFlexible hours- ...responsible for overall project management delivery on account* Support... ...Capital Plan development, Program Scope and assigning the proper... ...regarding potential liabilities and risk, including understanding the... ...preferred* Experience leading and running numerous projects...RiskFor contractorsWork at office
- ...Position Overview The Test Systems Integrated Program Manager (IPM) is responsible for leading sub IPMs and multidisciplinary engineering teams, managing technical... ...Plan (IMP) Integrated Master Schedule (IMS) Risk and Opportunity Management Experience managing:...RiskContract work
$132.4k - $251.6k
...Overview Senior Principal Engineer – Execution Program Manager (PM) for the AMRAAM Obsolescence Program... ...Tucson, Arizona. Key Responsibilities Lead a cross‑functional team to proactively... ...leadership on the state of obsolescence risks. Coordinate and align interactions,...RiskContract workTemporary workLocal areaFlexible hours- ...Program Manager II Program Manager II is a mid-level Program Management position. Working with... ..., and fosters strategic thinking. Leads the development of detailed project or program... ...Proactively prepares and interprets Risk and Opportunity analyses and financial reports...RiskContract workFlexible hours
$107.5k - $204.5k
...Material Program Manager Raytheon is seeking an experienced supply chain professional to join... ...one's own job function as well as with parties external to the organization. What You... ...Chain status, material constraints and risk mitigation or opportunity capture plans...RiskContract workTemporary workWork experience placementRelocationFlexible hours$132.4k - $251.6k
...holidays, and incentive compensation programs. Role Overview Senior Manager, Material Program Management (MPM)... ...requirements and program objectives. Lead a team of 1–3 people in a matrixed organization... ...chain status, material constraints, risk mitigation, and opportunity capture...RiskTemporary workWork at officeFlexible hours$157.2k - $298.8k
...team is looking for a Portfolio Lead in the PMO/Transformation... ...Organization to support Procurement and Program Services initiatives. The role... ...the execution of project management activities, including project... ..., requirements, issues, risks, and dependencies. Address complex...RiskFlexible hours$132.4k - $251.6k
...and Test (SEIT) Cross Product Team (CPT) Lead reports to the Land and Air Defense... ...Key Responsibilities Achieve Raytheon’s Program Manager Certification within six months of hire.... ...team to make technical decisions, manage risks, and drive product verification. Drive integration...RiskTemporary workRelocation packageFlexible hours- ...Transaction Agreement (OTA) Program Manager This position will require... ...etc. Program and contract risk analysis and mitigation Provide... ...briefings on OTA status Lead public relations efforts with... ..., and other interested parties Ensure all appropriate records...RiskContract workFor contractors
- .... We are seeking a Structures Lead to join our team. The Structures... ...the discretion of department management. SMS REQUIREMENTS Employees... ...when the rules are violated, the risk of a mishap is usually... ...participate in safety education programs and train to recognize hazards...RiskTemporary workAll shiftsFlexible hoursShift workNight shiftAfternoon shift
$107.5k - $204.5k
...NSMS Manager, Supply Chain Management Raytheon is... ...management (to include program start up as well as execution... ...'ll also develop and lead a material program... ...function as well as with parties external to the organization... ...constraints and risk mitigation or opportunity...RiskTemporary workWork experience placementWork at officeFlexible hours$132.4k - $251.6k
...Principal Mechanical Design Engineer to lead Hardware Integrated Product Team efforts for the Standard Missile 3 (SM-3) program. This role involves overseeing a multi... ...integrity for hardware design, while managing requirements, risks, and schedules. The ideal candidate...Risk$107.5k - $204.5k
...CAM duties, including cost and schedule management, variance analysis, and earned value management... ...control accounts. Collaborate with program and customer leadership teams to brief on... ...financial performance, constraints, and risk mitigation or opportunity capture plans....RiskTemporary workWork at officeRelocationFlexible hours$107k - $147k
...Overview Job Title: Staff Engineer, Program / Project Management Functional Area: Engineering (ENG)... ...(technology, organizationally). Lead cross-functional, global core team(s),... ...revenue, cost/labour & expense Manage risks and issues, taking corrective measurements...RiskWork at officeRemote work$132.4k - $251.6k
...Overview Test Equipment Senior Program Manager for the StormBreaker Program with the Air & Space... ..., quality, business finance, contracts, risk management, test equipment, finance, planning... ...Government Integrated Project Team Leads (ITPL), Production Program Manager, and...RiskContract workTemporary workFlexible hours$16.45 - $17.45 per hour
...you work here As a Receiving Lead, you will be responsible for managing the store's backroom operations by... ...forth by the Marketing Team Take Risks; Wear a Helmet: It never hurts... ...employees seriously. Our Wellness program and safety committee offer workshops...RiskHourly payFull timeImmediate startShift workNight shiftAfternoon shift$128.64k - $185.81k
...Area Chief of Staff is to lead, develop and manage associate veterinarians in... ...by consistently assessing risk, ensuring a proactive retention... ...role. Oversee the coaching program for newly hired... ...supervision. Tolerance for Stress / Resiliency Maintains a positive "can do...RiskFull timeTemporary workPart timeLocal areaFlexible hoursShift work- ...Information: Elbit America is a leading provider of high-performance... ...engaged in a wide range of programs for innovative defense and... ...Summary: The Material Program Manager leads material strategy,... ...material readiness, manages supply risk, supports cost and schedule...RiskContract workFor subcontractorFlexible hours
$175k - $245k
...seeking a highly organized and technically fluent Senior Program Manager (Sceptre) to lead the planning, coordination, and execution of complex programs... ...teams Track program progress and communicate status, risks, and mitigation strategies to leadership Facilitate sprint...RiskLocal areaFlexible hours$91k - $147.2k
...MTST Global Finance Reporting Lead - Endomech and Energy to be located... ...initiatives on the end-to-end management across all Endomechancial and... ...-based compensation programs. Under current guidelines, this... ...Reporting and Analysis, Financial Risk Management (FRM), Financial Statement...RiskFull timeTemporary workLocal areaRemote workWorldwide$31.59 - $41.06 per hour
...Plumber IV (Lead) Posting Number req26105 Department Facilities Mgmt-... ...insurance plans; life insurance and disability programs; paid vacation, sick leave, and holidays;... ...to emergency service calls, assess risk, implement corrective actions, and restore...RiskHourly payFull timePart timeFor contractorsWork experience placementWork at officeLocal areaRelocation- ...Pimasheriff is currently seeking a Public Health Program Manager I in Tucson, AZ. The role focuses on leading an evidence-based oral health program aimed at improving lifelong health habits among students. This position involves supervising a dedicated team, managing...
- ...modern data platforms, leading high-performing... ...we're looking for a Manager, Enterprise Data & Analytics... ...). Govern third-party connectivity and middleware... ...run a data literacy program including role-based... ...decisions. Risk, Compliance & Resilience Ensure...RiskWork at officeLocal areaRemote work
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Program Lead, Third Party Risk and Resilience Management. Be the first to apply!




