×
Register Here to Apply for Jobs or Post Jobs. X

Manager, IT Risk and Compliance

Job in Foster City, San Mateo County, California, 94420, USA
Listing for: Gilead Sciences, Inc.
Full Time position
Listed on 2025-11-27
Job specializations:
  • IT/Tech
    Cybersecurity, Information Security, IT Consultant, Data Security
Salary/Wage Range or Industry Benchmark: 100000 - 140000 USD Yearly USD 100000.00 140000.00 YEAR
Job Description & How to Apply Below

Gilead's mission is to discover, develop, and deliver therapies that will improve the lives of patients with life‑threatening illnesses worldwide. The Manager, IT Risk and Compliance is a key member of the Security Risk Compliance (SRC) - DP team and works closely with the legal Privacy & Data Ethics (P&DE) team, and other IT teams to ensure privacy program and controls are in place.

They will serve as a subject matter expert on Information Security and Privacy principles; company policies and standards; and regulatory requirements as they pertain to data privacy. The person in this position will be required to understand and communicate the reporting requirements as defined by company policy and interpret and apply the concepts and requirements when processing and managing privacy and security incidents.

Key Responsibilities
  • Develop / update / maintain data related privacy policies, standards and documentation.
  • Contribute directly to the data privacy program strategy and roadmap.
  • Be responsible for working on and leading Data Privacy related projects, project tasks and deliverables.
  • Serve as an initial point of contact & escalation for other team members, operational teams & works relating to Data Privacy (i.e. PIAs / Vendor Security Assessments and contract reviews and security rider updates) and escalate when appropriate.
  • Provide assessor / manager related lead activities for Data Privacy Incidents (DPIs) & work collaboratively with the Cybersecurity / SOC team for interactions between DPIs and SOC Security incidents.
  • Lead inputs for Data Privacy related assessments providing review / approval for resultant reports.
  • Participate in requirements for and reviews of vendor proposals.
  • Support the Privacy Champions group by delivering awareness and education beyond IT to other Gilead business units.
  • Drive continual improvements for the creation and delivery of Data Privacy educational, training and orientation programs for all employees, contractors and other appropriate third parties.
  • Maintain current knowledge of application U.S and EU and global data protection laws and accreditation standards.
  • Builds and develops strategic working relationships across business groups and provide lead coverage on more complex issues.
  • Review system‑related information security plans throughout the practice / organization’s network to ensure alignment between security and privacy practices.
  • Provide support and conduct reviews of contracts, service level and evaluation agreements.
  • Collaborates within various business groups to analyze and evaluate reported potential privacy incidents to determine whether a loss of sensitive data, protection health information, policy violation, and / or cyber or other threat to the enterprise has occurred.
  • Analyses and identifies trends from privacy and security reportable issues.
  • Define and creates privacy and security reportable issues metrics and reports.
  • Participate in other activities relating to security and privacy incident management.
Basic Qualifications
  • Bachelor's Degree and Six Years' Experience OR Masters' Degree and Four Years' Experience AND progressively responsible IT experience including experience in information security / privacy & risk management and being responsible for leading a team / service provider function.
  • Experience developing and implementing compliance monitoring processes and procedures.
  • In depth experience with formal project planning and risk assessment methodologies.
  • Strong knowledge of information systems security concepts and current information security / privacy trends and practices.
  • Knowledge of EU and global security and privacy‑related regulatory requirements (i.e. U.S Privacy and Security Regulations, GDPR, PIPA, PIPEDA, etc.).
  • Strong business and technical skills in the planning, administration, and management of information systems, operational and technical security controls; and security risk analysis and management.
  • Ability to write and communicate in proper business English (including writing our formal assessment documents), with strong verbal skills and ability to adapt information delivery based on the target audience.
Preferred Qualifications
  • Indus…
To View & Apply for jobs on this site that accept applications from your location or country, tap the button below to make a Search.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
 
 
 
Search for further Jobs Here:
(Try combinations for better Results! Or enter less keywords for broader Results)
Location
Increase/decrease your Search Radius (miles)

Job Posting Language
Employment Category
Education (minimum level)
Filters
Education Level
Experience Level (years)
Posted in last:
Salary