406,377open jobs
14,133companies
78,486added this week
Browse all
Salary
$33k – $86k per year (Estimated)
Location
In office (Madrid)
Seniority
Middle · 3+ years exp
Employment
Full-Time
Overview
Company
Impact
Profile match
Roche is a Swiss healthcare group founded in Basel in 1896 and is unusual in operating two large divisions of comparable importance: prescription medicines and in vitro diagnostics. The pharmaceutical business is built on oncology, neurology, immunology, ophthalmology and haemophilia, with products such as Ocrevus, Hemlibra, Perjeta and Vabysmo, while the diagnostics division supplies laboratory analysers, molecular tests and sequencing systems to hospitals worldwide. The group owns the American biotechnology company Genentech outright and the Japanese firm Chugai in majority, is controlled by a family shareholder pool, and spends among the largest research budgets in the industry.

At Roche you can show up as yourself, embraced for the unique qualities you bring. Our culture encourages personal expression, open dialogue, and genuine connections, where you are valued, accepted and respected for who you are, allowing you to thrive both personally and professionally. This is how we aim to prevent, stop and cure diseases and ensure everyone has access to healthcare today and for generations to come. Join Roche, where every voice matters.

The Position

The Network Securityproduct makes Roche’s connectivity accessible and secure through actionable, policy-driven processes. The capabilities we provide enable Roche to identify, inspect, and mitigate network-based risks, manage regulatory compliance, and oversee egress/ingress traffic across all layers. Our solutions are primarily instantiated through leading-edge security platforms and automated orchestration. We work closely with Cloud, Infrastructure, and Incident Response teams to provide enterprise visibility into Roche’s network security posture.

You’ll be working within the Network Security Productarea. This area is accountable for the end-to-end delivery of solutions-designing, building, and maintaining the technologies that protect Roche networks and the Internet, whether on-prem or cloud-based. This includes continuous improvement of capabilities like Internet Security Stack, DDoS Protection, Site-to-Site Connectivity (VPN), Network Access Control and Deep Packet Inspectionto stay ahead of an ever-evolving threat landscape.

As the Subject Matter Expert (SME) for Network Security, you will lead the Design, Build, and Improvement of critical security infrastructures, specifically focusing on Cisco ISE, Wired Access Control (WAC), and Palo Alto Networks. This is a dual-impact role: you are the technical authority for the secure access layer, while simultaneously leading the engineering of a custom observability framework. You will develop the front-end, back-end, and integration logic required to provide deep visibility into the security product health and asset inventory.

Job Responsibilities

1. SME:

Secure Access (ISE, WAC, Palo Alto)

  • Design & Architecture: Lead the high-level and low-level design (HLD/LLD) for global Cisco ISE deployments and Wired Access Control (WAC) strategies to ensure seamless, identity-based security.

  • Palo Alto SME: Serve as the primary engineer for Palo Alto NGFW architectures, including advanced threat prevention, decryption, and secure egress/ingress traffic management.

  • Continuous Improvement: Proactively identify gaps in the current security posture and implement technical enhancements to NAC policies, SGT (TrustSec) propagation, and firewall rule-sets.

  • Build & Implementation: Act as the lead "implementer" for complex global migrations and new feature rollouts across the network security stack.

2. Observability Framework Engineering

  • Full-Stack Development:Architect and develop a custom framework (front-end and back-end) to provide a "single pane of glass" for infrastructure health.

  • Inventory & Integration:Build automated integrations with external data sources (CMDB, IPAM, etc.) to maintain a real-time, dynamic inventory of all network assets and security nodes.

  • Telemetry Logic:Design custom logic to ingest and visualize telemetry from ISE, WAC, and Palo Alto using APIs, SNMP, and Syslog.

3. Operational Excellence & Visibility

  • Technical Subject Matter Expertise:Serve as the lead engineer for complex network security escalations, providing root-cause analysis and implementing long-term, automated architectural fixes.

  • Security Observability:Develop dashboards and reporting to provide real-time visibility into the "connected landscape," identifying insecure nodes or unauthorized devices before they can affect the network.

  • Automation & Orchestration:Manage security policies as code while continuously improving automation workflowsand cross-platform orchestrationto eliminate manual friction, reduce operational overhead, and ensure consistent, high-speed security enforcement.

  • Self-Service & Enablement:Design and build self-service capabilitiesthat empower internal teams to consume network security controls autonomously and securely.

Qualifications

Education / Experience

  • Educational Background:Bachelor’s degree in Computer Science, Software Engineering, Information Security, or a related technical field.

  • Network Access Control Mastery:3+ years of hands-on experience in designing, implementing, and managing enterprise-grade NAC solutions, specifically Cisco ISE.

  • Perimeter & Inspection Expertise:Proven track record in configuring and maintaining Palo Alto Next-Generation Firewalls (NGFW), including SSL decryption and threat prevention.

  • Automation Engineering:Proven experience using Ansible, Terraform, or Pythonto manage network security infrastructure at scale.

  • Large-Scale Infrastructure:Experience managing security controls in complex, global environments involving thousands of diverse device profiles (IoT, Medical, Corporate).

  • Regulated Industry:Experience working in highly regulated environments (e.g., Pharmaceuticals, Healthcare, or Finance) is a significant plus.

Technical Skills

  • Cisco ISE Specialist:Expert-level knowledge of Cisco ISE, including hands-on experience with TrustSec, Dot1x, MAB, and Profiling.

  • Coding & Integration:Strong scripting skills in Python, PowerShell, or Bashto develop self-service tools and custom API integrations between security platforms. API integrations between security platforms.

  • API & Integration:Deep experience with REST APIs for integrating security platforms with external information sources.

  • Segmentation Technologies:Proficiency in network virtualization and segmentation techniques (such as TrustSec, SGTs, or VRFs) applied to security use cases.

  • Palo Alto Mastery:Proven track record in deploying and troubleshooting Palo Alto Firewallsin complex HA environments (Active/Active and Active/Passive).

  • Network Foundations:Deep understanding of RADIUS, TACACS+, and core routing/switching as they relate to security enforcement.

  • Monitoring Stack:Advanced knowledge of LogicMonitor, Splunk, or similar tools, specifically for creating custom DataSources and Dashboards.

  • Architectural Mindset:Ability to design "Defense in Depth" flows that connect device identity to granular network permissions.

  • Skills below will be considered a plus:

  • Infrastructure as Code (IaC):Proficiency in Terraformand GitHubto design and manage reproducible, version-controlled network security configurations.

  • Engineering & Orchestration:Proven ability to build CI/CD pipelinesand automated workflows that streamline cross-platform security operations and eliminate manual friction.

  • Enterprise Networking:Solid foundation in enterprise networking (L2/L3), including advanced knowledge of routing protocols (BGP, OSPF) and switching (VLANs, VXLAN) to ensure seamless security policy integration.

Leadership Skills

  • Communication:Strong ability to build trust with network and infrastructure experts and explain complex security policy concepts to non-technical stakeholders.

  • Innovation & Curiosity:A relentless passion for staying ahead of threat actors by researching emerging network security trends and automated enforcement techniques.

  • Thriving in Ambiguity:Ability to navigate global complexity and drive clarity when translating high-level security requirements into functional network policies.

  • Self-Starter:Proven ability to manage technical workstreams from concept to production with minimal supervision, taking full ownership of the NAC product lifecycle.

Additional Qualifications

  • Demonstrated ability to mentor colleagues with less experience and provide guidance on cybersecurity best practices and analysis techniques

  • Strong facilitation, communication, and conflict resolution skills to ensure alignment across multiple product squads and complex stakeholder networks

  • Demonstrated interpersonal, collaborative and commitment to operational excellence skills.

Who we are

A healthier future drives us to innovate. Together, more than 100’000 employees across the globe are dedicated to advance science, ensuring everyone has access to healthcare today and for generations to come. Our efforts result in more than 26 million people treated with our medicines and over 30 billion tests conducted using our Diagnostics products. We empower each other to explore new possibilities, foster creativity, and keep our ambitions high, so we can deliver life-changing healthcare solutions that make a global impact.

Let’s build a healthier future, together.

Roche is an Equal Opportunity Employer.

Free account
Stop reading job ads. Get the ones that fit.
One free account turns this page into a shortlist built around your stack, your level and your pay.
Match on every job. Stack, seniority, pay and location, scored against your profile.
406,377 open roles. Read straight off company career pages, refreshed every day.
Unlimited applications. Every one you send is tracked in one place, on-site or on a company board.
3 tailored CVs a month. Rewritten for the exact job you are applying to. Included free.
Create a free account
Free forever. No card. Under a minute.

Your match

How well do you fit this role?
Two answers are enough for a real match. No account needed.
Check my fit
Answers stay in this browser until you create an account.

Recommended for you based on this role

Similar stack
Same company
Madrid
$24k – $63k per year (Estimated) • In office • 5+ years exp • Bachelor's Degree • Bengaluru
C#
JavaScript
SQL
TypeScript
C#
ASP.NET Core
Entity Framework Core
xUnit
Databases
Apache Kafka
ElasticSearch
Kafka
Microsoft Fabric
Redis
Redpanda
Frontend
Angular
React.js
Mobile
MVVM
DevOps
Amazon CloudWatch
Amazon EC2
Amazon S3
AWS
AWS Lambda
Azure
Azure DevOps
Bitbucket
Docker
Git
GitHub
Kubernetes
Cybersecurity
HIPAA
Analytics
Power BI
IoT
Matter
QA
Playwright
Apply
$68k – $158k per year (Estimated) • Remote • 3+ years exp
PowerShell
Python
DevOps
AppDynamics
AWS
Azure
Datadog
Docker
GCP
Incident Management
Kubernetes
New Relic
PagerDuty
SLI/SLO/SLA
Cybersecurity
HIPAA
Management
Jira
ServiceNow
Apply
Remote/Hybrid • 5+ years exp
Bash
PowerShell
Python
DevOps
Amazon EKS
AWS
Azure
CI/CD
CloudFormation
FinOps
GCP
IAM
Kubernetes
Terraform
Windows Server
Cybersecurity
CIS Benchmarks
FedRAMP
HIPAA
Least Privilege
SOC 2
Apply
$99k – $132k per year • In office • Full-Time • Heilbronn
Bash
PowerShell
Python
Apply
In office • 3+ years exp • PhD
DevOps
Ansible
Configuration Management
etcd
Grafana
kubectl
Kubernetes
OpenShift
Prometheus
Red Hat
Apply
$27k – $80k per year (Estimated) • Remote/Hybrid • Full-Time • 3+ years exp • Master's Degree • Madrid
Bash
PowerShell
Python
AI/ML
AI Agents
Model Context Protocol
DevOps
Ansible
CI/CD
Git
Jenkins
VMWare
GitHub
Apply
In office • Full-Time • Hyderabad
Apex
Apex
Lightning Web Components
MuleSoft
AI/ML
Agentforce
AI Agents
LLM Guardrails
DevOps
CI/CD
Kubernetes
Cybersecurity
Threat Modeling
Apply
In office • Full-Time • Bachelor's Degree • Hyderabad
JavaScript
Python
SQL
TypeScript
Databases
Apache Kafka
DynamoDB
Kafka
PostgreSQL
Snowflake
AI/ML
AI Agents
AWS Bedrock
Embeddings
LangChain
LangGraph
LangSmith
LLM
RAG
Semantic Search
Semantic Search
Frontend
GraphQL
DevOps
Amazon CloudWatch
Amazon EKS
Amazon EventBridge
Amazon Kinesis
Amazon S3
API Gateway
AWS
AWS CDK
AWS Lambda
AWS Step Functions
CI/CD
CloudFormation
Datadog
Docker
FinOps
GitHub
GitHub Actions
Grafana
Helm
IAM
Kubernetes
Rest API
Terraform
Vector
Cybersecurity
Threat Modeling
Apply
In office • Internship • Petaling Jaya
DevOps
SLI/SLO/SLA
Apply
Inventory Analyst 3 days ago
In office • Full-Time • Johannesburg
ABAP
ABAP
SAP IDoc
Apply
$60k – $90k per year • Equity • Remote • Full-Time • 3+ years exp • Madrid
C++
JavaScript
Node JS
Python
Rust
Databases
PostgreSQL
Frontend
WebAssembly
DevOps
GitHub
KVM
Xen
Apply
Remote • 7+ years exp • Madrid
DevOps
Azure
Apply
$57k – $103k per year (Estimated) • Remote • 5+ years exp • Madrid
DevOps
Azure
Apply
Controller de Servicos 10 hours ago
Remote • Madrid
DevOps
Azure
Analytics
Power BI
Apply
Remote/Hybrid • Full-Time • Bachelor's Degree • Madrid
Apply
See all jobs
This is one of many
406,377 more open roles from verified company boards, updated every day.