Jobs Companies Roche Cybersecurity Engineer for Edge Network Security

Über diese Cybersecurity Engineer for Edge Network Security Stelle bei Roche

Roche · Vor Ort · Madrid

At Roche you can show up as yourself, embraced for the unique qualities you bring. Our culture encourages personal expression, open dialogue, and genuine connections,  where you are valued, accepted and respected for who you are, allowing you to thrive both personally and professionally. This is how we aim to prevent, stop and cure diseases and ensure everyone has access to healthcare today and for generations to come. Join Roche, where every voice matters.

The Position

Description of the area

The Network & Perimeter Security product makes Roche’s connectivity accessible and secure through actionable, policy-driven processes. The capabilities we provide enable Roche to identify, inspect, and mitigate network-based risks, manage regulatory compliance, and oversee egress/ingress traffic across all layers. Our solutions are primarily instantiated through leading-edge security platforms and automated orchestration. We work closely with Cloud, Infrastructure, and Incident Response teams to provide enterprise visibility into Roche’s network security posture.

You’ll be working within the Network Security Product area. This area is accountable for the end-to-end delivery of solutions—designing, building, and maintaining the technologies that protect Roche networks and the Internet, whether on-prem or cloud-based. This includes continuous improvement of capabilities like Internet Security Stack, DDoS Protection, Site-to-Site Connectivity (VPN), Network Access Control and Deep Packet Inspection to stay ahead of an ever-evolving threat landscape.

Job description 

As a Senior Cybersecurity Engineer (Edge Defense), you will play a pivotal role in the end-to-end lifecycle of our perimeter and cloud security products. Your primary focus will be the global engineering, adoption, and optimization of our Edge security stack, including Next-Generation Firewalls (NGFW), DDoS mitigation, and Zero Trust Network Access (ZTNA). You are a technical "implementer" responsible for designing robust, high-availability architectures that protect our global network from external threats while enabling secure, seamless access to multi-cloud environments. By leveraging an "Automation-First" mindset, you will transform traditional perimeter controls into scalable, code-driven security services, ensuring Roche’s digital boundaries remain resilient in an evolving threat landscape.

Job responsibilities

1. Edge Architecture & Engineering

  • Perimeter Defense Mastery: Lead the end-to-end deployment, configuration, and maintenance of Next-Generation Firewalls (Palo Alto, Fortinet), ensuring high availability (Active/Active & Active/Passive) and optimal inspection performance across global entry points.

  • Zero Trust Transition: Architect and implement ZTNA solutions to move beyond legacy VPNs, focusing on granular, application-level access and identity-aware security policies.

  • Multi-Cloud Network Security: Engineer and manage cloud-native security controls within AWS, Azure, and GCP, ensuring consistent security posture across hybrid and multi-cloud environments.

  • DDoS & Threat Mitigation: Design and refine DDoS protection strategies and automated threat prevention policies (SSL decryption, IPS/IDS) to shield critical infrastructure from sophisticated external attacks.

2. Product Lifecycle & Evolution

  • Lifecycle Governance: Oversee the delivery of Edge solutions from initial design through build, global rollout, and continuous optimization, ensuring that all security controls are reliable, scalable, and documented.

  • Edge Innovation: Proactively identify emerging trends in Edge computing and SASE (Secure Access Service Edge) to inform the product roadmap and maintain a competitive advantage in network defense.

3. Operational Excellence & Visibility

  • Technical Subject Matter Expertise: Serve as the lead engineer for complex network security escalations, performing deep-packet analysis and root-cause investigations to implement long-term architectural fixes.

  • Security Observability: Develop advanced monitoring dashboards and telemetry to provide real-time visibility into edge traffic patterns, attack surfaces, and the health of the security stack.

  • Automation & Orchestration: Manage security policies as code while continuously improving automation workflows and cross-platform orchestration to  eliminate manual friction, reduce operational overhead, and ensure consistent, high-speed security enforcement.

  • Self-Service & Enablement: Build and maintain automated workflows and APIs that allow internal dev teams to consume edge security services (e.g., automated firewall rule requests) autonomously and securely.

  • On-Call Readiness: Available for on-call support on a rotating schedule to ensure the continuous availability and integrity of global edge security services.

Qualifications

Education / Experience

  • Educational Background: Bachelor’s degree in Computer Science, Software Engineering, Information Security, or a related technical field.

  • Perimeter Security Mastery: 5+ years of hands-on experience in designing and managing enterprise-grade Firewall environments (specifically Palo Alto and/or Fortinet).

  • Cloud Security Expertise: Proven track record of implementing network security controls in at least two major cloud providers (AWS, Azure, or GCP).

  • Perimeter & Inspection Expertise: Proven track record in configuring and maintaining Palo Alto Next-Generation Firewalls (NGFW), including TLS inspection, User identification, WildFire, Threat Prevention, URL Filtering and GlobalProtect.

  • Automation Engineering: Proven experience using Ansible, Terraform, or Python to manage network security infrastructure at scale.

  • Large-Scale Infrastructure: Experience managing security controls in complex, global environments involving thousands of diverse device profiles (IoT, Medical, Corporate).

  • Regulated Industry: Experience working in highly regulated environments (e.g., Pharmaceuticals, Healthcare, or Finance) is a significant plus.

Technical Skills

  • NGFW Expert: Expert-level knowledge of Palo Alto and/or Fortinet platforms, including advanced threat prevention, SSL decryption, and high-availability design.

  • DDoS Mitigation: Experience managing specialized DDoS protection services (e.g., Akamai, Cloudflare, or F5).

  • ZTNA & Remote Access: Proficiency in modern Zero Trust architectures and SASE frameworks (e.g., Zscaler, Prisma Access).

  • Multi-Cloud Networking: Strong understanding of cloud networking components (VPCs, VNETs, Transit Gateways, Cloud Firewalls).

  • Network Foundations: Deep understanding of core protocols (BGP, OSPF, DNS, TLS/SSL) and how they intersect with security enforcement.

Skills below will be considered a plus:

  • Vendor certifications: Fortinet NSE or Palo Alto Networks PCNSA

  • PCNSE or Cisco CCNP Security

  • Cybersecurity certification: CISSP

  • Infrastructure as Code (IaC): Proficiency in Terraform and GitHub to maintain version-controlled, reproducible security configurations.

  • Scripting & Integration: Strong skills in Python or Go to build custom API integrations between security platforms and internal orchestration tools.

  • DDoS Mitigation: Experience managing specialized DDoS protection services (e.g., Akamai, Cloudflare, or F5).

  • Governance Frameworks: Familiarity with NIST, ISO 27001, and FAIR data principles.

Leadership Skills

  • Communication: Strong ability to build trust with network and infrastructure experts and explain complex security policy concepts to non-technical stakeholders.

  • Innovation & Curiosity: A relentless passion for staying ahead of threat actors by researching emerging network security trends and automated enforcement techniques.

  • Thriving in Ambiguity: Ability to navigate global complexity and drive clarity when translating high-level security requirements into functional network policies.

  • Self-Starter: Proven ability to manage technical workstreams from concept to production with minimal supervision, taking full ownership of the Edge Defense product lifecycle.

Additional Qualifications

  • Demonstrated ability to mentor colleagues with less experience and provide guidance on cybersecurity best practices and analysis techniques

  • Strong facilitation, communication, and conflict resolution skills to ensure alignment across multiple product squads and complex stakeholder networks

  • Demonstrated interpersonal, collaborative and commitment to operational excellence skills

 

 

Who we are

A healthier future drives us to innovate. Together, more than 100’000 employees across the globe are dedicated to advance science, ensuring everyone has access to healthcare today and for generations to come. Our efforts result in more than 26 million people treated with our medicines and over 30 billion tests conducted using our Diagnostics products. We empower each other to explore new possibilities, foster creativity, and keep our ambitions high, so we can deliver life-changing healthcare solutions that make a global impact.


Let’s build a healthier future, together.

Roche is an Equal Opportunity Employer.

Bereit, sich bei Roche zu bewerben?
Bei Roche bewerben

Über Roche

We believe it’s urgent to deliver medical solutions right now – even as we develop innovations for the future. We are passionate about transforming patients’ lives. We are courageous in both decision and action. And we believe that good business means a better world. That is why we come to work each day. We commit ourselves to scientific rigor, unassailable ethics, and access to medical innovations for all. We do this today to build a better tomorrow. We are proud of who we are, what we do, and how we do it. We are many, working as one across functions, across companies, and across the world. We are Roche.

Alle Jobs bei Roche ansehen →

Ähnliche Jobs

OneTrust
Senior Information Security GRC Analyst
OneTrust
⚡ Früh bewerben Madrid, Spain Vor Ort
● Neu 👁 Gesehen ✓ Beworben vor 2 Tg.
Accenture
CyberSecurity Analyst / Consultant 22301 - continuidad de negocio
Accenture
⚡ Früh bewerben Madrid Vor Ort
● Neu 👁 Gesehen ✓ Beworben vor 3 Tg.
Roche
Expert Security Engineer - Manufacturing Cybersecurity
Roche
⚡ Früh bewerben Madrid Vor Ort
● Neu 👁 Gesehen ✓ Beworben vor 3 Wo.
BA
Cybersecurity Incident Senior Analyst
Babel
⚡ Früh bewerben MADRID Vor Ort
● Neu 👁 Gesehen ✓ Beworben vor 4 Wo.
Roche
Cybersecurity Engineer - Monitoring & Incident Response
Roche
⚡ Früh bewerben Madrid Vor Ort
● Neu 👁 Gesehen ✓ Beworben vor 1 Mon.
Roche
Cybersecurity Analyst - RDT Security Platforms
Roche
⚡ Früh bewerben Madrid Vor Ort
● Neu 👁 Gesehen ✓ Beworben vor 1 Mon.
Accenture
Analyst IT Cybersecurity - AWS Cloud
Accenture
⚡ Früh bewerben Madrid, Torre Chamartin Vor Ort
● Neu 👁 Gesehen ✓ Beworben vor 1 Mon.
SA
Senior Cybersecurity Operations Engineer - ODS
Santander
⚡ Früh bewerben Madrid Hybrid
● Neu 👁 Gesehen ✓ Beworben vor 1 Mon.
MA
Oliver Wyman Vector - DevOps Engineer (AWS & Cybersecurity)
Marsh
⚡ Früh bewerben Atlanta - Hartsfield Vor Ort $90,000–$115,000
● Neu 👁 Gesehen ✓ Beworben vor 1 Std.

Registrieren für Vorschläge, die auf die von Ihnen geöffneten Jobs und gespeicherten Suchen zugeschnitten sind.

Mehr Jobs bei Roche

Alle Jobs bei Roche ansehen →

Jetzt bewerben
🤖

Moment — langsam

JobsRadar wurde für echte Menschen gebaut, die eine schwere Zeit bei der Jobsuche haben — nicht für automatisierte Anfragen. Sie klicken viel zu schnell und sind jetzt vorübergehend blockiert.

Kommen Sie später wieder. Wenn Sie wirklich auf Jobsuche sind, stehen wir hinter Ihnen — verhalten Sie sich einfach wie ein Mensch.

Catch your next role the second it’s posted.

Create a free account and we’ll watch the boards for you — the instant a job matches your search, it lands in your inbox or Telegram. No digging, no refreshing.

Create free account

Free forever · takes 30 seconds · already have one?

Verschaffe dir einen Vorsprung bei der Jobsuche.

Tritt unserem Telegram-Kanal bei für das, was dir hilft, die Stelle zu bekommen — Gehaltsbenchmarks, den wöchentlichen Marktpuls und neue Feature-Drops. Kein Spam, nur Signal.

Dem Kanal beitreten — kostenlos