Jobs Companies Roche Senior Identity And Access Management Engineer - Cloud Environment

Über diese Senior Identity And Access Management Engineer - Cloud Environment Stelle bei Roche

Roche · Vor Ort · Madrid

At Roche you can show up as yourself, embraced for the unique qualities you bring. Our culture encourages personal expression, open dialogue, and genuine connections,  where you are valued, accepted and respected for who you are, allowing you to thrive both personally and professionally. This is how we aim to prevent, stop and cure diseases and ensure everyone has access to healthcare today and for generations to come. Join Roche, where every voice matters.

The Position

Job description

The Security and Cybersecurity Analyst serves as a trusted advisor and independent leader who drives the analysis of moderately complex cybersecurity incidents and technical problems

By bridging deep business and technical understanding, you will manage end-to-end security analysis tasks across multiple products within a domain

You will shape stakeholder perspectives, champion accountability by taking on security incident lead or project owner roles, and foster continuous improvement in security operations and best practices

Description of the area

The Identity Management Support Team manages and operates the solutions and components used to provide customers with Directory and Identity Management Services using SailPoint. We are part of a global Roche Digital Technology group (RDT).

Job Responsibilities

In this role, you are mainly responsible for the multi-cloud Identity Management environment, focusing specifically on Azure and Google Cloud Platform (GCP), while maintaining consistency with AWS. This includes the design of new solutions, consultancy, maintenance, performance, tactical lifecycle management and continuous improvement of the underlying technologies.

Scope

  • Strong background in IAM concepts at design level and evolution in Cloud environments, Azure and/or GCP.

  • Contributes to the design of new solutions based on SailPoint and PingFederate, AD, Privilege Access Management. 

  • Design and implement Centralized Role-Based Access Control (RBAC) based on Cloud Adoption Framework (CAF) principles.

  • Access Governance and Controls: Enforce strong security controls across cloud environments, including Multi-Factor Authentication (MFA) and Identity Protection. Implement Least Privilege policies, often involving custom roles and organizational-level controls. Implement IAM Deny Policies to strictly block high-risk actions, ensuring separation of duties

  • Automation and Infrastructure-as-Code (IaC): Drive the core value of "Automate as much as possible". Design and implement IAM infrastructure using IaC, leveraging Terraform. For Azure, this mandates IaC using Terraform and Azure Verified Modules (AVM) with CI/CD pipelines in GitLab

  • Privileged Access Management (PAM): Design and support Just-in-Time (JIT) Access mechanisms, ensuring no standing privileges for administrators, using tools like Cyberark for Just-in-Time access

  • Operational Excellence: Act as an expert in the release management activities, providing 2nd and 3rd level support for the Identity Management Infrastructure. Proactively monitor systems for performance, availability, and capacity management

  • Actively focus on self-development in creating actionable plans to improve.

Stakeholder Management 

  • Consultancy and Collaboration: Act as a mentor and reference, working closely with stakeholders to provide the right level of consultancy. Ensure regular interactions with the Managed Service Provider

  • Acts as a strategic influencer, defining and driving stakeholder engagement strategies for complex initiatives, facilitating workshops, resolving conflicts, and proactively shaping stakeholder perspectives to align with project goals

Impact/Strategy 

  • Demonstrates strong and consistent performance across diverse products, with an impact that typically extends to a specific product, initiative, or cluster

  • Translates requirements into strategic implementation plans that align with overall business objectives, and takes a proactive role in shaping team processes, often contributing to Communities of Practice (CoPs)

Complexity 

  • Manages business analysis activities on more complex projects or across multiple products within a domain

  • Capable of handling ambiguous requirements, navigating intricate stakeholder environments, and evaluating solution impacts considering both immediate and longer-term implications within the domain

Business/Technical ability 

  • Demonstrates a strong understanding of the business domain, related technologies, and their interdependencies

  • Can independently apply tools, principles, concepts, and techniques related to requirements, data, usability, and process analysis, effectively managing interconnections to improve overall efficiency and effectiveness

Qualifications

Education / Experience

  • 5-7 years of experience working in a major global organization, preferably in a regulated industry and in providing solutions aligned with standards, security, validation, capacity and high availability.

  • Bachelor’s Degree in computer science, engineering or related discipline; or recognition of prior working experience which is equivalent. 

  • Industry accredited certification is desirable. Willingness to continually acquire and maintain the technical skills appropriate to the requirements of this position.

  • Demonstrated ability to effectively manage relationships with a diverse range of cross-functional stakeholders on medium to large-sized engagements, acting as a trusted advisor

  • Proven track record of championing accountability by example, such as successfully taking on security incident lead and/or security project owner roles

Technical Skills

  • Strong hands-on technical skills with an IT operations background. Expert knowledge on infrastructure technologies, business processes and applications with a focus on Sailpoint IQ Identity Governance and Access Identity Management technologies and PingFederate. 

Cloud Platform skills:

  • Expertise in GCP Identity and Access Management (IAM), including Identity Synchronization, Service Account binding/federation, and organizational policy enforcement.

  • Expertise in Azure IAM/RBAC, including implementing centralized RBAC designs, Azure Policy, and alignment with the Azure Cloud Adoption Framework (CAF).

  • Experience applying cloud governance principles (e.g., Azure Policy, IAM Deny Policies) to ensure consistent governance and security across multi-cloud workloads​

Automation and DevOps: 

  • Experience with Infrastructure-as-Code (IaC) tools, particularly Terraform, for platform building and management.

  • Experience implementing governance as code and integrating automated workflows via CI/CD pipelines (e.g., GitLab).

  • Strong understanding of Computer Systems Validation and working experience in a validated environment.

  • Good understanding of IT Security systems and landscape with in-depth knowledge of Directories, Identity Management and Privileged Access Management technologies.

  • Strong proficiency in independently applying tools, principles, and concepts related to requirements, data, usability, and process analysis within the security domain

  • Advanced analytical and logical reasoning skills to identify security patterns, threats, and discrepancies, driving comprehensive root cause analysis

  • Ability to analyze technology fit and propose effective, strategically aligned cybersecurity solutions and controls

Additional Qualifications

  • Proactive, collaborative and supportive approach when interacting with colleagues. 

  • Committed to operational excellence, with willingness to cross-train and to learn additional technical expertise.

  • Strong customer focus and a highly responsive service delivery and support ethic.

  • Adaptable to change in a large organization.

  • Excellent communication, negotiation and documentation skills. 

  • Proven interpersonal skills to interact effectively with individuals in multiple countries and in varying cultures.

  • Strong verbal and written English.

  • Demonstrated ability to mentor colleagues with less experience and provide guidance on cybersecurity best practices and analysis techniques

  • Proactive contribution to organizational development, including identifying process improvements and actively participating in Communities of Practice (CoPs)

  • Strong facilitation, communication, and conflict resolution skills to ensure alignment across multiple product squads and complex stakeholder networks

 

 

Who we are

A healthier future drives us to innovate. Together, more than 100’000 employees across the globe are dedicated to advance science, ensuring everyone has access to healthcare today and for generations to come. Our efforts result in more than 26 million people treated with our medicines and over 30 billion tests conducted using our Diagnostics products. We empower each other to explore new possibilities, foster creativity, and keep our ambitions high, so we can deliver life-changing healthcare solutions that make a global impact.


Let’s build a healthier future, together.

Roche is an Equal Opportunity Employer.

Bereit, sich bei Roche zu bewerben?
Bei Roche bewerben

Über Roche

We believe it’s urgent to deliver medical solutions right now – even as we develop innovations for the future. We are passionate about transforming patients’ lives. We are courageous in both decision and action. And we believe that good business means a better world. That is why we come to work each day. We commit ourselves to scientific rigor, unassailable ethics, and access to medical innovations for all. We do this today to build a better tomorrow. We are proud of who we are, what we do, and how we do it. We are many, working as one across functions, across companies, and across the world. We are Roche.

Alle Jobs bei Roche ansehen →

Ähnliche Jobs

Roche
实习医药信息顾问
Roche
⚡ Früh bewerben Shantou Vor Ort
● Neu 👁 Gesehen ✓ Beworben vor 20 Std.
Roche
实习医药信息顾问
Roche
⚡ Früh bewerben Haikou Vor Ort
● Neu 👁 Gesehen ✓ Beworben vor 20 Std.
Roche
Sr Applications Specialist 资深应用支持专员
Roche
⚡ Früh bewerben Guangzhou Vor Ort
● Neu 👁 Gesehen ✓ Beworben vor 20 Std.
Roche
资深客户专员 - 病理实验室产品线
Roche
⚡ Früh bewerben Guangzhou Vor Ort
● Neu 👁 Gesehen ✓ Beworben vor 20 Std.
Roche
治疗领域经理 - 消化道肿瘤治疗领域
Roche
⚡ Früh bewerben Shenyang Vor Ort
● Neu 👁 Gesehen ✓ Beworben vor 20 Std.
Roche
治疗领域经理 - 消化道肿瘤治疗领域
Roche
⚡ Früh bewerben Dalian Vor Ort
● Neu 👁 Gesehen ✓ Beworben vor 20 Std.
Roche
Area Customer Support Lead - Engineering 地区客户支持负责人 - 工程技术
Roche
⚡ Früh bewerben Lanzhou Vor Ort
● Neu 👁 Gesehen ✓ Beworben vor 20 Std.
Roche
Finance Enterprise Partner
Roche
⚡ Früh bewerben Taguig City Vor Ort
● Neu 👁 Gesehen ✓ Beworben vor 20 Std.
Roche
Service Engineer 维修服务工程师
Roche
⚡ Früh bewerben Guiyang Vor Ort
● Neu 👁 Gesehen ✓ Beworben vor 20 Std.

Registrieren für Vorschläge, die auf die von Ihnen geöffneten Jobs und gespeicherten Suchen zugeschnitten sind.

Mehr Jobs bei Roche

Alle Jobs bei Roche ansehen →

Jetzt bewerben
🤖

Moment — langsam

JobsRadar wurde für echte Menschen gebaut, die eine schwere Zeit bei der Jobsuche haben — nicht für automatisierte Anfragen. Sie klicken viel zu schnell und sind jetzt vorübergehend blockiert.

Kommen Sie später wieder. Wenn Sie wirklich auf Jobsuche sind, stehen wir hinter Ihnen — verhalten Sie sich einfach wie ein Mensch.

Catch your next role the second it’s posted.

Create a free account and we’ll watch the boards for you — the instant a job matches your search, it lands in your inbox or Telegram. No digging, no refreshing.

Create free account

Free forever · takes 30 seconds · already have one?

Verschaffe dir einen Vorsprung bei der Jobsuche.

Tritt unserem Telegram-Kanal bei für das, was dir hilft, die Stelle zu bekommen — Gehaltsbenchmarks, den wöchentlichen Marktpuls und neue Feature-Drops. Kein Spam, nur Signal.

Dem Kanal beitreten — kostenlos