ph3Job Responsibilities /h3ulliDesign Architecture: Lead the high‑level and low‑level design (HLD/LLD) for global Cisco ISE deployments and Wired Access Control (WAC) strategies to ensure seamless, identity‑based security. /liliPalo Alto SME: Serve as the primary engineer for Palo Alto NGFW architectures, including advanced threat prevention, decryption, and secure egress/ingress traffic management. /liliContinuous Improvement: Proactively identify gaps in the current security posture and implement technical enhancements to NAC policies, SGT (TrustSec) propagation, and firewall rule‑sets. /liliBuild Implementation: Act as the lead implementer for complex global migrations and new feature rollouts across the network security stack. /liliObservability Framework Engineering. /liliFull‑Stack Development: Architect and develop a custom framework (front‑end and back‑end) to provide a "single pane of glass" for infrastructure health. /liliInventory Integration: Build automated integrations with external data sources (CMDB, IPAM, etc.) to maintain a real‑time, dynamic inventory of all network assets and security nodes. /liliTelemetry Logic: Design custom logic to ingest and visualize telemetry from ISE, WAC, and Palo Alto using APIs, SNMP, and Syslog. /liliOperational Excellence Visibility. /liliTechnical Subject Matter Expertise: Serve as the lead engineer for complex network security escalations, providing root‑cause analysis and implementing long‑term, automated architectural fixes. /liliSecurity Observability: Develop dashboards and reporting to provide real‑time visibility into the "connected landscape," identifying insecure nodes or unauthorized devices before they can affect the network. /liliAutomation Orchestration: Manage security policies as code while continuously improving automation workflows and cross‑platform orchestration to eliminate manual friction, reduce operational overhead, and ensure consistent, high‑speed security enforcement. /liliSelf‑Service Enablement: Design and build self‑service capabilities that empower internal teams to consume network security controls autonomously and securely. /li /ulh3Qualifications /h3ulliEducational Background:
Bachelor’s degree in Computer Science, Software Engineering, Information Security, or a related technical field. /liliNetwork Access Control Mastery: 3+ years of hands‑on experience in designing, implementing, and managing enterprise‑grade NAC solutions, specifically Cisco ISE. /liliPerimeter Inspection Expertise: Proven track record in configuring and maintaining Palo Alto Next‑Generation Firewalls (NGFW), including SSL decryption and threat prevention. /liliAutomation Engineering: Proven experience using Ansible, Terraform, or Python to manage network security infrastructure at scale. /liliLarge‑Scale Infrastructure: Experience managing security controls in complex, integral environments involving thousands of diverse device profiles (IoT, Medical, Corporate). /liliRegulated Industry: Experience working in highly regulated environments (e.g., Pharmaceuticals, Healthcare, or Finance) is a significant plus. /li /ulh3Technical Skills /h3ulliCisco ISE Specialist: Expert‑level knowledge of Cisco ISE, including hands‑on experience with TrustSec, Dot1x, MAB, and profiling. /liliCoding Integration: Strong scripting skills in Python, PowerShell, or Bash to develop self‑service tools and custom API integrations between security platforms. /liliAPI Integration: Deep experience with REST APIs for integrating security platforms with external information sources. /liliSegmentation Technologies: Proficiency in network virtualization and segmentation techniques (such as TrustSec, SGTs, or VRFs) applied to security use cases. /liliPalo Alto Mastery: Proven track record in deploying and troubleshooting Palo Alto Firewalls in complex HA environments (Active/Active and Active/Passive). /liliNetwork Foundations: Deep understanding of RADIUS, TACACS+,
and core routing/switching as they relate to security enforcement. /liliMonitoring Stack: Advanced knowledge of LogicMonitor, Splunk, or similar tools, specifically for creating custom DataSources and dashboards. /liliArchitectural Mindset: Ability to design "Defense in Depth" flows that connect device identity to granular network permissions. /liliSkills below will be considered a plus:ulliInfrastructure as Code (IaC): Proficiency in Terraform and GitHub to design and manage reproducible, version‑controlled network security configurations. /liliEngineering Orchestration: Proven ability to build CI/CD pipelines and automated workflows that streamline cross‑platform security operations and eliminate manual friction. /liliEnterprise Networking: Solid foundation in enterprise networking (L2/L3), including advanced knowledge of routing protocols (BGP, OSPF) and switching (VLANs, VXLAN) to ensure seamless security policy integration. /li /ul /li /ulh3Leadership Skills /h3ulliCommunication: Strong ability to build trust with network and infrastructure experts and explain complex security policy concepts to non‑technical stakeholders. /liliInnovation Curiosity: A relentless passion for staying ahead of threat actors by researching emerging network security trends and automated enforcement techniques. /liliThriving in Ambiguity: Ability to navigate global complexity and drive clarity when translating high‑level security requirements into functional network policies. /liliSelf‑Starter: Proven ability to manage technical workstreams from concept to production with minimal supervision, taking full ownership of the NAC product lifecycle. /li /ulh3Additional Qualifications /h3ulliDemonstrated ability to mentor colleagues with less experience and provide guidance on cybersecurity best practices and analysis techniques. /liliStrong facilitation, communication, and conflict resolution skills to ensure alignment across multiple product squads and complex stakeholder networks. /liliDemonstrated interpersonal, collaborative and commitment to operational excellence skills. /li /ulpbRoche is an Equal Opportunity Employer. /b /p /p #J-18808-Ljbffr
📌 Cybersecurity Engineer for Network Security (Madrid)
🏢 Roche
📍 Madrid