04 ago
|
Roche Holding
|
Madrid
04 ago
Roche Holding
Madrid
ppChez Roche, vous pouvez être vous-même et être apprécié pour les qualités uniques que vous apportez. Notre culture encourage l'expression personnelle, le dialogue ouvert et les connexions authentiques, où vous êtes valorisé, accepté et respecté pour ce que vous êtes, vous permettant de prospérer tant personnellement que professionnellement. Voici comment nous visons à prévenir, arrêter et guérir les maladies et à garantir à chacun l'accès aux soins de santé aujourd'hui et pour les générations à venir. Rejoignez Roche, où chaque voix compte. /p h3La position /h3 pAs an Expert DevSecOps Engineer, acting as a Software Development Security Expert, you will sit at the intersection of software and security engineering. You are accountable for designing robust software development security frameworks, handling ambiguous security and compliance requirements, managing complex stakeholder landscapes, and mentoring junior engineers. You will also collaborate with the area architect in defining the long-term architecture for software engineering security solutions. /p h3bDescription of the area: /b /h3 pEngineering Excellence Experience (E3) enables engineers to explore, plan, design, code, build, test, and deploy software packages in a reliable, secure, automated, and consistent manner across our different business areas. This includes providing facilitated access to automated, composable infrastructure consumable through Infrastructure as Code (IaC) and APIs, both on-premises and in the public cloud. /p pWithin E3, you will join the Embedded Security Testing Team, which champions the integration of testing and security concepts throughout the software development lifecycle. Specifically, the Code Quality, Security, and Testing Engineering team combines best practices and modern solutions to ensure that all code generated is secure and of the highest quality. The team provides a range of DevSecOps components fit for diverse technical complexities, delivers Proofs of Concept (PoCs), and supports internal adoption both during and after implementation. /p h3bJob Responsibilities: /b /h3 h3Scope: /h3 ul lipProvides expert-level leadership and strategic guidance in DevSecOps area, including Threat Modelling, Code Quality, SAST, Secret Scanning, Software Composition Analysis, IaC Scanning, License Compliance, Dependency Management, Container Image Scanning, API Security and Container Runtime Scanner. /p /li lipParticipate in the definition of Software Security best practices, ensuring consistency, traceability,
and alignment with enterprise standards /p /li lipLeads DevSecOps efforts on strategic activities and provides guidance to less experienced members. /p /li /ul h3Problem Solving: /h3 ul lipLeads the analysis of complex and strategic business problems, defining the problem space and driving comprehensive root cause analysis that may span organizational boundaries /p /li lipWorks on unusually complex problems, provides highly innovative solutions, and applies expert-level analytical and logical reasoning to proactively identify strategic opportunities and risks /p /li /ul h3Stakeholder Management Strategic Influence: /h3 ul lipBuilds and maintains strong relationships with key stakeholders and cultivates collaboration across the organization /p /li lipElicits and analyzes complex stakeholder needs with expertise, and influences business stakeholders to inform and make the right decisions /p /li lipShapes strategy as a trusted advisor to leadership, acting as an influential partner and organizational trust builder /p /li lipRecommends and guides the implementation of optimal strategies, transitions, and future states, fostering a culture of strategic innovation and continuous improvement within their product line or domain /p /li /ul h3Leadership, Accountability Mentorship: /h3 ul lipEvaluates strategic solution alternatives through rigorous risk assessment and value analysis, ensuring key initiatives align with overall organizational objectives, and recommends optimal technology solutions to drive business transformation. /p /li lipIs accountable for deliverables on significant projects, ensuring alignment with strategic objectives, defining strategic solution scope, and managing complexity /p /li lipMentors colleagues, helps others develop expertise and skills, and provides guidance to other Experts /p /li lipActively contributes to organizational development, including showing leadership in Communities of Practice (CoPs). /p /li lipUnderstands and balances strict security compliances without slowing down developers. /p /li /ul h3bQualifications Experience: /b /h3 h3Required Technical Experience: /h3 ul lipEducation: Bachelor’s or Master’s degree in Computer Science, Software Engineering,
or a related technical field (or equivalent practical experience). /p /li lipDevSecOps Expertise: Minimum of 8-10+ years of progressive experience, including 3+ years of specialization in building DevSecOps frameworks from scratch. /p /li lipBe a hands‑on tools agnostic technical expert on the DevSecOps Enablement tools to support Product and Application teams in deploying and using DevSecOps Enablement tooling across SDLC, including but not limited to: SonarQube, GHAS, Sysdig, Snyk, IriusRisk, JFrog Xray, NowSecure, etc. /p /li lipDesign and implement automated security testing guardrails (SAST, SCA, Container scanning, etc.) directly into DevOps workflows to enable frictionless, secure software delivery. /p /li lipExperienced in self‑service DevOps platforms to automate security via templates for product team /p /li lipSolid understanding of supply chain security to secure software packages, libraries, container images, etc. via security tools, processes and automations. /p /li /ul h3Core Competencies Soft Skills: /h3 ul lipbAnalytical Thinking: Advanced logical reasoning skills to identify hidden software defects, quality risks, and architectural gaps. /b /p /li lipNavigating Ambiguity: Proven ability to manage business analysis activities on complex projects where requirements are highly fluid or loosely defined. /p /li lipStrategic Influencing: Exceptional communication skills with a track record of driving consensus among cross‑functional stakeholders (Product Owners, Developers, and Business Leads). /p /li lipSystems Thinking: Ability to manage interdependencies, handling the interconnections between various internal and external processes to improve overall delivery efficiency. /p /li /ul h3Qui nous sommes /h3 pUn avenir plus sain nous pousse à innover. Ensemble, plus de 100 000 employés à travers le monde sont dédiés à faire progresser la science et à garantir à chacun l'accès aux soins de santé aujourd'hui et pour les générations à venir. Nos efforts aboutissent à plus de 26 millions de personnes traitées avec nos médicaments et plus de 30 milliards de tests réalisés avec nos produits de Diagnostique. Nous nous encourageons mutuellement à explorer de nouvelles possibilités, à favoriser la créativité et à conserver nos grandes ambitions, afin de fournir des solutions de santé qui changent des vies et ont un impact mondial. /p pConstruisons ensemble un avenir plus sain. /p pbRoche est un employeur offrant l'équité en matière d'emploi. /b /p /p #J-18808-Ljbffr
📌 Expert DevSecOps Engineer (Expert Software Development Security Engineer) (Madrid)
🏢 Roche Holding
📍 Madrid