Cybersecurity Engineer for Network Security observability (Madrid)

Cybersecurity Engineer for Network Security observability (Madrid)

04 ago
|
Roche Holding
|
Madrid

04 ago

Roche Holding

Madrid

ppBei Roche kannst du ganz du selbst sein und wirst für deine einzigartigen Qualitäten geschätzt. Unsere Kultur fördert persönlichen Ausdruck, offenen Dialog und echte Verbindungen. Hier wirst du für das, was du bist, wertgeschätzt, akzeptiert und respektiert. Dies schafft ein Umfeld, in dem du sowohl persönlich als auch beruflich wachsen kannst. Gemeinsam wollen wir Krankheiten vorbeugen, stoppen und heilen und sicherstellen, dass jeder Zugang zur Gesundheitsversorgung hat – heute und in Zukunft. Werde Teil von Roche, wo jede Stimme zählt. /p h3Die Position /h3 pThe bNetwork Perimeter Security /b product makes Roche’s connectivity accessible and secure through actionable, policy-driven processes. The capabilities we provide enable Roche to identify, inspect, and mitigate network-based risks, manage regulatory compliance, and oversee egress/ingress traffic across all layers. Our solutions are primarily instantiated through leading-edge security platforms and automated orchestration. We work closely with Cloud, Infrastructure, and Incident Response teams to provide enterprise visibility into Roche’s network security posture. /p pYou’ll be working within the bNetwork Security Product /b area. This area is accountable for the end-to-end delivery of solutions—designing, building, and maintaining the technologies that protect Roche networks and the Internet, whether on-prem or cloud-based. This includes continuous improvement of capabilities like Internet Security Stack, bDDoS Protection /b, bSite-to-Site Connectivity (VPN) /b, Network Access Control and bDeep Packet Inspection /b to stay ahead of an ever-evolving threat landscape. /p h3Job Description /h3 pAs the Lead for Network Security Infrastructure Observability, you will be the primary architect and engineer responsible for the health, availability, and performance of our global security infrastructure. This is a hands‑on technical leadership role that requires a solid foundation in Network Security engineering. You will barchitect, design, build, and operate /b the monitoring frameworks that ensure our security platforms (Firewalls, NAC, ZTNA) are running at peak operational efficiency. While your focus is on Infrastructure Reliability, success in this role depends on your deep technical understanding of how security controls—such as packet inspection, encryption, and access policies—impact system performance. By bridging the gap between security hardware/software (Palo Alto, Fortinet, ISE) and modern observability toolchains (LogicMonitor, Python, IaC), you will ensure that the organization’s security "engine" is always visible, resilient, and perfectly tuned. /p h3Job Responsibilities /h3 h31. Infrastructure Architecture, Design Build /h3 ul lipSecurity-Aware Monitoring Architecture: Architect and design a global visibility framework for understanding the key performance, health, and throughput indicators of core security appliances across services such as Edge Firewalls, Network Access Control (NAC), DDoS Mitigation, Network Authentication, Internal Network Segmentation, and VPNs. /p /li lipObservability Engineering: Build and deploy the observability toolchain specifically optimized to monitor the hardware and virtualized instances of Palo Alto, Fortinet, and Cisco ISE.



/p /li lipLogicMonitor Development: Hands‑on creation and tuning of DataSources and ConfigSources to capture hardware-level security telemetry (CPU/Data Plane utilization, Session counts, Tunnel health, and HA synchronization). /p /li lipService Health Dashboarding: Design and build real‑time operational dashboards that provide a clear view of the health, performance, and compliance status of the general security infrastructure. /p /li /ul h32. Infrastructure Operations Evolution /h3 ul lipGlobal Service Operations: Operate the global monitoring environment, ensuring the continuous health of the observability stack across diverse network segments and security zones. /p /li lipInfrastructure-as-Code (IaC): Leverage APIs and automation (Python/GitLab) to automate the provisioning of monitoring for new security devices, ensuring a "security-first" approach to visibility. /p /li lipCapacity Performance Management: Analyze long‑term infrastructure trends to provide data‑driven recommendations for capacity scaling, especially as it relates to resource‑intensive security features like SSL Decryption and IPS. /p /li lipReliability Alerting: Establish and tune proactive alert thresholds that identify hardware or software degradation within the security stack before it impacts service delivery. /p /li /ul h33. Operational Excellence System Visibility /h3 ul lipInfrastructure Diagnostics: Use tools like Wireshark and SNMP Walk to troubleshoot complex connectivity issues between the observability platform and security devices, resolving MIB/OID mismatches in secured management planes. /p /li lipTechnical Reliability Documentation: Develop comprehensive runbooks and technical guides for the ongoing operation, maintenance, and troubleshooting of the monitoring ecosystem. /p /li lipCollaborative Engineering: Partner with Network and Security Engineering squads to align monitoring setups with the deployment of new architectural security standards. /p /li lipProactive Maintenance: Proactively identify and resolve potential monitoring gaps by staying updated on hardware telemetry updates and the latest secure SNMP (v3) implementation standards. /p /li /ul h3Qualifications /h3 h3bEducation / Experience /b /h3 ul lipSolid Security Foundation: 3-4 years of experience in Network Security Engineering or Infrastructure Reliability, with a deep understanding of firewall architectures and network access control systems. /p /li lipProfessional Experience: Proven track record of designing and operating monitoring solutions for large‑scale enterprise security infrastructure. /p /li lipScale Scope: Proven experience in architecting and operating solutions at a global scale. /p /li lipEducational Background: Bachelor’s degree in Computer Science, Cyber Security, Information Technology, or a related technical field.



/p /li /ul h3bTechnical Skills /b /h3 ul lipSecurity Infrastructure Mastery: Expert-level knowledge of the operational mechanics and hardware architectures of Palo Alto Firewalls, Fortinet Firewalls, and Cisco ISE. /p /li lipNetworking Security Foundations: Strong foundation in TCP/IP, UDP, and the OSI model, with a specific focus on how security protocols (SSL/TLS, IPsec, RADIUS/TACACS+) interact with management and data planes. /p /li lipObservability Stack: Mastery of LogicMonitor (Collectors, DataSources) and experience with broader toolchains like Splunk, ELK, or Grafana. /p /li lipNetwork Protocols: Expert knowledge of SNMP (v2c/v3), MIBs, OIDs, and the ability to interpret security-specific device telemetry. /p /li lipDevOps Automation: Proven ability to automate infrastructure tasks using Python, Groovy, GitLab, and GitLab-CI. /p /li /ul pSkills below will be considered a plus: /p ul lipCertification: Professional certifications in Network Security (e.g., PCNSE, CCNP Security) or Monitoring (LogicMonitor Certified Professional). /p /li lipCloud Infrastructure Monitoring: Knowledge of monitoring virtualized security appliances in AWS, Azure, or GCP. /p /li lipForensic Diagnostics: Proficiency in Wireshark for analyzing management‑plane traffic and SNMP communication within secured networks. /p /li /ul h3bLeadership Skills /b /h3 ul lipCommunication: Strong ability to build trust with network and infrastructure experts and explain complex security policy concepts to non-technical stakeholders. /p /li lipInnovation Curiosity: A relentless passion for staying ahead of threat actors by researching emerging network security trends and automated enforcement techniques. /p /li lipThriving in Ambiguity: Ability to navigate global complexity and drive clarity when translating high‑level security requirements into functional network policies. /p /li lipSelf-Starter: Proven ability to manage technical workstreams from concept to production with minimal supervision, taking full ownership of the Edge Defense product lifecycle. /p /li /ul h3Additional Qualifications /h3 ul lipDemonstrated ability to mentor colleagues with less experience and provide guidance on cybersecurity best practices and analysis techniques. /p /li lipStrong facilitation, communication, and conflict resolution skills to ensure alignment across multiple product squads and complex stakeholder networks. /p /li lipDemonstrated interpersonal, collaborative and commitment to operational excellence skills. /p /li /ul h3Wer wir sind /h3 pEine gesündere Zukunft treibt uns zur Innovation an. Mehr als 100.000 Mitarbeiter weltweit arbeiten gemeinsam daran, wissenschaftliche Fortschritte zu erzielen und sicherzustellen, dass jeder Zugang zur Gesundheitsversorgung hat – heute und für zukünftige Generationen. Durch unser Engagement werden über 26 Millionen Menschen mit unseren Medikamenten behandelt und mehr als 30 Milliarden Tests mit unseren Diagnostik-Produkten durchgeführt. Wir ermutigen uns gegenseitig, neue Möglichkeiten zu erkunden, Kreativität zu fördern und hohe Ziele zu setzen, um lebensverändernde Gesundheitslösungen zu liefern. /p pGemeinsam können wir eine gesündere Zukunft gestalten. /p pbRoche ist ein Arbeitgeber, der die Chancengleichheit fördert. /b /p /p #J-18808-Ljbffr

📌 Cybersecurity Engineer for Network Security observability (Madrid)
🏢 Roche Holding
📍 Madrid

Postulate a este anuncio

Muestra tus habilidades a la empresa, rellenar el formulario y deja un toque personal en la carta, ayudará el reclutador en la elección del candidato.

Suscribete a esta alerta:

Recibe por email las nuevas ofertas de trabajo para: cybersecurity engineer for network security observability (madrid) / madrid

Suscribete a esta alerta:

Recibe por email las nuevas ofertas de trabajo para: cybersecurity engineer for network security observability (madrid) / madrid