04 ago
|
F. Hoffmann-La Roche
|
Madrid
04 ago
F. Hoffmann-La Roche
Madrid
ph3Senior Cybersecurity Engineer (Network Security) /h3pThe Network Security product makes Roche’s connectivity accessible and secure through actionable, policy‑driven processes. The role focuses on designing, building, and maintaining the technologies that protect Roche networks and the Internet, whether on‑prem or cloud‑based. /ph3Responsibilities /h3ulliProduct Ownership and Technical LeadershipulliAct as the primary SME for Secure Access technologies and evaluate emerging tools. /liliDrive the long‑term technical roadmap for network access aligned with Roche’s Zero Trust strategy. /liliPartner with business units to translate high‑level security requirements into actionable, scalable initiatives and policies. /liliMentor junior engineers and foster continuous learning. /li /ul /liliIdentity‑Based Access and AuthenticationulliDesign, deploy, and maintain authentication solutions using protocols such as 802.1X, EAP‑TLS, EAP‑TEAP, RADIUS, TACACS+, SAML, and MFA. /liliIntegrate security platforms with enterprise IdPs to provide a seamless authentication flow. /liliArchitect highly available authentication services supporting Roche’s general workforce. /li /ul /liliNetwork Access Control (NAC) and SegmentationulliManage Cisco ISE deployments, including upgrades, capacity planning, and optimization. /liliDevelop endpoint profiling techniques to secure corporate, medical, and IoT devices. /liliImplement access control mechanisms such as Dot1x, MAB, Guest Access, and posture‑based authorization. /liliDesign and oversee TrustSec and SGT‑based micro‑segmentation. /li /ul /liliOperational Excellence and AutomationulliEscalate and analyze complex incidents to prevent recurrence. /liliMaintain observability,
monitoring, and reporting dashboards. /liliApply IaC principles and security automation to improve deployment speed and consistency. /liliBuild and optimize API‑driven integrations and self‑service capabilities. /li /ul /liliGlobal OperationsulliEnsure secure connectivity for thousands of endpoints across global regions. /liliCollaborate with distributed product squads and stakeholders to deliver integrated security solutions. /li /ul /li /ulh3Qualifications /h3ulliEducation / ExperienceulliBachelor’s degree in Computer Science, Software Engineering, Information Security, or a related technical field. /lili5+ years of hands‑on experience designing, implementing, and managing enterprise‑grade NAC solutions, especially Cisco ISE. /liliProven experience deploying and configuring Palo Alto NGFWs, including SSL decryption and threat prevention. /liliExperience managing security controls in large, global environments with diverse device profiles (IoT, medical, corporate). /liliExperience in highly regulated industries such as Pharmaceuticals, Healthcare, or Finance is a significant plus. /li /ul /liliTechnical SkillsulliExpert knowledge of Cisco ISE, TrustSec, Dot1x, MAB, profiling, guest portals, REST APIs, complex enterprise policies, EAP‑TLS, EAP‑TEAP, RADIUS, TACACS+.
/liliStrong understanding of PKI and certificate lifecycle management. /liliProficiency in network virtualization and segmentation techniques (TrustSec, SGTs, VRFs). /liliExperience troubleshooting Palo Alto Firewalls in HA environments. /liliArchitectural mindset: design Defense in Depth flows that connect device identity to granular network permissions. /li /ul /liliAutomation and EngineeringulliProficiency with Ansible/Terraform, Python, and IaC tools for managing network security infrastructure. /liliBuild CI/CD pipelines with Gitlab/GitHub and automate workflows across security platforms. /liliStrong scripting skills in Python, PowerShell, or Bash. /li /ul /liliEnterprise NetworkingulliSolid foundation in L2/L3 networking, routing protocols (BGP, OSPF), and switching (VLANs, VXLAN). /li /ul /liliLeadership and CommunicationulliExcellent stakeholder management and communication skills. /liliAbility to mentor junior engineers and drive operational excellence. /liliStrong facilitation, conflict resolution, and collaboration skills. /li /ul /liliDesirable SkillsulliTerraform, GitHub for IaC; network security automation through APIs. /liliExperience building self‑service tools and custom API integrations between security platforms. /li /ul /li /ulh3Equal Opportunity Employer /h3pRoche is an Equal Opportunity Employer. We believe it’s urgent to deliver medical solutions right now – even as we develop innovations for the future. We are passionate about transforming patients’ lives, courageous in both decision and action, and committed to scientific rigor, ethics, and access to medical innovations for all. /p /p #J-18808-Ljbffr
📌 Senior Cybersecurity Engineer for Secure Access Network (Madrid)
🏢 F. Hoffmann-La Roche
📍 Madrid