Cybersecurity Engineer For Network Security (Madrid)

Cybersecurity Engineer For Network Security (Madrid)

04 ago
|
Roche
|
Madrid

04 ago

Roche

Madrid

Job Responsibilities

- Design & Architecture: Lead the high‑level and low‑level design (HLD/LLD) for general Cisco ISE deployments and Wired Access Control (WAC) strategies to ensure seamless, identity‑based security.
- Palo Alto SME: Serve as the primary engineer for Palo Alto NGFW architectures, including advanced threat prevention, decryption, and secure egress/ingress traffic management.
- Continuous Improvement: Proactively identify gaps in the current security posture and implement technical enhancements to NAC policies, SGT (TrustSec) propagation, and firewall rule‑sets.
- Build & Implementation: Act as the lead implementer for complex global migrations and new feature rollouts across the network security stack.
- Observability Framework Engineering.
- Full‑Stack Development: Architect and develop a custom framework (front‑end and back‑end) to provide a "single pane of glass" for infrastructure health.
- Inventory & Integration: Build automated integrations with external data sources (CMDB, IPAM, etc.) to maintain a real‑time, dynamic inventory of all network assets and security nodes.
- Telemetry Logic: Design custom logic to ingest and visualize telemetry from ISE, WAC, and Palo Alto using APIs, SNMP, and Syslog.
- Operational Excellence & Visibility.
- Technical Subject Matter Expertise: Serve as the lead engineer for complex network security escalations, providing root‑cause analysis and implementing long‑term, automated architectural fixes.
- Security Observability: Develop dashboards and reporting to provide real‑time visibility into the "connected landscape," identifying insecure nodes or unauthorized devices before they can affect the network.
- Automation & Orchestration: Manage security policies as code while continuously improving automation workflows and cross‑platform orchestration to eliminate manual friction, reduce operational overhead, and ensure consistent, high‑speed security enforcement.
- Self‑Service & Enablement: Design and build self‑service capabilities that empower internal teams to consume network security controls autonomously and securely.

Qualifications
- Educational Background:



Bachelor’s degree in Computer Science, Software Engineering, Information Security, or a related technical field.
- Network Access Control Mastery: 3+ years of hands‑on experience in designing, implementing, and managing enterprise‑grade NAC solutions, specifically Cisco ISE.
- Perimeter & Inspection Expertise: Proven track record in configuring and maintaining Palo Alto Next‑Generation Firewalls (NGFW), including SSL decryption and threat prevention.
- Automation Engineering: Proven experience using Ansible, Terraform, or Python to manage network security infrastructure at scale.
- Large‑Scale Infrastructure: Experience managing security controls in complex, global environments involving thousands of diverse device profiles (IoT, Medical, Corporate).
- Regulated Industry: Experience working in highly regulated environments (e.G., Pharmaceuticals, Healthcare, or Finance) is a significant plus.

Technical Skills
- Cisco ISE Specialist: Expert‑level knowledge of Cisco ISE, including hands‑on experience with TrustSec, Dot1x, MAB, and profiling.
- Coding & Integration: Strong scripting skills in Python, PowerShell, or Bash to develop self‑service tools and custom API integrations between security platforms.
- API & Integration: Deep experience with REST APIs for integrating security platforms with external information sources.
- Segmentation Technologies: Proficiency in network virtualization and segmentation techniques (such as TrustSec, SGTs, or VRFs) applied to security use cases.
- Palo Alto Mastery: Proven track record in deploying and troubleshooting Palo Alto Firewalls in complex HA environments (Active/Active and Active/Passive).
- Network Foundations: Deep understanding of RADIUS, TACACS+,



and core routing/switching as they relate to security enforcement.
- Monitoring Stack: Advanced knowledge of LogicMonitor, Splunk, or similar tools, specifically for creating custom DataSources and dashboards.
- Architectural Mindset: Ability to design "Defense in Depth" flows that connect device identity to granular network permissions.
- Skills below will be considered a plus:
- Infrastructure as Code (IaC): Proficiency in Terraform and GitHub to design and manage reproducible, version‑controlled network security configurations.
- Engineering & Orchestration: Proven ability to build CI/CD pipelines and automated workflows that streamline cross‑platform security operations and eliminate manual friction.
- Enterprise Networking: Solid foundation in enterprise networking (L2/L3), including advanced knowledge of routing protocols (BGP, OSPF) and switching (VLANs, VXLAN) to ensure seamless security policy integration.

Leadership Skills
- Communication: Strong ability to build trust with network and infrastructure experts and explain complex security policy concepts to non‑technical stakeholders.
- Innovation & Curiosity: A relentless passion for staying ahead of threat actors by researching emerging network security trends and automated enforcement techniques.
- Thriving in Ambiguity: Ability to navigate global complexity and drive clarity when translating high‑level security requirements into functional network policies.
- Self‑Starter: Proven ability to manage technical workstreams from concept to production with minimal supervision, taking full ownership of the NAC product lifecycle.

Additional Qualifications
- Demonstrated ability to mentor colleagues with less experience and provide guidance on cybersecurity best practices and analysis techniques.
- Strong facilitation, communication, and conflict resolution skills to ensure alignment across multiple product squads and complex stakeholder networks.
- Demonstrated interpersonal, collaborative and commitment to operational excellence skills. xhfqzwm

Roche is an Equal Opportunity Employer.

#J-18808-Ljbffr

📌 Cybersecurity Engineer For Network Security (Madrid)
🏢 Roche
📍 Madrid

Postulate a este anuncio

Muestra tus habilidades a la empresa, rellenar el formulario y deja un toque personal en la carta, ayudará el reclutador en la elección del candidato.

Suscribete a esta alerta:

Recibe por email las nuevas ofertas de trabajo para: cybersecurity engineer for network security (madrid) / madrid

Suscribete a esta alerta:

Recibe por email las nuevas ofertas de trabajo para: cybersecurity engineer for network security (madrid) / madrid