Cybersecurity Engineer for Internal Network Defense
hace 8 días
Madrid
ppBei Roche kannst du ganz du selbst sein und wirst für deine einzigartigen Qualitäten geschätzt. Unsere Kultur fördert persönlichen Ausdruck, offenen Dialog und echte Verbindungen. Hier wirst du für das, was du bist, wertgeschätzt, akzeptiert und respektiert. Dies schafft ein Umfeld, in dem du sowohl persönlich als auch beruflich wachsen kannst. Gemeinsam wollen wir Krankheiten vorbeugen, stoppen und heilen und sicherstellen, dass jeder Zugang zur Gesundheitsversorgung hat – heute und in Zukunft. Werde Teil von Roche, wo jede Stimme zählt. /p /brh3Die Position /h3 /brpThe Network Perimeter Security product makes Roche’s connectivity accessible and secure through actionable, policy-driven processes. The capabilities we provide enable Roche to identify, inspect, and mitigate network-based risks, manage regulatory compliance, and oversee egress/ingress traffic across all layers. Our solutions are primarily instantiated through leading-edge security platforms and automated orchestration. We work closely with Cloud, Infrastructure, and Incident Response teams to provide enterprise visibility into Roche’s network security posture. /p /brpYou’ll be working within the Network Security Product area. This area is accountable for the end-to-end delivery of solutions—designing, building, and maintaining the technologies that protect Roche networks and the Internet, whether on‑prem or cloud-based. This includes continuous improvement of capabilities like Internet Security Stack, DDoS Protection, Site‑to‑Site Connectivity (VPN), Network Access Control and Deep Packet Inspection to stay ahead of an ever‑evolving threat landscape. /p /brh3Job description /h3 /brpAs a Senior Cybersecurity Engineer for Internal Network Defense, you will be the primary guardian of our internal environment, protecting our most sensitive segments—from manufacturing plants and research labs to warehouses and corporate offices. Your mission is to architect and enforce robust “East‑West” segmentation, preventing lateral movement and securing the diverse environments that drive our core business. This is a technical “implementer” role where you will architect, design, build, and operate high-performance security boundaries using a dual‑vendor strategy (Palo Alto and Fortinet). Beyond traditional enforcement, you will champion the adoption of AI‑driven insights to identify latent risks and define the safe boundaries for automated security workflows, ensuring our internal network is resilient, compliant, and prepared for machine‑speed threats. /p /brh3Job responsibilities /h3 /brh3Architecture, Design AI Ambition /h3 /brul /brliSegmentation Strategy: Design, develop and document robust network segmentation architectures leveraging Fortinet and Palo Alto firewalls to meet complex business and security requirements. /li /brliAI-Driven Risk Discovery: Actively explore and integrate AI opportunities to analyze internal traffic patterns and identify emerging security risks within complex Manufacturing and Lab environments. /li /brliAutomated Guardrails: Define and establish clear boundaries and governance for automated workflows, ensuring that machine‑driven policy changes remain within safe, predictable parameters. /li /brliSolution Blueprints: Create detailed network diagrams, technical design documents, and implementation plans for new segmentation environments (Labs, Manufacturing, Research). /li /br /ul /brh3Implementation Deployment /h3 /brul /brliFirewall Engineering: Configure, deploy, and manage Palo Alto Networks (PA-Series, VM-Series) and Fortinet FortiGate firewalls at scale. /li /brliCentralized Management: Utilize Panorama and FortiManager to enforce consistent security policies, NAT rules, VPNs (IPSec/SSL), and advanced routing features. /li /brliInfrastructure Evolution: Lead the migration and upgrade of existing internal firewall infrastructure, ensuring zero‑downtime transitions in critical environments. /li /br /ul /brh33. Operational Excellence Visibility /h3 /brul /brliTechnical Subject Matter Expertise: Serve as the lead engineer for complex network security escalations, performing deep‑packet analysis and root‑cause investigations to implement long‑term architectural fixes. /li /brliValidated Environments: Apply security best practices within validated (GxP) environments, ensuring compliance with manufacturing and healthcare regulations. /li /brliContinuous Improvement: Stay current with emerging threats, vulnerabilities, and security technologies to proactively refine internal defenses. /li /brliAutomation Orchestration: Manage security policies as code while continuously improving automation workflows and cross‑platform orchestration to eliminate manual friction, reduce operational overhead, and ensure consistent, high‑speed security enforcement. /li /brliOn‑Call Readiness: Available for on‑call support on a rotating schedule to ensure the continuous availability and integrity of global edge security services. /li /br /ul /brh3Qualifications /h3 /brh3Education / Experience /h3 /brul /brliEducational Background: Bachelor’s degree in Computer Science, Software Engineering, Information Security, or a related technical field. /li /brliProfessional Experience: 3+ years of experience in designing, deploying, and supporting Next‑Generation Firewalls (NGFW) in large enterprise environments. /li /brliAutomation Engineering: Proven experience using Ansible, Terraform, or Python to manage network security infrastructure at scale. /li /brliLarge‑Scale Infrastructure: Experience managing security controls in complex, global environments involving thousands of diverse device profiles (IoT, Medical, Corporate). /li /brliRegulated Industry: Experience working in highly regulated environments (e.g., Pharmaceuticals, Healthcare, or Finance) is highly preferred. /li /br /ul /brh3Technical Skills /h3 /brul /brliPalo Alto Mastery: Deep knowledge of PA‑Series, Panorama, App‑ID, User‑ID, WildFire, and Threat Prevention. /li /brliFortinet Expertise: Extensive hands‑on experience with FortiGate, FortiManager, FortiAnalyzer, and the Fortinet Security Fabric. /li /brliSecurity Foundations: Solid understanding of security concepts, trends, and best practices, specifically for “Defense in Depth” within internal networks. /li /brliNetworking Depth: Strong foundation in core routing/switching, VPN architectures, and network protocols. /li /br /ul /brh3Skills below will be considered a plus /h3 /brul /brliVendor certifications: Fortinet NSE 4‑8 or Palo Alto Networks: PCNSA PCNSE, Cisco CCNP /li /brliCybersecurity certification: CISSP /li /brliInfrastructure as Code (IaC): Proficiency in Terraform and GitHub to maintain version‑controlled, reproducible security configurations. /li /brliScripting Integration: Strong skills in Python or Go to build custom API integrations between security platforms and internal orchestration tools. /li /brliGovernance Frameworks: Familiarity with NIST, IEC 62443, ISO 27001, and FAIR data principles. /li /br /ul /brh3Leadership Skills /h3 /brul /brliCommunication: Strong ability to build trust with network and infrastructure experts and explain complex security policy concepts to non‑technical stakeholders. /li /brliInnovation Curiosity: A relentless passion for staying ahead of threat actors by researching emerging network security trends and automated enforcement techniques. /li /brliThriving in Ambiguity: Ability to navigate global complexity and drive clarity when translating high‑level security requirements into functional network policies. /li /brliSelf‑Starter: Proven ability to manage technical workstreams from concept to production with minimal supervision, taking full ownership of the Edge Defense product lifecycle. /li /br /ul /brh3Additional Qualifications /h3 /brul /brliDemonstrated ability to mentor colleagues with less experience and provide guidance on cybersecurity best practices and analysis techniques. /li /brliStrong facilitation, communication, and conflict resolution skills to ensure alignment across multiple product squads and complex stakeholder networks. /li /brliDemonstrated interpersonal, collaborative and commitment to operational excellence skills. /li /br /ul /brh3Wer wir sind /h3 /brpEine gesündere Zukunft treibt uns zur Innovation an. Mehr als 100.000 Mitarbeiter weltweit arbeiten gemeinsam daran, wissenschaftliche Fortschritte zu erzielen und sicherzustellen, dass jeder Zugang zur Gesundheitsversorgung hat – heute und für zukünftige Generationen. Durch unser Engagement werden über 26 Millionen Menschen mit unseren Medikamenten behandelt und mehr als 30 Milliarden Tests mit unseren Diagnostik‑Produkten durchgeführt. Wir ermutigen uns gegenseitig, neue Möglichkeiten zu erkunden, Kreativität zu fördern und hohe Ziele zu setzen, um lebensverändernde Gesundheitslösungen zu liefern. /p /brpGemeinsam können wir eine gesündere Zukunft gestalten. /p /brpbRoche ist ein Arbeitgeber, der die Chancengleichheit fördert. /b /p /p #J-18808-Ljbffr