Cybersecurity Engineer for Edge Network Security
2 days ago
Madrid
ppChez Roche, vous pouvez être vous-même et être apprécié pour les qualités uniques que vous apportez. Notre culture encourage l'expression personnelle, le dialogue ouvert et les connexions authentiques, où vous êtes valorisé, accepté et respecté pour ce que vous êtes, vous permettant de prospérer tant personnellement que professionnellement. Voici comment nous visons à prévenir, arrêter et guérir les maladies et à garantir à chacun l'accès aux soins de santé aujourd'hui et pour les générations à venir. Rejoignez Roche, où chaque voix compte. /p h3La position /h3 h3Description of the area /h3 pNetwork Perimeter Security product makes Roche’s connectivity accessible and secure through actionable, policy-driven processes. The capabilities we provide enable Roche to identify, inspect, and mitigate network-based risks, manage regulatory compliance, and oversee egress/ingress traffic across all layers. Our solutions are primarily instantiated through leading-edge security platforms and automated orchestration. We work closely with Cloud, Infrastructure, and Incident Response teams to provide enterprise visibility into Roche’s network security posture. /p pYou’ll be working within the Network Security Product area. This area is accountable for the end-to-end delivery of solutions—designing, building, and maintaining the technologies that protect Roche networks and the Internet, whether on-prem or cloud-based. This includes continuous improvement of capabilities like Internet Security Stack, DDoS Protection, Site-to-Site Connectivity (VPN), Network Access Control and Deep Packet Inspection to stay ahead of an ever-evolving threat landscape. /p h3Job description /h3 pAs a Senior Cybersecurity Engineer (Edge Defense), you will play a pivotal role in the end-to-end lifecycle of our perimeter and cloud security products. Your primary focus will be the global engineering, adoption, and optimization of our Edge security stack, including Next-Generation Firewalls (NGFW), DDoS mitigation, and Zero Trust Network Access (ZTNA). You are a technical "implementer" responsible for designing robust, high-availability architectures that protect our global network from external threats while enabling secure, seamless access to multi-cloud environments. By leveraging an "Automation-First" mindset, you will transform traditional perimeter controls into scalable, code-driven security services, ensuring Roche’s digital boundaries remain resilient in an evolving threat landscape. /p h3Job responsibilities /h3 h31. Edge Architecture Engineering /h3 ul lipPerimeter Defense Mastery: Lead the end-to-end deployment, configuration, and maintenance of Next-Generation Firewalls (Palo Alto, Fortinet), ensuring high availability (Active/Active Active/Passive) and optimal inspection performance across global entry points. /p /li lipZero Trust Transition: Architect and implement ZTNA solutions to move beyond legacy VPNs, focusing on granular, application-level access and identity-aware security policies. /p /li lipMulti-Cloud Network Security: Engineer and manage cloud-native security controls within AWS, Azure, and GCP, ensuring consistent security posture across hybrid and multi-cloud environments. /p /li lipDDoS Threat Mitigation: Design and refine DDoS protection strategies and automated threat prevention policies (SSL decryption, IPS/IDS) to shield critical infrastructure from sophisticated external attacks. /p /li /ul h32. Product Lifecycle Evolution /h3 ul lipLifecycle Governance: Oversee the delivery of Edge solutions from initial design through build, global rollout, and continuous optimization, ensuring that all security controls are reliable, scalable, and documented. /p /li lipEdge Innovation: Proactively identify emerging trends in Edge computing and SASE (Secure Access Service Edge) to inform the product roadmap and maintain a competitive advantage in network defense. /p /li /ul h33. Operational Excellence Visibility /h3 ul lipTechnical Subject Matter Expertise: Serve as the lead engineer for complex network security escalations, performing deep-packet analysis and root-cause investigations to implement long-term architectural fixes. /p /li lipSecurity Observability: Develop advanced monitoring dashboards and telemetry to provide real-time visibility into edge traffic patterns, attack surfaces, and the health of the security stack. /p /li lipAutomation Orchestration: Manage security policies as code while continuously improving automation workflows and cross-platform orchestration to eliminate manual friction, reduce operational overhead, and ensure consistent, high-speed security enforcement. /p /li lipSelf-Service Enablement: Build and maintain automated workflows and APIs that allow internal dev teams to consume edge security services (e.g., automated firewall rule requests) autonomously and securely. /p /li lipOn-Call Readiness: Available for on-call support on a rotating schedule to ensure the continuous availability and integrity of global edge security services. /p /li /ul h3Qualifications /h3 h3Education / Experience /h3 ul lipEducational Background: Bachelor’s degree in Computer Science, Software Engineering, Information Security, or a related technical field. /p /li lipPerimeter Security Mastery: 5+ years of hands‑on experience in designing and managing enterprise-grade Firewall environments (specifically Palo Alto and/or Fortinet). /p /li lipCloud Security Expertise: Proven track record of implementing network security controls in at least two major cloud providers (AWS, Azure, or GCP). /p /li lipPerimeter Inspection Expertise: Proven track record in configuring and maintaining Palo Alto Next-Generation Firewalls (NGFW), including TLS inspection, User identification, WildFire, Threat Prevention, URL Filtering and GlobalProtect. /p /li lipAutomation Engineering: Proven experience using Ansible, Terraform, or Python to manage network security infrastructure at scale. /p /li lipLarge-Scale Infrastructure: Experience managing security controls in complex, global environments involving thousands of diverse device profiles (IoT, Medical, Corporate). /p /li lipRegulated Industry: Experience working in highly regulated environments (e.g., Pharmaceuticals, Healthcare, or Finance) is a significant plus. /p /li /ul h3Technical Skills /h3 ul lipNGFW Expert: Expert-level knowledge of Palo Alto and/or Fortinet platforms, including advanced threat prevention, SSL decryption, and high-availability design. /p /li lipDDoS Mitigation: Experience managing specialized DDoS protection services (e.g., Akamai, Cloudflare, or F5). /p /li lipZTNA Remote Access: Proficiency in modern Zero Trust architectures and SASE frameworks (e.g., Zscaler, Prisma Access). /p /li lipMulti-Cloud Networking: Strong understanding of cloud networking components (VPCs, VNETs, Transit Gateways, Cloud Firewalls). /p /li lipNetwork Foundations: Deep understanding of core protocols (BGP, OSPF, DNS, TLS/SSL) and how they intersect with security enforcement. /p /li /ul pSkills below will be considered a plus: /p ul lipVendor certifications: Fortinet NSE or Palo Alto Networks PCNSA /p /li lipPCNSE or Cisco CCNP Security /p /li lipCybersecurity certification: CISSP /p /li lipInfrastructure as Code (IaC): Proficiency in Terraform and GitHub to maintain version-controlled, reproducible security configurations. /p /li lipScripting Integration: Strong skills in Python or Go to build custom API integrations between security platforms and internal orchestration tools. /p /li lipDDoS Mitigation: Experience managing specialized DDoS protection services (e.g., Akamai, Cloudflare, or F5). /p /li lipGovernance Frameworks: Familiarity with NIST, ISO 27001, and FAIR data principles. /p /li /ul h3Leadership Skills /h3 ul lipCommunication: Strong ability to build trust with network and infrastructure experts and explain complex security policy concepts to non-technical stakeholders. /p /li lipInnovation Curiosity: A relentless passion for staying ahead of threat actors by researching emerging network security trends and automated enforcement techniques. /p /li lipThriving in Ambiguity: Ability to navigate global complexity and drive clarity when translating high-level security requirements into functional network policies. /p /li lipSelf-Starter: Proven ability to manage technical workstreams from concept to production with minimal supervision, taking full ownership of the Edge Defense product lifecycle. /p /li /ul h3Additional Qualifications /h3 ul lipDemonstrated ability to mentor colleagues with less experience and provide guidance on cybersecurity best practices and analysis techniques. /p /li lipStrong facilitation, communication, and conflict resolution skills to ensure alignment across multiple product squads and complex stakeholder networks. /p /li lipDemonstrated interpersonal, collaborative and commitment to operational excellence skills. /p /li /ul h3Qui nous sommes /h3 pUn avenir plus sain nous pousse à innover. Ensemble, plus de 100 000 employés à travers le monde sont dédiés à faire progresser la science et à garantir à chacun l'accès aux soins de santé aujourd'hui et pour les générations à venir. Nos efforts aboutissent à plus de 26 millions de personnes traitées avec nos médicaments et plus de 30 milliards de tests réalisés avec nos produits de Diagnostique. Nous nous encourageons mutuellement à explorer de nouvelles possibilités, à favoriser la créativité et à conserver nos grandes ambitions, afin de fournir des solutions de santé qui changent des vies et ont un impact mondial. /p pConstruisons ensemble un avenir plus sain. /p pRoche est un employeur offrant l'équité en matière d'emploi. /p /p #J-18808-Ljbffr