Solution Architect - Identity & Access Management At Roche

Roche
Madrid, Spain
14 days ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience required
10 years minimum
Working hours
Regular working hours
Languages
English

Tech stack

Active Directory Application Programming Interfaces (APIs) Artificial Intelligence Amazon Web Services Microsoft Azure Catalyst (Software) Cloud Computing Cyber Security Continuous Integration Data Security DevOps Identity and Access Management
+15 more
Machine Learning OpenID Software Architecture Ansible Zero Trust Network Access Security Assertion Markup Language (SAML) SAP (Applications) Google Cloud Cyberark Information Technology Hashicorp SailPoint Devsecops GXP Microservices

Job description

Solution Architect - Identity & Access ManagementLocation: Madrid, MD, ES.This full?time on?site position offers great opportunities for career growth.Job ResponsibilitiesStrategy & Roadmap Definition - Provide expert technical knowledge to define the overarching IAM strategy and multi?year technology roadmaps in alignment with the overall Information Security vision.Roadmap Support - Support the Head of IAM and the Leadership Team in transforming complex scientific and business needs into high?value technology solutions.Trend Integration - Proactively monitor market shifts and technology trends, including AI/ML capabilities, to inform product iterations and maintain a competitive advantage.Cross?Functional Technical Leadership - Provide technical consultancy and architectural oversight to the seven IAM areas (Enterprise Identity, Access Management, Customer Identity, Data Access Control, Privileged Access Management, External Identity, and Directory Services).Zero Trust Catalyst - Champion modern principles such as “Never Trust, Always Verify” and “Policy?as?Code,” ensuring these are integrated into CI/CD and DevSecOps workflows.Continuous Platform Evolution - Drive ongoing collaboration with RDT Functions and business stakeholders to ensure the continuous evolution of our IAM platforms, delivering services that meet emerging needs.Technical Excellence & Lifecycle Management - Contribute to the lifecycle management of technological components, from initial ideation to decommissioning.Operational Integrity - Ensure solutions integrate seamlessly with existing systems, deliver high performance, and provide an intuitive user experience.Compliance & Standards - Guarantee that all technical architectures comply with GxP, CSV, and global data privacy regulations such as GDPR.Mentorship - Coach and provide technical guidance to specialists and engineers across the IAM organization.QualificationsYou have a technical visionary mindset with an “Enterprise Mindset,” 10+ years of experience supporting Enterprise IAM and IT Security systems in a major global organization, and a Bachelor’s or Advanced degree in Computer Science, Cyber Security, or a related Engineering field.Experience in the pharmaceutical, biotechnology, or regulated healthcare industry is a significant asset.Professional certifications such as CISSP, CISM, or CISA are desirable.Technical MasteryDeep knowledge in at least three of our core technology pillars or similar platform is required: Identity Governance & Administration (SailPoint IdentityIQ or IdentityNow / Identity Security Cloud), Access Management/Directory Services (Entra ID, Ping Identity, Active Directory, OIDC/SAML), Privileged Access Management/Secret Management (CyberArk or HashiCorp Vault), Data Access Control (Policy?Based Access Control), Customer IAM (SAP CDC/Gigya).Skills & CompetenciesAdvanced Architecture - Understanding of modern software architecture, including microservices, APIs, and cloud platforms (AWS, Azure, GCP).DevOps & Automation - Experience with CI/CD principles and automation tools such as Ansible and Jenkins.Influencing - Exceptional communication and negotiation skills to manage expectations of senior executives and technical engineers alike.LanguagesExcellent verbal and written English is a must.Roche ist ein Arbeitgeber, der die Chancengleichheit fördert.#J-*****-Ljbffr

Requirements

Zero Trust Catalyst - Champion modern principles such as “Never Trust, Always Verify” and “Policy?as?Code,” ensuring these are integrated into CI/CD and DevSecOps workflows.Continuous Platform Evolution - Drive ongoing collaboration with RDT Functions and business stakeholders to ensure the continuous evolution of our IAM platforms, delivering services that meet emerging needs.Technical Excellence & Lifecycle Management - Contribute to the lifecycle management of technological components, from initial ideation to decommissioning.Operational Integrity - Ensure solutions integrate seamlessly with existing systems, deliver high performance, and provide an intuitive user experience.Compliance & Standards - Guarantee that all technical architectures comply with GxP, CSV, and global data privacy regulations such as GDPR.Mentorship - Coach and provide technical guidance to specialists and engineers across the IAM organization.QualificationsYou have a technical visionary mindset with an “Enterprise Mindset,” 10+ years of experience supporting Enterprise IAM and IT Security systems in a major global organization, and a Bachelor’s or Advanced degree in Computer Science, Cyber Security, or a related Engineering field.Experience in the pharmaceutical, biotechnology, or regulated healthcare industry is a significant asset. Professional certifications such as CISSP, CISM, or CISA are desirable.Technical MasteryDeep knowledge in at least three of our core technology pillars or similar platform is required: Identity Governance & Administration (SailPoint IdentityIQ or IdentityNow / Identity Security Cloud), Access Management/Directory Services (Entra ID, Ping Identity, Active Directory, OIDC/SAML), Privileged Access Management/Secret Management (CyberArk or HashiCorp Vault), Data Access Control (Policy?Based Access Control), Customer IAM (SAP CDC/Gigya). Skills & CompetenciesAdvanced Architecture - Understanding of modern software architecture, including microservices, APIs, and cloud platforms (AWS, Azure, GCP). DevOps & Automation - Experience with CI/CD principles and automation tools such as Ansible and Jenkins.Influencing - Exceptional communication and negotiation skills to manage expectations of senior executives and technical engineers alike.LanguagesExcellent verbal and written English is a must.Roche ist ein Arbeitgeber, der die Chancengleichheit fördert.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.buscojobs.com.es

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

2:17 min

Mapping the maturity roadmap for scaled devops adoption

Dominik Krichbaum Dominik Krichbaum · WWC Europe 2026

4:35 min

Setting up passwordless federated identity configuring OpenID Connect patterns

Marcel Lupo · LIVE

3:13 min

Core components of the internal Optimize ecosystem

Dominik Schneider Dominik Schneider · WWC 2025

2:47 min

Exploring career opportunities and recruitment open positions

Kurt Eder · LIVE

3:18 min

Scaling global network engineering through DevOps culture

Stuart Clark · LIVE

2:52 min

Implementing IAM with Keycloak and OpenID Connect

Thomas Südbröcker · LIVE

Videos

See all

Related articles

See all