Senior Cloud Security Engineer

Roche
Madrid, Spain
15 days ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Working hours
Regular working hours
Languages
English

Tech stack

Microsoft Access Application Programming Interfaces (APIs) Amazon Web Services Microsoft Azure Cloud Computing Cloud Computing Security Cloud Engineering Cyber Security DevOps Infrastructure as a Service (IaaS) Platform as a Service (PAAS) Software Engineering
+9 more
Multi-Cloud Infrastructure as Code (IaC) Kubernetes Information Technology Prisma Cloud Platform Devsecops Serverless Computing Docker Vulnerability Analysis

Job description

Chez Roche, vous pouvez être vous-même et être apprécié pour les qualités uniques que vous apportez.Notre culture encourage l’expression personnelle, le dialogue ouvert et les connexions authentiques, où vous êtes valorisé, accepté et respecté pour ce que vous êtes, vous permettant de prospérer tant personnellement que professionnellement.Voici comment nous visons à prévenir, arrêter et guérir les maladies et à garantir à chacun l’accès aux soins de santé aujourd’hui et pour les générations à venir.Rejoignez Roche, où chaque voix compte.La position We are a high-performing cybersecurity team tasked with protecting the organization’s computing environments.While our historical stronghold has been managing enterprise Endpoint Detection and Response (EDR), Application Control, and Secure Data Erasure, we are now expanding our focus to secure our dynamic, cloud-native environments.We are looking for a Cloud Security Engineer specializing in Cloud Workload Protection.You will be responsible for securing IaaS, PaaS, containers, and serverless architectures.Working alongside your senior endpoint security colleagues, you will bridge the gap between traditional endpoint defense and modern cloud infrastructure, ensuring our threat detection and application governance standards are seamlessly extended to the cloud.Job Responsibilities Cloud Workload Protection (CWPP): Architect, deploy, and manage Cloud Workload Protection Platforms (e.G., Prisma Cloud, Microsoft Defender for Cloud, Wiz, or Aqua) across our multi-cloud environment (AWS, Azure, and/or GCP).Container & Kubernetes Security: Implement runtime defense, vulnerability scanning, and configuration hardening for containerized applications and orchestration platforms (EKS, AKS, GKE).Extending Core Services to the Cloud: Adapt our existing strategies for EDR and Application Control to function effectively in ephemeral, cloud-native workloads without degrading performance.DevSecOps Integration: Embed security controls directly into CI/CD pipelines (Shift-Left), ensuring images, registries, and Infrastructure as Code (IaC) templates are scanned and secured before deployment.Automated Remediation: Develop automated response playbooks for cloud misconfigurations and workload alerts using serverless functions and native cloud APIs.Qualifications Education / Experience / Technical Skills Bachelor’s degree in Computer Science, Software Engineering, Cybersecurity, or equivalent practical experience.3+ years of dedicated experience securing public cloud workloads, with a strong understanding of the shared responsibility model.Deep technical knowledge of Docker, Kubernetes, and container orchestration.You should know how to secure a pod, restrict container privileges, and manage network policies.Proven, hands?on experience deploying and tuning commercial or open?source cloud security platforms (CWPP / CNAPP).Strong grasp of cloud-native networking (VPCs, Security Groups) and Identity and Access Management (least?privilege roles, service accounts).Proficiency in written and spoken English (C1 or above level).Additional Qualifications Bridge Builder: Ability to collaborate closely with DevOps and Cloud Engineering teams, acting as an enabler rather than a roadblock.Strategic Thinker: Capacity to look at our existing on?premise security policies and intelligently adapt them for ephemeral cloud environments.Adaptable: Comfortable working in a highly dynamic cybersecurity environment where priorities can shift based on emerging needs.Team Player: Ability to collaborate effectively with internal and external team mates and stakeholders.Mentorship: Willingness to cross?train our existing senior endpoint engineers on cloud?native security concepts, while learning from their deep endpoint telemetry expertise.Qui nous sommes Un avenir plus sain nous pousse à innover.Ensemble, plus de *** employés à travers le monde sont dédiés à faire progresser la science et à garantir à chacun l’accès aux soins de santé aujourd’hui et pour les générations à venir.Nos efforts aboutissent à plus de 26 millions de personnes traitées avec nos médicaments et plus de 30 milliards de tests réalisés avec nos produits de Diagnostique.Nous nous encourageons mutuellement à explorer de nouvelles possibilités, à favoriser la créativité et à conserver nos grandes ambitions, afin de fournir des solutions de santé qui changent des vies et ont un impact mondial.Roche est un employeur offrant l’équité en matière d’emploi.#J-*****-Ljbffr

Requirements

Automated Remediation: Develop automated response playbooks for cloud misconfigurations and workload alerts using serverless functions and native cloud APIs. Qualifications Education / Experience / Technical Skills Bachelor’s degree in Computer Science, Software Engineering, Cybersecurity, or equivalent practical experience. 3+ years of dedicated experience securing public cloud workloads, with a strong understanding of the shared responsibility model. Deep technical knowledge of Docker, Kubernetes, and container orchestration. You should know how to secure a pod, restrict container privileges, and manage network policies. Proven, hands?on experience deploying and tuning commercial or open?source cloud security platforms (CWPP / CNAPP). Strong grasp of cloud-native networking (VPCs, Security Groups) and Identity and Access Management (least?privilege roles, service accounts). Proficiency in written and spoken English (C1 or above level). Additional Qualifications Bridge Builder: Ability to collaborate closely with DevOps and Cloud Engineering teams, acting as an enabler rather than a roadblock. Strategic Thinker: Capacity to look at our existing on?premise security policies and intelligently adapt them for ephemeral cloud environments. Adaptable: Comfortable working in a highly dynamic cybersecurity environment where priorities can shift based on emerging needs. Team Player: Ability to collaborate effectively with internal and external team mates and stakeholders. Mentorship: Willingness to cross?train our existing senior endpoint engineers on cloud?native security concepts, while learning from their deep endpoint telemetry expertise.

Benefits & conditions

Nos efforts aboutissent à plus de 26 millions de personnes traitées avec nos médicaments et plus de 30 milliards de tests réalisés avec nos produits de Diagnostique. Nous nous encourageons mutuellement à explorer de nouvelles possibilités, à favoriser la créativité et à conserver nos grandes ambitions, afin de fournir des solutions de santé qui changent des vies et ont un impact mondial. Roche est un employeur offrant l’équité en matière d’emploi. #J-*****-Ljbffr

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.buscojobs.com.es

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

2:07 min

Inspecting default bridge architectures and custom Docker networks

Oliver Seitz Oliver Seitz · WWC 2025

2:17 min

Mapping the maturity roadmap for scaled devops adoption

Dominik Krichbaum Dominik Krichbaum · WWC Europe 2026

1:15 min

Key lessons learned from implementing automated mobile DevSecOps

Moataz Nabil Moataz Nabil · LIVE

3:22 min

Transitioning from software engineering to security roles

Anna Oliveira · Coffee With Developers

2:34 min

Docker sandbox architecture and microVM environment integration

Manuel de la Peña Manuel de la Peña · WWC Europe 2026

6:13 min

Defining cloud proficiency by technical role

Piet Van Dongen · LIVE

Videos

See all

Related articles

See all