Cybersecurity Engineer For Internal Network Defense

Roche
Madrid, Spain
5 days ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience required
3 years minimum
Working hours
Regular working hours

Tech stack

Private Networks Artificial Intelligence Cloud Computing Complex Networks Cyber Security Computer Networks Continuous Availability DDoS Mitigation Deep Packet Inspection Github Internet Protocol Security (IP SEC) Internet Security
+24 more
Intrusion Detection and Prevention Virtual Private Networks (VPN) Python (Programming Language) Network Security Network Diagrams Routing Network Segmentation Packet Analyzer Network Protocols Ansible Software Engineering Scripting Transport Layer Security Network Access Control Firewalls (Computer Science) Infrastructure as Code (IaC) Information Technology Palo Alto Networks Data Analytics Fortinet Terraform Api Management GXP Cisco

Job description

Chez Roche, vous pouvez ĂȘtre vous-mĂȘme et ĂȘtre apprĂ©ciĂ© pour les qualitĂ©s uniques que vous apportez.Notre culture encourage l’expression personnelle, le dialogue ouvert et les connexions authentiques, oĂč vous ĂȘtes valorisĂ©, acceptĂ© et respectĂ© pour ce que vous ĂȘtes, vous permettant de prospĂ©rer tant personnellement que professionnellement.Voici comment nous visons Ă  prĂ©venir, arrĂȘter et guĂ©rir les maladies et Ă  garantir Ă  chacun l’accĂšs aux soins de santĂ© aujourd’hui et pour les gĂ©nĂ©rations Ă  venir.Rejoignez Roche, oĂč chaque voix compte.La positionThe Network & Perimeter Security product makes Roche’s connectivity accessible and secure through actionable, policy-driven processes.The capabilities we provide enable Roche to identify, inspect, and mitigate network-based risks, manage regulatory compliance, and oversee egress/ingress traffic across all layers.Our solutions are primarily instantiated through leading-edge security platforms and automated orchestration.We work closely with Cloud, Infrastructure, and Incident Response teams to provide enterprise visibility into Roche’s network security posture.You’ll be working within the Network Security Product area.This area is accountable for the end-to-end delivery of solutions-designing, building, and maintaining the technologies that protect Roche networks and the Internet, whether on-prem or cloud-based.This includes continuous improvement of capabilities like Internet Security Stack, DDoS Protection, Site-to-Site Connectivity (VPN), Network Access Control and Deep Packet Inspection to stay ahead of an ever-evolving threat landscape.Job descriptionAs a Senior Cybersecurity Engineer for Internal Network Defense, you will be the primary guardian of our internal environment, protecting our most sensitive segments-from manufacturing plants and research labs to warehouses and corporate offices.Your mission is to architect and enforce robust “East-West” segmentation, preventing lateral movement and securing the diverse environments that drive our core business.This is a technical “implementer” role where you will architect, design, build, and operate high-performance security boundaries using a dual-vendor strategy (Palo Alto and Fortinet).Beyond traditional enforcement, you will champion the adoption of AI-driven insights to identify latent risks and define the safe boundaries for automated security workflows, ensuring our internal network is resilient, compliant, and prepared for machine-speed threats.Job responsibilitiesArchitecture, Design & AI AmbitionSegmentation Strategy: Design, develop and document robust network segmentation architectures leveraging Fortinet and Palo Alto firewalls to meet complex business and security requirements.AI-Driven Risk Discovery: Actively explore and integrate AI opportunities to analyze internal traffic patterns and identify emerging security risks within complex Manufacturing and Lab environments.Automated Guardrails: Define and establish clear boundaries and governance for automated workflows, ensuring that machine-driven policy changes remain within safe, predictable parameters.Solution Blueprints: Create detailed network diagrams, technical design documents, and implementation plans for new segmentation environments (Labs, Manufacturing, Research).Implementation & DeploymentFirewall Engineering: Configure, deploy, and manage Palo Alto Networks (PA-Series, VM-Series) and Fortinet FortiGate firewalls at scale.Centralized Management: Utilize Panorama and FortiManager to enforce consistent security policies, NAT rules, VPNs (IPSec/SSL), and advanced routing features.Infrastructure Evolution: Lead the migration and upgrade of existing internal firewall infrastructure, ensuring zero-downtime transitions in critical environments.3. Operational Excellence & VisibilityTechnical Subject Matter Expertise: Serve as the lead engineer for complex network security escalations, performing deep-packet analysis and root-cause investigations to implement long-term architectural fixes.Validated Environments: Apply security best practices within validated (GxP) environments, ensuring compliance with manufacturing and healthcare regulations.Continuous Improvement: Stay current with emerging threats, vulnerabilities, and security technologies to proactively refine internal defenses.Automation & Orchestration: Manage security policies as code while continuously improving automation workflows and cross-platform orchestration to eliminate manual friction, reduce operational overhead, and ensure consistent, high-speed security enforcement.On-Call Readiness: Available for on-call support on a rotating schedule to ensure the continuous availability and integrity of global edge security services.QualificationsEducation / ExperienceEducational Background: Bachelor’s degree in Computer Science, Software Engineering, Information Security, or a related technical field.Professional Experience: 3+ years of experience in designing, deploying, and supporting Next-Generation Firewalls (NGFW) in large enterprise environments.Automation Engineering: Proven experience using Ansible, Terraform, or Python to manage network security infrastructure at scale.Large-Scale Infrastructure: Experience managing security controls in complex, global environments involving thousands of diverse device profiles (IoT, Medical, Corporate).Regulated Industry: Experience working in highly regulated environments (e.g., Pharmaceuticals, Healthcare, or Finance) is highly preferred.Technical SkillsPalo Alto Mastery: Deep knowledge of PA-Series, Panorama, App-ID, User-ID, WildFire, and Threat Prevention.Fortinet Expertise: Extensive hands-on experience with FortiGate, FortiManager, FortiAnalyzer, and the Fortinet Security Fabric.Security Foundations: Solid understanding of security concepts, trends, and best practices, specifically for “Defense in Depth” within internal networks.Networking Depth: Strong foundation in core routing/switching, VPN architectures, and network protocols.Skills below will be considered a plus:Vendor certifications: Fortinet NSE 4-8 or Palo Alto Networks: PCNSA PCNSE, Cisco CCNPCybersecurity certification: CISSPInfrastructure as Code (IaC): Proficiency in Terraform and GitHub to maintain version-controlled, reproducible security configurations.Scripting & Integration: Strong skills in Python or Go to build custom API integrations between security platforms and internal orchestration tools.Governance Frameworks: Familiarity with NIST, IEC **, ISO **, and FAIR data principles.Leadership SkillsCommunication: Strong ability to build trust with network and infrastructure experts and explain complex security policy concepts to non-technical stakeholders.Innovation & Curiosity: A relentless passion for staying ahead of threat actors by researching emerging network security trends and automated enforcement techniques.Thriving in Ambiguity: Ability to navigate global complexity and drive clarity when translating high-level security requirements into functional network policies.Self-Starter: Proven ability to manage technical workstreams from concept to production with minimal supervision, taking full ownership of the Edge Defense product lifecycle.Additional QualificationsDemonstrated ability to mentor colleagues with less experience and provide guidance on cybersecurity best practices and analysis techniquesStrong facilitation, communication, and conflict resolution skills to ensure alignment across multiple product squads and complex stakeholder networksDemonstrated interpersonal, collaborative and commitment to operational excellence skills.Qui nous sommesUn avenir plus sain nous pousse Ă  innover.Ensemble, plus de *** employĂ©s Ă  travers le monde sont dĂ©diĂ©s Ă  faire progresser la science et Ă  garantir Ă  chacun l’accĂšs aux soins de santĂ© aujourd’hui et pour les gĂ©nĂ©rations Ă  venir.Nos efforts aboutissent Ă  plus de 26 millions de personnes traitĂ©es avec nos mĂ©dicaments et plus de 30 milliards de tests rĂ©alisĂ©s avec nos produits de Diagnostique.Nous nous encourageons mutuellement Ă  explorer de nouvelles possibilitĂ©s, Ă  favoriser la crĂ©ativitĂ© et Ă  conserver nos grandes ambitions, afin de fournir des solutions de santĂ© qui changent des vies et ont un impact mondial.Construisons ensemble un avenir plus sain.Roche est un employeur offrant l’équitĂ© en matiĂšre d’emploi.#J-*****-Ljbffr

Requirements

Educational Background: Bachelor’s degree in Computer Science, Software Engineering, Information Security, or a related technical field. Professional Experience: 3+ years of experience in designing, deploying, and supporting Next-Generation Firewalls (NGFW) in large enterprise environments. Automation Engineering: Proven experience using Ansible, Terraform, or Python to manage network security infrastructure at scale. Large-Scale Infrastructure: Experience managing security controls in complex, global environments involving thousands of diverse device profiles (IoT, Medical, Corporate). Regulated Industry: Experience working in highly regulated environments (e.g., Pharmaceuticals, Healthcare, or Finance) is highly preferred. Technical Skills Palo Alto Mastery: Deep knowledge of PA-Series, Panorama, App-ID, User-ID, WildFire, and Threat Prevention. Fortinet Expertise: Extensive hands-on experience with FortiGate, FortiManager, FortiAnalyzer, and the Fortinet Security Fabric. Security Foundations: Solid understanding of security concepts, trends, and best practices, specifically for “Defense in Depth” within internal networks. Networking Depth: Strong foundation in core routing/switching, VPN architectures, and network protocols. Skills below will be considered a plus: Vendor certifications: Fortinet NSE 4-8 or Palo Alto Networks: PCNSA PCNSE, Cisco CCNP Cybersecurity certification: CISSP Infrastructure as Code (IaC): Proficiency in Terraform and GitHub to maintain version-controlled, reproducible security configurations. Scripting & Integration: Strong skills in Python or Go to build custom API integrations between security platforms and internal orchestration tools. Governance Frameworks: Familiarity with NIST, IEC **, ISO **, and FAIR data principles. Leadership Skills Communication: Strong ability to build trust with network and infrastructure experts and explain complex security policy concepts to non-technical stakeholders. Innovation & Curiosity: A relentless passion for staying ahead of threat actors by researching emerging network security trends and automated enforcement techniques. Thriving in Ambiguity: Ability to navigate global complexity and drive clarity when translating high-level security requirements into functional network policies. Self-Starter: Proven ability to manage technical workstreams from concept to production with minimal supervision, taking full ownership of the Edge Defense product lifecycle. Additional Qualifications Demonstrated ability to mentor colleagues with less experience and provide guidance on cybersecurity best practices and analysis techniques Strong facilitation, communication, and conflict resolution skills to ensure alignment across multiple product squads and complex stakeholder networks Demonstrated interpersonal, collaborative and commitment to operational excellence skills.

Benefits & conditions

Ensemble, plus de *** employĂ©s Ă  travers le monde sont dĂ©diĂ©s Ă  faire progresser la science et Ă  garantir Ă  chacun l’accĂšs aux soins de santĂ© aujourd’hui et pour les gĂ©nĂ©rations Ă  venir. Nos efforts aboutissent Ă  plus de 26 millions de personnes traitĂ©es avec nos mĂ©dicaments et plus de 30 milliards de tests rĂ©alisĂ©s avec nos produits de Diagnostique. Nous nous encourageons mutuellement Ă  explorer de nouvelles possibilitĂ©s, Ă  favoriser la crĂ©ativitĂ© et Ă  conserver nos grandes ambitions, afin de fournir des solutions de santĂ© qui changent des vies et ont un impact mondial. Construisons ensemble un avenir plus sain. Roche est un employeur offrant l’équitĂ© en matiĂšre d’emploi. #J-*****-Ljbffr

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.buscojobs.com.es

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

4:01 min

Finding personal fulfillment in the cybersecurity industry

LIVE

6:36 min

Funding open source through GitHub Accelerator and Sponsors

Stormy Peters · WWC 2023

3:13 min

Core components of the internal Optimize ecosystem

Dominik Schneider Dominik Schneider · WWC 2025

1:29 min

Expanding practical knowledge with community sandboxes and resources

Stuart Clark · LIVE

3:22 min

Transitioning from software engineering to security roles

Anna Oliveira · Coffee With Developers

2:40 min

Using GitHub primitives for internal documentation and corporate operations

Kyle Daigle · Coffee With Developers

Videos

See all

Related articles

See all