Expert Devsecops Engineer (Expert Software Development Security Engineer)

Roche
Badajoz, Spain
10 days ago
Apply on www.buscojobs.com.es
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience required
3 years minimum
Working hours
Regular working hours

Tech stack

Application Programming Interfaces (APIs) Software Quality DevOps Systems Development Life Cycle Software Engineering SonarQube Value Engineering Enterprise Software Applications Software Security Infrastructure as Code (IaC) Information Technology Devsecops
+1 more
Static Application Security Testing

Job description

Bei Roche kannst du ganz du selbst sein und wirst für deine einzigartigen Qualitäten geschätzt. Unsere Kultur fördert persönlichen Ausdruck, offenen Dialog und echte Verbindungen. Hier wirst du für das, was du bist, wertgeschätzt, akzeptiert und respektiert. Dies schafft ein Umfeld, in dem du sowohl persönlich als auch beruflich wachsen kannst. Gemeinsam wollen wir Krankheiten vorbeugen, stoppen und heilen und sicherstellen, dass jeder Zugang zur Gesundheitsversorgung hat - heute und in Zukunft. Werde Teil von Roche, wo jede Stimme zählt.Die PositionAs an Expert DevSecOps Engineer, acting as a Software Development Security Expert, you will sit at the intersection of software and security engineering. You are accountable for designing robust software development security frameworks, handling ambiguous security and compliance requirements, managing complex stakeholder landscapes, and mentoring junior engineers. You will also collaborate with the area architect in defining the long-term architecture for software engineering security solutions.Description of the area:Engineering Excellence & Experience (E3) enables engineers to explore, plan, design, code, build, test, and deploy software packages in a reliable, secure, automated, and consistent manner across our different business areas. This includes providing facilitated access to automated, composable infrastructure consumable through Infrastructure as Code (IaC) and APIs, both on-premises and in the public cloud.Within E3, you will join the Embedded Security & Testing Team, which champions the integration of testing and security concepts throughout the software development lifecycle. Specifically, the Code Quality, Security, and Testing Engineering team combines best practices and modern solutions to ensure that all code generated is secure and of the highest quality. The team provides a range of DevSecOps components fit for diverse technical complexities, delivers Proofs of Concept (PoCs), and supports internal adoption both during and after implementation.Job Responsibilities:Scope:Provides expert-level leadership and strategic guidance in DevSecOps area, including Threat Modelling, Code Quality, SAST, Secret Scanning, Software Composition Analysis, IaC Scanning, License Compliance, Dependency Management, Container Image Scanning, API Security and Container Runtime Scanner.Participate in the definition of Software Security best practices, ensuring consistency, traceability, and alignment with enterprise standardsLeads DevSecOps efforts on strategic activities and provides guidance to less experienced members.Problem Solving:Leads the analysis of complex and strategic business problems, defining the problem space and driving comprehensive root cause analysis that may span organizational boundariesWorks on unusually complex problems, provides highly innovative solutions, and applies expert-level analytical and logical reasoning to proactively identify strategic opportunities and risksStakeholder Management & Strategic Influence:Builds and maintains strong relationships with key stakeholders and cultivates collaboration across the organizationElicits and analyzes complex stakeholder needs with expertise, and influences business stakeholders to inform and make the right decisionsShapes strategy as a trusted advisor to leadership, acting as an influential partner and organizational trust builderRecommends and guides the implementation of optimal strategies, transitions, and future states, fostering a culture of strategic innovation and continuous improvement within their product line or domainLeadership, Accountability & Mentorship:Evaluates strategic solution alternatives through rigorous risk assessment and value analysis, ensuring key initiatives align with overall organizational objectives, and recommends optimal technology solutions to drive business transformation.Is accountable for deliverables on significant projects, ensuring alignment with strategic objectives, defining strategic solution scope, and managing complexityMentors colleagues, helps others develop expertise and skills, and provides guidance to other ExpertsActively contributes to organizational development, including showing leadership in Communities of Practice (CoPs).Understands and balances strict security compliances without slowing down developers.Qualifications & Experience:Required Technical Experience:Education: Bachelor’s or Master’s degree in Computer Science, Software Engineering, or a related technical field (or equivalent practical experience).DevSecOps Expertise: Minimum of 8-10+ years of progressive experience, including 3+ years of specialization in building DevSecOps frameworks from scratch.Be a hands?on tools agnostic technical expert on the DevSecOps Enablement tools to support Product and Application teams in deploying and using DevSecOps Enablement tooling across SDLC, including but not limited to: SonarQube, GHAS, Sysdig, Snyk, IriusRisk, JFrog Xray, NowSecure, etc.Design and implement automated security testing guardrails (SAST, SCA, Container scanning, etc.) directly into DevOps workflows to enable frictionless, secure software delivery.Experienced in self?service DevOps platforms to automate security via templates for product teamSolid understanding of supply chain security to secure software packages, libraries, container images, etc. via security tools, processes and automations.Core Competencies & Soft Skills:Analytical Thinking: Advanced logical reasoning skills to identify hidden software defects, quality risks, and architectural gaps.Navigating Ambiguity: Proven ability to manage business analysis activities on complex projects where requirements are highly fluid or loosely defined.Strategic Influencing: Exceptional communication skills with a track record of driving consensus among cross-functional stakeholders (Product Owners, Developers, and Business Leads).Systems Thinking: Ability to manage interdependencies, handling the interconnections between various internal and external processes to improve overall delivery efficiency.Wer wir sindEine gesündere Zukunft treibt uns zur Innovation an. Mehr als *** Mitarbeiter weltweit arbeiten gemeinsam daran, wissenschaftliche Fortschritte zu erzielen und sicherzustellen, dass jeder Zugang zur Gesundheitsversorgung hat - heute und für zukünftige Generationen. Durch unser Engagement werden über 26 Millionen Menschen mit unseren Medikamenten behandelt und mehr als 30 Milliarden Tests mit unseren Diagnostik-Produkten durchgeführt. Wir ermutigen uns gegenseitig, neue Möglichkeiten zu erkunden, Kreativität zu fördern und hohe Ziele zu setzen, um lebensverändernde Gesundheitslösungen zu liefern.Gemeinsam können wir eine gesündere Zukunft gestalten.Roche ist ein Arbeitgeber, der die Chancengleichheit fördert.#J-*****-Ljbffr

Requirements

Education: Bachelor’s or Master’s degree in Computer Science, Software Engineering, or a related technical field (or equivalent practical experience). DevSecOps Expertise: Minimum of 8-10+ years of progressive experience, including 3+ years of specialization in building DevSecOps frameworks from scratch. Be a hands?on tools agnostic technical expert on the DevSecOps Enablement tools to support Product and Application teams in deploying and using DevSecOps Enablement tooling across SDLC, including but not limited to: SonarQube, GHAS, Sysdig, Snyk, IriusRisk, JFrog Xray, NowSecure, etc. Design and implement automated security testing guardrails (SAST, SCA, Container scanning, etc.) directly into DevOps workflows to enable frictionless, secure software delivery. Experienced in self?service DevOps platforms to automate security via templates for product team Solid understanding of supply chain security to secure software packages, libraries, container images, etc. via security tools, processes and automations. Core Competencies & Soft Skills: Analytical Thinking: Advanced logical reasoning skills to identify hidden software defects, quality risks, and architectural gaps. Navigating Ambiguity: Proven ability to manage business analysis activities on complex projects where requirements are highly fluid or loosely defined. Strategic Influencing: Exceptional communication skills with a track record of driving consensus among cross-functional stakeholders (Product Owners, Developers, and Business Leads). Systems Thinking: Ability to manage interdependencies, handling the interconnections between various internal and external processes to improve overall delivery efficiency.

Benefits & conditions

Eine gesßndere Zukunft treibt uns zur Innovation an. Mehr als *** Mitarbeiter weltweit arbeiten gemeinsam daran, wissenschaftliche Fortschritte zu erzielen und sicherzustellen, dass jeder Zugang zur Gesundheitsversorgung hat - heute und fßr zukßnftige Generationen. Durch unser Engagement werden ßber 26 Millionen Menschen mit unseren Medikamenten behandelt und mehr als 30 Milliarden Tests mit unseren Diagnostik-Produkten durchgefßhrt. Wir ermutigen uns gegenseitig, neue MÜglichkeiten zu erkunden, Kreativität zu fÜrdern und hohe Ziele zu setzen, um lebensverändernde GesundheitslÜsungen zu liefern. Gemeinsam kÜnnen wir eine gesßndere Zukunft gestalten. Roche ist ein Arbeitgeber, der die Chancengleichheit fÜrdert. #J-*****-Ljbffr

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.buscojobs.com.es
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

1:20 min

Identifying multi-disciplinary talent for developer experience engineering roles

Hazal Mestci +1 ¡ Coffee With Developers

2:17 min

Mapping the maturity roadmap for scaled devops adoption

Dominik Krichbaum Dominik Krichbaum ¡ World Congress 2026 Europe

3:23 min

Building and installing the compiled custom rule extension

Daniel Strmečki +1 · World Congress 2022

1:15 min

Key lessons learned from implementing automated mobile DevSecOps

Moataz Nabil Moataz Nabil ¡ LIVE

2:07 min

Integrating security practices for devsecops adoption

Nevelina Aleksandrova ¡ LIVE

2:09 min

Shifting security left using the DevSecOps approach

Aarno Aukia ¡ LIVE

Videos

See all

Related articles

See all