Threat & Vulnerability Analyst

Roche
Spain
about 2 months ago
Apply on es.trabajo.org
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Working hours
Regular working hours
Job source

Tech stack

Artificial Intelligence Application Integration Architecture Computing Platforms Bash Shell Cyber Security Python (Programming Language) Machine Learning Open Web Application Security Software Vulnerability Management Software Security Vulnerability Analysis

Job description

Chez Roche, vous pouvez être vous-même et être apprécié pour les qualités uniques que vous apportez. Notre culture encourage l’expression personnelle, le dialogue ouvert et les connexions authentiques, où vous êtes valorisé, accepté et respecté pour ce que vous êtes, vous permettant de prospérer tant personnellement que professionnellement. Voici comment nous visons à prévenir, arrêter et guérir les maladies et à garantir à chacun l’accès aux soins de santé aujourd’hui et pour les générations à venir. Rejoignez Roche, où chaque voix compte. La position Threat & Vulnerability Analyst (Product Security) The Opportunity At Roche, we believe that secure products build trust and save lives. As a Threat & Vulnerability Analyst, you will play a pivotal role in safeguarding our healthcare products, software platforms, and medical technology ecosystem. You will be responsible for identifying, evaluating, and reporting security vulnerabilities across product lines while leveraging cutting-edge automation and AI-driven methodologies. Working at the intersection of cybersecurity, engineering, and product innovation, you will serve as a trusted security partner to product development teams: helping them understand security risks, prioritize remediations, and continuously strengthen our security posture. Key Responsibilities - Vulnerability Assessment & Analysis: Perform end-to-end security assessments on product components and software stacks, identifying potential security flaws, exposure points, and software risks. - Automation & AI Integration: Contribute actively to the automation of Software Bill of Materials (SBOM) vulnerability management workflows and help pioneer AI-augmented vulnerability assessment frameworks to scale security operations. - Cross-Stakeholder Reporting: Translate complex technical vulnerabilities into clear, actionable risk reports for engineering, product management, and leadership teams. - Product Team Enablement & Remediation

Requirements

Support: Partner directly with product teams to help them comprehend vulnerability root causes and potential impact, collaborate on pragmatic and effective remediation strategies, and assist in prioritizing fixes within development roadmaps. - Continuous Improvement: Track emerging threat vectors, zero-days, and security industry standards (such as CVSS, NIST, OWASP) to continuously refine assessment criteria and automated tooling. Who You Are You are a proactive, analytical cybersecurity professional who thrives on solving complex technical challenges and communicating security concepts to both technical and non-technical audiences. Qualifications & Skills: - Experience: Proven experience in threat and vulnerability management, product security, application security, or software security analysis. - Technical Knowledge: Strong understanding of vulnerability scoring systems (e.g., CVSS), Software Bill of Materials (SBOM) management, software composition analysis (SCA), and common vulnerability frameworks (CVE/CWE). - Automation & Scripting: Demonstrated ability or strong interest in automating security workflows (e.g., Python, Bash, CI/CD integrations) and applying emerging AI/ML technologies to security assessments. - Remediation Strategy: Ability to guide engineering teams through root-cause analysis and realistic fix prioritization without compromising delivery velocity. - Communication & Influence: Excellent written and verbal communication skills, with a track record of building positive, consultative relationships with software and product teams. Qui nous sommes Un avenir plus sain nous pousse à innover. Ensemble, plus de 100 000 employés à travers le monde sont dédiés à faire progresser la science et à garantir à chacun l’accès aux soins de santé aujourd’hui et pour les générations à venir. Nos efforts aboutissent à plus de 26 millions de personnes traitées avec nos médicaments et plus de 30 milliards de tests réalisés avec nos produits de Diagnostique. Nous nous encourageons mutuellement à explorer de nouvelles possibilités, à favoriser la créativité et à conserver nos grandes ambitions, afin de fournir des solutions de santé qui changent des vies et ont un impact mondial. Construisons ensemble un avenir plus sain. Roche est un employeur offrant l’équité en matière d’emploi.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on es.trabajo.org
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

4:01 min

Finding personal fulfillment in the cybersecurity industry

LIVE

3:52 min

Avoiding remote code execution from unsanitized inputs

Alexander Pirker · World Congress 2022

2:36 min

Applying supervised machine learning for practical rule extraction

Katja Träumner

4:11 min

Introduction to cloud-native application developer security

Micah Silverman · World Congress 2022

2:47 min

Exploring career opportunities and recruitment open positions

Kurt Eder · LIVE

54 sec

Interpreting complex terminal commands safely using external explanation utilities

Dan Cranney +2 · LIVE

Videos

See all

Related articles

See all