Senior Cloud Security Engineer

Roche
Madrid, Spain
12 days ago
Apply on www.buscojobs.com.es
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience required
3 years minimum
Working hours
Regular working hours
Languages
English

Tech stack

Kubernetes Security Amazon Web Services Microsoft Azure Cloud Computing Cloud Computing Security Cloud Engineering Cyber Security Computer Networks Data Security DevOps Infrastructure as a Service (IaaS) Identity and Access Management
+14 more
Intrusion Detection and Prevention Open Source Technology Platform as a Service (PAAS) Software Engineering Cloud Platform System Multi-Cloud Infrastructure as Code (IaC) Kubernetes Information Technology Prisma Cloud Platform Devsecops Serverless Computing Docker Vulnerability Analysis

Job description

At Roche you can show up as yourself, embraced for the unique qualities you bring.Our culture encourages personal expression, open dialogue, and genuine connections, where you are valued, accepted and respected for who you are, allowing you to thrive both personally and professionally.This is how we aim to prevent, stop and cure diseases and ensure everyone has access to healthcare today and for generations to come.Join Roche, where every voice matters.The PositionWe are a high-performing cybersecurity team tasked with protecting the organization’s computing environments.While our historical stronghold has been managing enterprise Endpoint Detection and Response (EDR), Application Control, and Secure Data Erasure, we are now expanding our focus to secure our dynamic, cloud-native environments.We are looking for a Cloud Security Engineer specializing in Cloud Workload Protection.You will be responsible for securing IaaS, PaaS, containers, and serverless architectures.Working alongside your senior endpoint security colleagues, you will bridge the gap between traditional endpoint defense and modern cloud infrastructure, ensuring our threat detection and application governance standards are seamlessly extended to the cloud.Job Responsibilities- Cloud Workload Protection (CWPP): Architect, deploy, and manage Cloud Workload Protection Platforms (e.G., Prisma Cloud, Microsoft Defender for Cloud, Wiz, or Aqua) across our multi-cloud environment (AWS, Azure, and/or GCP).- Container & Kubernetes Security: Implement runtime defense, vulnerability scanning, and configuration hardening for containerized applications and orchestration platforms (EKS, AKS, GKE).- Extending Core Services to the Cloud: Adapt our existing strategies for EDR and Application Control to function effectively in ephemeral, cloud-native workloads without degrading performance.- DevSecOps Integration: Embed security controls directly into CI/CD pipelines (Shift-Left), ensuring images, registries, and Infrastructure as Code (IaC) templates are scanned and secured before deployment.- Automated Remediation: Develop automated response playbooks for cloud misconfigurations and workload alerts using serverless functions and native cloud APIs.QualificationsEducation / Experience / Technical Skills- Bachelor’s degree in Computer Science, Software Engineering, Cybersecurity, or equivalent practical experience.- 3+ years of dedicated experience securing public cloud workloads, with a strong understanding of the shared responsibility model.- Deep technical knowledge of Docker, Kubernetes, and container orchestration.You should know how to secure a pod, restrict container privileges, and manage network policies.- Proven, hands-on experience deploying and tuning commercial or open-source cloud security platforms (CWPP / CNAPP).- Strong grasp of cloud-native networking (VPCs, Security Groups) and Identity and Access Management (least-privilege roles, service accounts).- Proficiency in written and spoken English (C1 or above level).Additional Qualifications- Bridge Builder: Ability to collaborate closely with DevOps and Cloud Engineering teams, acting as an enabler rather than a roadblock.- Strategic Thinker: Capacity to look at our existing on-premise security policies and intelligently adapt them for ephemeral cloud environments.- Adaptable: Comfortable working in a highly dynamic cybersecurity environment where priorities can shift based on emerging needs.- Team Player: Ability to collaborate effectively with internal and external team mates and stakeholders.- Mentorship: Willingness to cross-train our existing senior endpoint engineers on cloud-native security concepts, while learning from their deep endpoint telemetry expertise.Who we areA healthier future drives us to innovate.Together, more than 100’000 employees across the globe are dedicated to advance science, ensuring everyone has access to healthcare today and for generations to come.Our efforts result in more than 26 million people treated with our medicines and over 30 billion tests conducted using our Diagnostics products.We empower each other to explore new possibilities, foster creativity, and keep our ambitions high, so we can deliver life-changing healthcare solutions that make a global impact.Let’s build a healthier future, together.Roche is an Equal Opportunity Employer.

Requirements

Automated Remediation: Develop automated response playbooks for cloud misconfigurations and workload alerts using serverless functions and native cloud APIs.QualificationsEducation / Experience / Technical Skills- Bachelor’s degree in Computer Science, Software Engineering, Cybersecurity, or equivalent practical experience.

  • 3+ years of dedicated experience securing public cloud workloads, with a strong understanding of the shared responsibility model.
  • Deep technical knowledge of Docker, Kubernetes, and container orchestration. You should know how to secure a pod, restrict container privileges, and manage network policies.

  • Proven, hands-on experience deploying and tuning commercial or open-source cloud security platforms (CWPP / CNAPP).
  • Strong grasp of cloud-native networking (VPCs, Security Groups) and Identity and Access Management (least-privilege roles, service accounts).
  • Proficiency in written and spoken English (C1 or above level). Additional Qualifications- Bridge Builder: Ability to collaborate closely with DevOps and Cloud Engineering teams, acting as an enabler rather than a roadblock.

  • Strategic Thinker: Capacity to look at our existing on-premise security policies and intelligently adapt them for ephemeral cloud environments.
  • Adaptable: Comfortable working in a highly dynamic cybersecurity environment where priorities can shift based on emerging needs.
  • Team Player: Ability to collaborate effectively with internal and external team mates and stakeholders.

About the company

Mentorship: Willingness to cross-train our existing senior endpoint engineers on cloud-native security concepts, while learning from their deep endpoint telemetry expertise.Who we areA healthier future drives us to innovate. Together, more than 100’000 employees across the globe are dedicated to advance science, ensuring everyone has access to healthcare today and for generations to come. Our efforts result in more than 26 million people treated with our medicines and over 30 billion tests conducted using our Diagnostics products. We empower each other to explore new possibilities, foster creativity, and keep our ambitions high, so we can deliver life-changing healthcare solutions that make a global impact.Let’s build a healthier future, together.Roche is an Equal Opportunity Employer.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.buscojobs.com.es
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

1:34 min

Pivoting careers into specialized platform engineering roles

Xavier Portilla Edo · LIVE

2:07 min

Inspecting default bridge architectures and custom Docker networks

Oliver Seitz Oliver Seitz · World Congress 2025

2:17 min

Mapping the maturity roadmap for scaled devops adoption

Dominik Krichbaum Dominik Krichbaum · World Congress 2026 Europe

1:15 min

Key lessons learned from implementing automated mobile DevSecOps

Moataz Nabil Moataz Nabil · LIVE

4:40 min

Assessing common Kubernetes security incidents and misconfigurations

Rico Komenda Rico Komenda · World Congress 2025

2:34 min

Docker sandbox architecture and microVM environment integration

Manuel de la Peña Manuel de la Peña · World Congress 2026 Europe

Videos

See all

Related articles

See all