Cybersecurity Analyst Intern

Roche Holding AG

Sant Cugat del Vallès

Presencial

EUR 70.000 - 100.000

Jornada completa

14 días+

Recibe más respuestas de empleadores

Envía un currículum específico para el puesto de trabajo en cuestión de minutos.

Descripción de la vacante

Roche Holding AG à Sant Cugat del Vallès, Espagne, recherche un Threat & Vulnerability Analyst (Product Security). Vous identifierez et évaluerez les vulnérabilités à travers les lignes de produits et leurs logiciels, en utilisant l'automatisation et l'IA pour accélérer les analyses.

Vous collaborez avec les équipes de développement pour prioriser les correctifs, produire des rapports clairs et soutenir l'amélioration continue de la sécurité des produits médicaux et logiciels.

Formación

  • Expérience en gestion des menaces et vulnérabilités dans le domaine produit.
  • Connaissance des systèmes d'évaluation CVSS, SBOM et SCA.
  • Capacité d'automatiser les flux de travail de sécurité (Python, Bash, CI/CD).
  • Capacité à guider les équipes de développement sur la remédiation et la priorisation des correctifs.
  • Excellentes compétences de communication et d'influence auprès des équipes produit.

Responsabilidades

  • Effectuer des évaluations de sécurité complètes des composants produit et des stacks logiciels.
  • Contribuer à l'automatisation de la gestion SBOM et à l'intégration IA en sécurité.
  • Préparer des rapports de risques clairs pour engineering, produit et leadership.
  • Collaborer avec les équipes produit pour comprendre les causes profondes et prioriser les correctifs.
  • Suivre les vecteurs de menace et les standards (CVSS, NIST, OWASP) pour améliorer les outils.

Conocimientos

Gestion des vulnérabilités
Sécurité produit
Automatisation & scripting
Rapports de sécurité
Communication efficace

Descripción del empleo

Chez Roche, vous pouvez être vous-même et être apprécié pour les qualités uniques que vous apportez. Notre culture encourage l'expression personnelle, le dialogue ouvert et les connexions authentiques, où vous êtes valorisé, accepté et respecté pour ce que vous êtes, vous permettant de prospérer tant personnellement que professionnellement. Voici comment nous visons à prévenir, arrêter et guérir les maladies et à garantir à chacun l'accès aux soins de santé aujourd'hui et pour les générations à venir. Rejoignez Roche, où chaque voix compte.

La position
Threat & Vulnerability Analyst (Product Security)

The Opportunity

At Roche, we believe that secure products build trust and save lives. As a Threat & Vulnerability Analyst, you will play a pivotal role in safeguarding our healthcare products, software platforms, and medical technology ecosystem.

You will be responsible for identifying, evaluating, and reporting security vulnerabilities across product lines while leveraging cutting-edge automation and AI-driven methodologies. Working at the intersection of cybersecurity, engineering, and product innovation, you will serve as a trusted security partner to product development teams: helping them understand security risks, prioritize remediations, and continuously strengthen our security posture.

Key Responsibilities
  • Vulnerability Assessment & Analysis: Perform end-to-end security assessments on product components and software stacks, identifying potential security flaws, exposure points, and software risks.
  • Automation & AI Integration: Contribute actively to the automation of Software Bill of Materials (SBOM) vulnerability management workflows and help pioneer AI-augmented vulnerability assessment frameworks to scale security operations.
  • Cross-Stakeholder Reporting: Translate complex technical vulnerabilities into clear, actionable risk reports for engineering, product management, and leadership teams.
  • Product Team Enablement & Remediation Support: Partner directly with product teams to help them comprehend vulnerability root causes and potential impact, collaborate on pragmatic and effective remediation strategies, and assist in prioritizing fixes within development roadmaps.
  • Continuous Improvement: Track emerging threat vectors, zero-days, and security industry standards (such as CVSS, NIST, OWASP) to continuously refine assessment criteria and automated tooling.
Who You Are

You are a proactive, analytical cybersecurity professional who thrives on solving complex technical challenges and communicating security concepts to both technical and non-technical audiences.

Qualifications & Skills:

  • Experience: Proven experience in threat and vulnerability management, product security, application security, or software security analysis.
  • Technical Knowledge: Strong understanding of vulnerability scoring systems (e.g., CVSS), Software Bill of Materials (SBOM) management, software composition analysis (SCA), and common vulnerability frameworks (CVE/CWE).
  • Automation & Scripting: Demonstrated ability or strong interest in automating security workflows (e.g., Python, Bash, CI/CD integrations) and applying emerging AI/ML technologies to security assessments.
  • Remediation Strategy: Ability to guide engineering teams through root-cause analysis and realistic fix prioritization without compromising delivery velocity.
  • Communication & Influence: Excellent written and verbal communication skills, with a track record of building positive, consultative relationships with software and product teams.
Qui nous sommes

Un avenir plus sain nous pousse à innover. Ensemble, plus de 100 000 employés à travers le monde sont dédiés à faire progresser la science et à garantir à chacun l'accès aux soins de santé aujourd'hui et pour les générations à venir. Nos efforts aboutissent à plus de 26 millions de personnes traitées avec nos médicaments et plus de 30 milliards de tests réalisés avec nos produits de Diagnostique. Nous nous encourageons mutuellement à explorer de nouvelles possibilités, à favoriser la créativité et à conserver nos grandes ambitions, afin de fournir des solutions de santé qui changent des vies et ont un impact mondial.

Construisons ensemble un avenir plus sain.

Roche est un employeur offrant l'équité en matière d'emploi.

Consigue la evaluación confidencial y gratuita de tu currículum.
o arrastra y suelta tu archivo aquí
Similar jobs

Puestos de trabajo similares que vale la pena comparar

Security Risk and Audit Specialist - RDT Information Security
Security Risk and Audit Specialist - RDT Information Security

Roche Holding AG • Madrid

Presencial
EUR 55.000 - 85.000
Cybersecurity Engineer for Internal Network Defense
Cybersecurity Engineer for Internal Network Defense

Roche Holding AG • Madrid

Presencial
EUR 70.000 - 110.000
Expert DevSecOps Engineer (Expert Software Development Security Engineer)
Expert DevSecOps Engineer (Expert Software Development Security Engineer)

Roche Holding AG • Madrid

Presencial
EUR 90.000 - 120.000
IT Software Engineer - RDT Engineering Excellence & Experience
IT Software Engineer - RDT Engineering Excellence & Experience

Roche Holding AG • Madrid

Presencial
EUR 90.000 - 120.000
IT Quality & Compliance Expert (Temporary)
IT Quality & Compliance Expert (Temporary)

Roche Holding AG • Madrid

Presencial
EUR 42.000 - 70.000
Cybersecurity Analyst Intern
Cybersecurity Analyst Intern

Roche • Sant Cugat del Vallès

Presencial
EUR 60.000 - 80.000
Cybersecurity Analyst Intern
Cybersecurity Analyst Intern

F. Hoffmann-La Roche AG • Sant Cugat del Vallès

Presencial
EUR 42.000 - 62.000
Technical Lead - Observability - RDT Digital Operations and Reliability
Technical Lead - Observability - RDT Digital Operations and Reliability

Roche Holding AG • Madrid

Presencial
EUR 90.000 - 130.000
IT Infrastructure Engineer
IT Infrastructure Engineer

Roche Holding AG • Madrid

Híbrido
EUR 52.000 - 76.000
Privileged Access Management Developer (HashiVault Focus) - RDT Identity & Access Management
Privileged Access Management Developer (HashiVault Focus) - RDT Identity & Access Management

Roche Holding AG • Madrid

Presencial
EUR 42.000 - 62.000