Cybersecurity Analyst Intern

F. Hoffmann-La Roche AG

Sant Cugat del Vallès

Presencial

EUR 42.000 - 62.000

Jornada completa

14 días+
Generador de candidaturas

No envíes un currículum genérico: crea un currículum y una carta de presentación adaptados a este puesto concreto.

Supera los filtros ATS

Descripción de la vacante

Roche is seeking a Threat & Vulnerability Analyst (Product Security) in Spain to perform end-to-end security assessments on product components and software stacks. The role emphasizes automation of SBOM vulnerability workflows and AI-augmented security approaches, with reporting to engineering, product, and leadership teams.

You will collaborate with product teams to prioritize fixes, track emerging threat vectors, and apply standards like CVSS, NIST, and OWASP to continuously improve tooling

Formación

  • Experience in threat and vulnerability management, product security, or software security analysis.
  • Strong understanding of vulnerability scoring (CVSS), SBOM, SCA, and CVE/CWE frameworks.
  • Interest in automating security workflows with Python, Bash, and CI/CD.
  • Ability to guide engineering teams in root-cause analysis and prioritization without compromising delivery velocity.
  • Excellent written and verbal communication with product teams.

Responsabilidades

  • Perform end-to-end security assessments on product components and software stacks.
  • Automate SBOM vulnerability management workflows and AI-augmented frameworks.
  • Translate vulnerabilities into clear risk reports for engineering, product management, and leadership teams.
  • Partner with product teams to plan remediation within development roadmaps.
  • Track threat vectors and align with CVSS, NIST, OWASP to refine tooling and criteria.

Conocimientos

Threat management
Vulnerability management
Product security
App security
SBOM
SCA
CVSS
CVE/CWE
Automation
Python
CI/CD
Communication

Herramientas

CI/CD

Descripción del empleo

At Roche you can show up as yourself, embraced for the unique qualities you bring. Our culture encourages personal expression, open dialogue, and genuine connections, where you are valued, accepted and respected for who you are, allowing you to thrive both personally and professionally. This is how we aim to prevent, stop and cure diseases and ensure everyone has access to healthcare today and for generations to come. Join Roche, where every voice matters.

The Position Threat & Vulnerability Analyst (Product Security) The Opportunity
Key Responsibilities
  • Vulnerability Assessment & Analysis: Perform end-to-end security assessments on product components and software stacks, identifying potential security flaws, exposure points, and software risks.
  • Automation & AI Integration: Contribute actively to the automation of Software Bill of Materials (SBOM) vulnerability management workflows and help pioneer AI-augmented vulnerability assessment frameworks to scale security operations.
  • Cross-Stakeholder Reporting: Translate complex technical vulnerabilities into clear, actionable risk reports for engineering, product management, and leadership teams.
  • Product Team Enablement & Remediation Support: Partner directly with product teams to help them comprehend vulnerability root causes and potential impact, collaborate on pragmatic and effective remediation strategies, and assist in prioritizing fixes within development roadmaps.
  • Continuous Improvement: Track emerging threat vectors, zero-days, and security industry standards (such as CVSS, NIST, OWASP) to continuously refine assessment criteria and automated tooling.
Who You Are

You are a proactive, analytical cybersecurity professional who thrives on solving complex technical challenges and communicating security concepts to both technical and non-technical audiences.

Qualifications & Skills
  • Experience: Proven experience in threat and vulnerability management, product security, application security, or software security analysis.
  • Technical Knowledge: Strong understanding of vulnerability scoring systems (e.g., CVSS), Software Bill of Materials (SBOM) management, software composition analysis (SCA), and common vulnerability frameworks (CVE/CWE).
  • Automation & Scripting: Demonstrated ability or strong interest in automating security workflows (e.g., Python, Bash, CI/CD integrations) and applying emerging AI/ML technologies to security assessments.
  • Remediation Strategy: Ability to guide engineering teams through root-cause analysis and realistic fix prioritization without compromising delivery velocity.
  • Communication & Influence: Excellent written and verbal communication skills, with a track record of building positive, consultative relationships with software and product teams.
Who we are

A healthier future drives us to innovate. Together, more than 100'000 employees across the globe are dedicated to advance science, ensuring everyone has access to healthcare today and for generations to come.

Our efforts result in more than 26 million people treated with our medicines and over 30 billion tests conducted using our Diagnostics products.

We empower each other to explore new possibilities, foster creativity, and keep our ambitions high, so we can deliver life-changing healthcare solutions that make a global impact.

Lets build a healthier future, together.

Roche is an Equal Opportunity Employer.

We believe it's urgent to deliver medical solutions right now - even as we develop innovations for the future.

We are passionate about transforming patients' lives.

We are courageous in both decision and action.

And we believe that good business means a better world. That is why we come to work each day.

We commit ourselves to scientific rigor, unassailable ethics, and access to medical innovations for all.

We do this today to build a better tomorrow.

We are proud of who we are, what we do, and how we do it.

We are many, working as one across functions, across companies, and across the world.

We are Roche.

Consigue la evaluación confidencial y gratuita de tu currículum.
o arrastra y suelta tu archivo aquí
Similar jobs

Puestos de trabajo similares que vale la pena comparar

Cybersecurity Analyst Intern
Cybersecurity Analyst Intern

Roche • Sant Cugat del Vallès

Presencial
EUR 60.000 - 80.000
Cybersecurity Analyst
Cybersecurity Analyst

Roche • Madrid

Presencial
EUR 55.000 - 85.000
External Workforce Identity - External Collaborators & Id Verification - Rdt Identity & Access Manag
External Workforce Identity - External Collaborators & Id Verification - Rdt Identity & Access Manag

Roche & Company • Madrid

Presencial
EUR 65.000 - 80.000
PAM - Cyberark SME
PAM - Cyberark SME

F. Hoffmann-La Roche AG • Madrid

Presencial
EUR 42.000 - 64.000
Cybersecurity Analyst –IAM ID Verification & External Collaborators
Cybersecurity Analyst –IAM ID Verification & External Collaborators

Roche • Madrid

Presencial
EUR 40.000 - 60.000
Cybersecurity Analyst Intern
Cybersecurity Analyst Intern

Roche Holding AG • Sant Cugat del Vallès

Presencial
EUR 70.000 - 100.000
Cybersecurity Engineer - Monitoring & Incident Response
Cybersecurity Engineer - Monitoring & Incident Response

Roche & Company • Madrid

Presencial
EUR 65.000 - 90.000
Threat & Vulnerability Analyst Intern — Product Security
Threat & Vulnerability Analyst Intern — Product Security

Roche • Sant Cugat del Vallès

Presencial
EUR 60.000 - 80.000
Expert DevSecOps Engineer (Expert Software Development Security Engineer)
Expert DevSecOps Engineer (Expert Software Development Security Engineer)

F. Hoffmann-La Roche AG • Madrid

Presencial
EUR 90.000 - 130.000
Security Risk and Audit Specialist - RDT Information Security
Security Risk and Audit Specialist - RDT Information Security

Roche • Madrid

Presencial
EUR 70.000 - 110.000