Cybersecurity Analyst Intern

Roche

Sant Cugat del Vallès

Presencial

EUR 60.000 - 80.000

Jornada completa

14 días+

Recibe más respuestas de empleadores

Envía un currículum específico para el puesto de trabajo en cuestión de minutos.

Descripción de la vacante

Roche seeks a Threat & Vulnerability Analyst (Product Security) to safeguard healthcare software and devices. You will identify vulnerabilities, assess risk, and report findings to cross-functional partners across engineering and product teams.

You’ll drive automation for SBOM vulnerability management and explore AI-augmented approaches to scale security operations, while collaborating with product teams to prioritize remediation in development roadmaps and strengthen overall security posture.

Formación

  • Experience in threat and vulnerability management, product security, application security, or software security analysis.
  • Strong understanding of vulnerability scoring systems (CVSS), SBOM management, SCA, and common vulnerability frameworks (CVE/CWE).
  • Automation or scripting experience (e.g., Python, Bash) and familiarity with CI/CD integrations.
  • Ability to guide engineering teams through root-cause analysis and realistic fix prioritization.
  • Excellent written and verbal communication skills with cross-functional influence.

Responsabilidades

  • Perform end-to-end security assessments on product components and software stacks, identifying vulnerabilities and risk exposure.
  • Contribute to automation of SBOM vulnerability management workflows and AI-augmented assessment frameworks.
  • Translate complex vulnerabilities into clear, actionable risk reports for engineering and leadership teams.
  • Collaborate with product teams to understand root causes and prioritize fixes within roadmaps.
  • Track threat vectors, CVSS/NIST/OWASP standards to refine assessment criteria and tooling.

Conocimientos

Threat & Vulnerability Mgmt
SBOM management
SCA (Software Composition Analysis)
CVE/CWE knowledge
Automation scripting
Security reporting & communication

Herramientas

Python
CI/CD integrations

Descripción del empleo

At Roche you can show up as yourself, embraced for the unique qualities you bring. Our culture encourages personal expression, open dialogue, and genuine connections, where you are valued, accepted and respected for who you are, allowing you to thrive both personally and professionally. This is how we aim to prevent, stop and cure diseases and ensure everyone has access to healthcare today and for generations to come. Join Roche, where every voice matters.

The Position

Threat & Vulnerability Analyst (Product Security)

The Opportunity

At Roche, we believe that secure products build trust and save lives. As a Threat & Vulnerability Analyst, you will play a pivotal role in safeguarding our healthcare products, software platforms, and medical technology ecosystem.

You will be responsible for identifying, evaluating, and reporting security vulnerabilities across product lines while leveraging cutting-edge automation and AI-driven methodologies. Working at the intersection of cybersecurity, engineering, and product innovation, you will serve as a trusted security partner to product development teams: helping them understand security risks, prioritize remediations, and continuously strengthen our security posture.

Key Responsibilities
  • Vulnerability Assessment & Analysis: Perform end-to-end security assessments on product components and software stacks, identifying potential security flaws, exposure points, and software risks
  • Automation & AI Integration: Contribute actively to the automation of Software Bill of Materials (SBOM) vulnerability management workflows and help pioneer AI-augmented vulnerability assessment frameworks to scale security operations
  • Cross-Stakeholder Reporting: Translate complex technical vulnerabilities into clear, actionable risk reports for engineering, product management, and leadership teams
  • Product Team Enablement & Remediation Support: Partner directly with product teams to help them comprehend vulnerability root causes and potential impact, collaborate on pragmatic and effective remediation strategies, and assist in prioritizing fixes within development roadmaps
  • Continuous Improvement: Track emerging threat vectors, zero-days, and security industry standards (such as CVSS, NIST, OWASP) to continuously refine assessment criteria and automated tooling
Who You Are

You are a proactive, analytical cybersecurity professional who thrives on solving complex technical challenges and communicating security concepts to both technical and non-technical audiences.

Qualifications & Skills
  • Experience: Proven experience in threat and vulnerability management, product security, application security, or software security analysis
  • Technical Knowledge: Strong understanding of vulnerability scoring systems (e.g., CVSS), Software Bill of Materials (SBOM) management, software composition analysis (SCA), and common vulnerability frameworks (CVE/CWE)
  • Automation & Scripting: Demonstrated ability or strong interest in automating security workflows (e.g., Python, Bash, CI/CD integrations) and applying emerging AI/ML technologies to security assessments
  • Remediation Strategy: Ability to guide engineering teams through root-cause analysis and realistic fix prioritization without compromising delivery velocity
  • Communication & Influence: Excellent written and verbal communication skills, with a track record of building positive, consultative relationships with software and product teams
Who we are

A healthier future drives us to innovate. Together, more than 100’000 employees across the globe are dedicated to advance science, ensuring everyone has access to healthcare today and for generations to come. Our efforts result in more than 26 million people treated with our medicines and over 30 billion tests conducted using our Diagnostics products. We empower each other to explore new possibilities, foster creativity, and keep our ambitions high, so we can deliver life-changing healthcare solutions that make a global impact.

Let’s build a healthier future, together.

Roche is an Equal Opportunity Employer.

Consigue la evaluación confidencial y gratuita de tu currículum.
o arrastra y suelta tu archivo aquí
Similar jobs

Puestos de trabajo similares que vale la pena comparar

Cybersecurity Analyst Intern
Cybersecurity Analyst Intern

F. Hoffmann-La Roche AG • Sant Cugat del Vallès

Presencial
EUR 42.000 - 62.000
Cybersecurity Analyst
Cybersecurity Analyst

Roche • Madrid

Presencial
EUR 55.000 - 85.000
Cybersecurity Analyst Intern
Cybersecurity Analyst Intern

Roche Holding AG • Sant Cugat del Vallès

Presencial
EUR 70.000 - 100.000
Threat & Vulnerability Analyst Intern — Product Security
Threat & Vulnerability Analyst Intern — Product Security

Roche • Sant Cugat del Vallès

Presencial
EUR 60.000 - 80.000
Cybersecurity Analyst –IAM ID Verification & External Collaborators
Cybersecurity Analyst –IAM ID Verification & External Collaborators

Roche • Madrid

Presencial
EUR 40.000 - 60.000
Security Risk and Audit Specialist - RDT Information Security
Security Risk and Audit Specialist - RDT Information Security

Roche • Madrid

Presencial
EUR 70.000 - 110.000
Cybersecurity Engineer for Edge Defense (Cloud)
Cybersecurity Engineer for Edge Defense (Cloud)

Roche • Madrid

Presencial
EUR 60.000 - 90.000
Cybersecurity Engineer - Endpoint
Cybersecurity Engineer - Endpoint

Roche • Madrid

Presencial
EUR 55.000 - 85.000
Expert DevSecOps Engineer (Expert Software Development Security Engineer)
Expert DevSecOps Engineer (Expert Software Development Security Engineer)

Roche • Madrid

Presencial
EUR 70.000 - 110.000
Expert DevSecOps Engineer (Expert Software Development Security Engineer)
Expert DevSecOps Engineer (Expert Software Development Security Engineer)

F. Hoffmann-La Roche AG • Madrid

Presencial
EUR 90.000 - 130.000