Cybersecurity Engineer for Network Security

Roche

Madrid

Presencial

EUR 50.000 - 70.000

Jornada completa

14 días+

Recibe más respuestas de empleadores

Envía un currículum específico para el puesto de trabajo en cuestión de minutos.

Descripción de la vacante

Roche is seeking a Network Security Engineer to lead high-level and low-level designs for Cisco ISE deployments and manage Palo Alto firewalls. The role demands experience in network access control and a strong technical background in security engineering.

The successful candidate will ensure operational excellence and implement enhancements to the network security infrastructure, using advanced technologies to improve security posture across global regions.

Formación

  • 3+ years of hands-on experience in designing and managing enterprise-grade NAC solutions.
  • Proven experience configuring Palo Alto Next-Generation Firewalls.
  • Experience using Ansible, Terraform, or Python for managing network security.

Responsabilidades

  • Lead high-level and low-level design for Cisco ISE deployments.
  • Serve as primary engineer for Palo Alto NGFW architectures.
  • Identify gaps in security and implement enhancements.

Conocimientos

Cisco ISE
Palo Alto Firewalls
Ansible
Python
REST APIs
Automation

Educación

Bachelor’s degree in Computer Science or related field

Herramientas

LogicMonitor
Splunk

Descripción del empleo

Job Responsibilities
  • Design & Architecture: Lead the high‑level and low‑level design (HLD/LLD) for global Cisco ISE deployments and Wired Access Control (WAC) strategies to ensure seamless, identity‑based security.
  • Palo Alto SME: Serve as the primary engineer for Palo Alto NGFW architectures, including advanced threat prevention, decryption, and secure egress/ingress traffic management.
  • Continuous Improvement: Proactively identify gaps in the current security posture and implement technical enhancements to NAC policies, SGT (TrustSec) propagation, and firewall rule‑sets.
  • Build & Implementation: Act as the lead implementer for complex global migrations and new feature rollouts across the network security stack.
  • Observability Framework Engineering.
  • Full‑Stack Development: Architect and develop a custom framework (front‑end and back‑end) to provide a "single pane of glass" for infrastructure health.
  • Inventory & Integration: Build automated integrations with external data sources (CMDB, IPAM, etc.) to maintain a real‑time, dynamic inventory of all network assets and security nodes.
  • Telemetry Logic: Design custom logic to ingest and visualize telemetry from ISE, WAC, and Palo Alto using APIs, SNMP, and Syslog.
  • Operational Excellence & Visibility.
  • Technical Subject Matter Expertise: Serve as the lead engineer for complex network security escalations, providing root‑cause analysis and implementing long‑term, automated architectural fixes.
  • Security Observability: Develop dashboards and reporting to provide real‑time visibility into the "connected landscape," identifying insecure nodes or unauthorized devices before they can affect the network.
  • Automation & Orchestration: Manage security policies as code while continuously improving automation workflows and cross‑platform orchestration to eliminate manual friction, reduce operational overhead, and ensure consistent, high‑speed security enforcement.
  • Self‑Service & Enablement: Design and build self‑service capabilities that empower internal teams to consume network security controls autonomously and securely.
Qualifications
  • Educational Background: Bachelor’s degree in Computer Science, Software Engineering, Information Security, or a related technical field.
  • Network Access Control Mastery: 3+ years of hands‑on experience in designing, implementing, and managing enterprise‑grade NAC solutions, specifically Cisco ISE.
  • Perimeter & Inspection Expertise: Proven track record in configuring and maintaining Palo Alto Next‑Generation Firewalls (NGFW), including SSL decryption and threat prevention.
  • Automation Engineering: Proven experience using Ansible, Terraform, or Python to manage network security infrastructure at scale.
  • Large‑Scale Infrastructure: Experience managing security controls in complex, global environments involving thousands of diverse device profiles (IoT, Medical, Corporate).
  • Regulated Industry: Experience working in highly regulated environments (e.g., Pharmaceuticals, Healthcare, or Finance) is a significant plus.
Technical Skills
  • Cisco ISE Specialist: Expert‑level knowledge of Cisco ISE, including hands‑on experience with TrustSec, Dot1x, MAB, and profiling.
  • Coding & Integration: Strong scripting skills in Python, PowerShell, or Bash to develop self‑service tools and custom API integrations between security platforms.
  • API & Integration: Deep experience with REST APIs for integrating security platforms with external information sources.
  • Segmentation Technologies: Proficiency in network virtualization and segmentation techniques (such as TrustSec, SGTs, or VRFs) applied to security use cases.
  • Palo Alto Mastery: Proven track record in deploying and troubleshooting Palo Alto Firewalls in complex HA environments (Active/Active and Active/Passive).
  • Network Foundations: Deep understanding of RADIUS, TACACS+, and core routing/switching as they relate to security enforcement.
  • Monitoring Stack: Advanced knowledge of LogicMonitor, Splunk, or similar tools, specifically for creating custom DataSources and dashboards.
  • Architectural Mindset: Ability to design "Defense in Depth" flows that connect device identity to granular network permissions.
  • Skills below will be considered a plus:
    • Infrastructure as Code (IaC): Proficiency in Terraform and GitHub to design and manage reproducible, version‑controlled network security configurations.
    • Engineering & Orchestration: Proven ability to build CI/CD pipelines and automated workflows that streamline cross‑platform security operations and eliminate manual friction.
    • Enterprise Networking: Solid foundation in enterprise networking (L2/L3), including advanced knowledge of routing protocols (BGP, OSPF) and switching (VLANs, VXLAN) to ensure seamless security policy integration.
Leadership Skills
  • Communication: Strong ability to build trust with network and infrastructure experts and explain complex security policy concepts to non‑technical stakeholders.
  • Innovation & Curiosity: A relentless passion for staying ahead of threat actors by researching emerging network security trends and automated enforcement techniques.
  • Thriving in Ambiguity: Ability to navigate global complexity and drive clarity when translating high‑level security requirements into functional network policies.
  • Self‑Starter: Proven ability to manage technical workstreams from concept to production with minimal supervision, taking full ownership of the NAC product lifecycle.
Additional Qualifications
  • Demonstrated ability to mentor colleagues with less experience and provide guidance on cybersecurity best practices and analysis techniques.
  • Strong facilitation, communication, and conflict resolution skills to ensure alignment across multiple product squads and complex stakeholder networks.
  • Demonstrated interpersonal, collaborative and commitment to operational excellence skills.

Roche is an Equal Opportunity Employer.

Consigue la evaluación confidencial y gratuita de tu currículum.
o arrastra y suelta tu archivo aquí
Similar jobs

Puestos de trabajo similares que vale la pena comparar

Cybersecurity Engineer for Network Security observability
Cybersecurity Engineer for Network Security observability

Roche • Madrid

Presencial
EUR 60.000 - 90.000
Cybersecurity Engineer for Network Security observability
Cybersecurity Engineer for Network Security observability

F. Hoffmann-La Roche AG • Madrid

Presencial
EUR 65.000 - 85.000
Senior Cybersecurity Engineer for Secure Access Network
Senior Cybersecurity Engineer for Secure Access Network

F. Hoffmann-La Roche AG • Madrid

Presencial
EUR 60.000 - 80.000
Senior Cybersecurity Engineer for Secure Access Network
Senior Cybersecurity Engineer for Secure Access Network

Roche • Madrid

Presencial
EUR 60.000 - 80.000
Cybersecurity Engineer for Network Security AI
Cybersecurity Engineer for Network Security AI

Roche • Madrid

Presencial
EUR 60.000 - 80.000
Senior Technical Support Engineer (Focused Services)
Senior Technical Support Engineer (Focused Services)

Palo Alto Networks • España

Presencial
EUR 60.000 - 90.000
Healthcare options
On-site gym and wellness
Professional development
+2
Network Security Engineer: NAC, ISE & Palo Alto Expert
Network Security Engineer: NAC, ISE & Palo Alto Expert

Roche • Madrid

Presencial
EUR 50.000 - 70.000
Security Engineer
Security Engineer

MKS PAMP • Barcelona

Presencial
EUR 50.000 - 70.000
Senior Technical Support Engineer (Focused Services, Cortex XSIAM)
Senior Technical Support Engineer (Focused Services, Cortex XSIAM)

Palo Alto Networks • España

Presencial
EUR 42.000 - 66.000
Healthcare plans
On-site gym & wellness facilities
Professional development
Expert, Cybersecurity Architecture and Security Operations
Expert, Cybersecurity Architecture and Security Operations

Schneider Electric • Comunidad de Madrid

Híbrido
EUR 70.000 - 90.000
Flexible schedule
Hybrid work plan
Extended leave options
+4