Cybersecurity Engineer for Network Security observability

3M HEALTHCARE

Madrid

Presencial

EUR 90.000 - 130.000

Jornada completa

14 días+
Generador de candidaturas

No envíes un currículum genérico: crea un currículum y una carta de presentación adaptados a este puesto concreto.

Supera los filtros ATS

Descripción de la vacante

Roche seeks a Lead for Network Security Infrastructure Observability to own the health, availability, and performance of its global security infrastructure. This hands-on technical leadership role requires deep expertise in security engineering and monitoring of core appliances, including firewalls and NAC, across on-prem and cloud environments.

You will architect and operate the observability stack, integrate tools like LogicMonitor and SNMP-based telemetry, and collaborate with Security and

Formación

  • 3-4 years of experience in Network Security Engineering or Infrastructure Reliability.
  • Proven track record designing and operating monitoring for large-scale enterprise security infrastructure.
  • Bachelor's degree in Computer Science, Cyber Security, Information Technology, or related field.

Responsabilidades

  • Infrastructure Architecture, Design & Build: global visibility framework for security appliances.
  • Global Service Operations: operate the global monitoring environment and IaC automation.
  • Operational Excellence: create runbooks, guidance, and collaboration with squads.
  • Proactive maintenance: identify monitoring gaps and update SNMP implementations.
  • Leadership: mentor colleagues and drive security policy visibility initiatives.

Conocimientos

Security engineering
Infrastructure reliability
Network monitoring
Python scripting
Automation (GitLab)
Communication

Educación

Bachelor's in Computer Science

Herramientas

Palo Alto Firewalls
Fortinet Firewalls
Cisco ISE
LogicMonitor
Splunk/Grafana/ELK
SNMP v3
Python
GitLab

Descripción del empleo

At Roche you can show up as yourself, embraced for the unique qualities you bring. Our culture encourages personal expression, open dialogue, and genuine connections, where you are valued, accepted and respected for who you are, allowing you to thrive both personally and professionally. This is how we aim to prevent, stop and cure diseases and ensure everyone has access to healthcare today and for generations to come. Join Roche, where every voice matters.

The Position

The Network & Perimeter Security product makes Roche's connectivity accessible and secure through actionable, policy-driven processes. The capabilities we provide enable Roche to identify, inspect, and mitigate network-based risks, manage regulatory compliance, and oversee egress/ingress traffic across all layers. Our solutions are primarily instantiated through leading-edge security platforms and automated orchestration. We work closely with Cloud, Infrastructure, and Incident Response teams to provide enterprise visibility into Roche's network security posture. You'll be working within the Network Security Product area. This area is accountable for the end-to-end delivery of solutions - designing, building, and maintaining the technologies that protect Roche networks and the Internet, whether on-prem or cloud-based. This includes continuous improvement of capabilities like Internet Security Stack, DDoS Protection, Site-to-Site Connectivity (VPN), Network Access Control and Deep Packet Inspection to stay ahead of an ever-evolving threat landscape.

Job Description

As the Lead for Network Security Infrastructure Observability, you will be the primary architect and engineer responsible for the health, availability, and performance of our global security infrastructure. This is a hands-on technical leadership role that requires a solid foundation in Network Security engineering. You will architect, design, build, and operate the monitoring frameworks that ensure our security platforms (Firewalls, NAC, ZTNA) are running at peak operational efficiency. While your focus is on Infrastructure Reliability, success in this role depends on your deep technical understanding of how security controls—such as packet inspection, encryption, and access policies—impact system performance. By bridging the gap between security hardware/software (Palo Alto, Fortinet, ISE) and modern observability toolchains (LogicMonitor, Python, IaC), you will ensure that the organization's security "engine" is always visible, resilient, and perfectly tuned.

Job Responsibilities
  • 1. Infrastructure Architecture, Design & BuildSecurity-Aware Monitoring Architecture: Architect and design a global visibility framework for understanding the key performance, health, and throughput indicators of core security appliances across services such as Edge Firewalls, Network Access Control (NAC), DDoS Mitigation, Network Authentication, Internal Network Segmentation, and VPNs.
  • 2. Infrastructure Operations & EvolutionGlobal Service Operations: Operate the global monitoring environment, ensuring the continuous health of the observability stack across diverse network segments and security zones.Infrastructure-as-Code (IaC): Leverage APIs and automation (Python/GitLab) to automate the provisioning of monitoring for new security devices, ensuring a "security-first" approach to visibility.Capacity & Performance Management: Analyze long-term infrastructure trends to provide data-driven recommendations for capacity scaling, especially as it relates to resource-intensive security features like SSL Decryption and IPS.Reliability Alerting: Establish and tune proactive alert thresholds that identify hardware or software degradation within the security stack before it impacts service delivery.
  • 3. Operational Excellence & System Visibility
    • Infrastructure Diagnostics: Use tools like Wireshark and SNMP Walk to troubleshoot complex connectivity issues between the observability platform and security devices, resolving MIB/OID mismatches in secured management planes.
    • Technical Reliability Documentation: Develop comprehensive runbooks and technical guides for the ongoing operation, maintenance, and troubleshooting of the monitoring ecosystem.
    • Collaborative Engineering: Partner with Network and Security Engineering squads to align monitoring setups with the deployment of new architectural security standards.
    • Proactive Maintenance: Proactively identify and resolve potential monitoring gaps by staying updated on hardware telemetry updates and the latest secure SNMP (v3) implementation standards.
Qualifications
  • Education / ExperienceSolid Security Foundation: 3-4 years of experience in Network Security Engineering or Infrastructure Reliability, with a deep understanding of firewall architectures and network access control systems.
  • Professional Experience: Proven track record of designing and operating monitoring solutions for large-scale enterprise security infrastructure.
  • Scale & Scope: Proven experience in architecting and operating solutions at a global scale.
  • Educational Background: Bachelor’s degree in Computer Science, Cyber Security, Information Technology, or a related technical field.
Technical Skills
  • Security Infrastructure Mastery: Expert-level knowledge of the operational mechanics and hardware architectures of Palo Alto Firewalls, Fortinet Firewalls, and Cisco ISE.
  • Networking & Security Foundations: Strong foundation in TCP/IP, UDP, and the OSI model, with a specific focus on how security protocols (SSL/TLS, IPsec, RADIUS/TACACS+) interact with management and data planes.
  • Observability Stack: Mastery of LogicMonitor (Collectors, DataSources) and experience with broader toolchains like Splunk, ELK, or Grafana.
  • Network Protocols: Expert knowledge of SNMP (v2c/v3), MIBs, OIDs, and the ability to interpret security-specific device telemetry.
  • DevOps & Automation: Proven ability to automate infrastructure tasks using Python, Groovy, GitLab, and GitLab-CI.
  • Skills below will be considered a plus: Certification: Professional certifications in Network Security (e.g., PCNSE, CCNP Security) or Monitoring (LogicMonitor Certified Professional). Cloud Infrastructure Monitoring: Knowledge of monitoring virtualized security appliances in AWS, Azure, or GCP. Forensic Diagnostics: Proficiency in Wireshark for analyzing management-plane traffic and SNMP communication within secured networks.
Leadership Skills
  • Communication: Strong ability to build trust with network and infrastructure experts and explain complex security policy concepts to non-technical stakeholders.
  • Innovation & Curiosity: A relentless passion for staying ahead of threat actors by researching emerging network security trends and automated enforcement techniques.
  • Thriving in Ambiguity: Ability to navigate global complexity and drive clarity when translating high-level security requirements into functional network policies.
  • Self-Starter: Proven ability to manage technical workstreams from concept to production with minimal supervision, taking full ownership of the Edge Defense product lifecycle.
Additional Qualifications
  • Demonstrated ability to mentor colleagues with less experience and provide guidance on cybersecurity best practices and analysis techniques
  • Strong facilitation, communication, and conflict resolution skills to ensure alignment across multiple product squads and complex stakeholder networks
  • Demonstrated interpersonal, collaborative and commitment to operational excellence skills.
Who we are

A healthier future drives us to innovate. Together, more than 100'000 employees across the globe are dedicated to advance science, ensuring everyone has access to healthcare today and for generations to come. Our efforts result in more than 26 million people treated with our medicines and over 30 billion tests conducted using our Diagnostics products. We empower each other to explore new possibilities, foster creativity, and keep our ambitions high, so we can deliver life-changing healthcare solutions that make a global impact. Let's build a healthier future, together.

Roche is an Equal Opportunity Employer.

Consigue la evaluación confidencial y gratuita de tu currículum.
o arrastra y suelta tu archivo aquí
Similar jobs

Puestos de trabajo similares que vale la pena comparar

Cybersecurity Engineer - Monitoring & Incident Response
Cybersecurity Engineer - Monitoring & Incident Response

Roche • Madrid

Presencial
EUR 70.000 - 100.000
Senior Cybersecurity Engineer for Secure Access Network
Senior Cybersecurity Engineer for Secure Access Network

Roche • Madrid

Presencial
EUR 60.000 - 80.000
Cybersecurity Analyst - RDT Security Platforms
Cybersecurity Analyst - RDT Security Platforms

F. Hoffmann-La Roche AG • Madrid

Presencial
EUR 60.000 - 85.000
Cybersecurity Engineer for Network Security observability
Cybersecurity Engineer for Network Security observability

Roche Holding AG • Madrid

Presencial
EUR 70.000 - 110.000
Cybersecurity Engineer for Edge Defense (Cloud)
Cybersecurity Engineer for Edge Defense (Cloud)

Roche • Madrid

Presencial
EUR 60.000 - 90.000
Expert Security Engineer - Manufacturing Cybersecurity
Expert Security Engineer - Manufacturing Cybersecurity

F. Hoffmann-La Roche AG • Madrid

Híbrido
EUR 95.000 - 130.000
European Network & Engineering Leader
European Network & Engineering Leader

Txo • Madrid

Presencial
EUR 50.000 - 70.000
Cybersecurity Engineer for Internal Network Defense
Cybersecurity Engineer for Internal Network Defense

Roche Holding AG • Madrid

Presencial
EUR 70.000 - 110.000
Cybersecurity Analyst
Cybersecurity Analyst

Roche • Madrid

Presencial
EUR 55.000 - 85.000
Senior Cybersecurity Engineer for Secure Access Network
Senior Cybersecurity Engineer for Secure Access Network

Roche Holding AG • Madrid

Presencial
EUR 90.000 - 130.000