PAM - Cyberark SME

Roche Holding AG

Madrid

Presencial

EUR 45.000 - 70.000

Jornada completa

14 días+

Recibe más respuestas de empleadores

Envía un currículum específico para el puesto de trabajo en cuestión de minutos.

Descripción de la vacante

Roche Holding AG à Madrid recherche un Analyste en cybersécurité capable d’enquêter sur les incidents, d’évaluer les vulnérabilités et d’améliorer les opérations de sécurité tout en travaillant de manière autonome sur des tâches définies.

Vous prendrez en charge des livrables de sécurité, soutiendrez la conception de solutions et participerez à des initiatives d’amélioration continue, avec des déplacements internationaux occasionnels et une forte orientation résultats.

Formación

  • Expérience solide dans une grande organisation mondiale est souhaitée.
  • Connaissance des concepts ITIL et des méthodologies Agile.
  • Compréhension des principes de sécurité et des pratiques de développement sécurisé.

Responsabilidades

  • Diriger les outils Privileged Access CyberArk et l'automatisation, fournir des consultations et définir la feuille de route pour les initiatives stratégiques.
  • Participer à l'équipe PAM pour gérer et améliorer les capacités PAM pour les utilisateurs métier et le personnel sécurité.
  • Répondre rapidement aux besoins produit et aux demandes clients, mettre en œuvre des changements et des améliorations.
  • Soutenir et fournir des preuves pour les audits et les revues de conformité.
  • Se concentrer sur le développement personnel et élaborer des plans d'action pour progresser.
  • Voyages internationaux occasionnels.
  • Gérer des tâches moins complexes et contribuer à la conception de solutions pour des domaines spécifiques.
  • Se concentrer sur la compréhension du domaine problématique et proposer des options de solution.

Conocimientos

CyberArk PAM
Conjur
HashiCorp Vault
Python
PowerShell
Ansible
YAML
Cloud IAM
DevOps
OWASP

Educación

Bachelor's degree in computer science or related field

Herramientas

CyberArk SaaS
CyberArk Self-Hosted
Conjur
HashiCorp Vault

Descripción del empleo

Chez Roche, vous pouvez être vous-même et être apprécié pour les qualités uniques que vous apportez. Notre culture encourage l'expression personnelle, le dialogue ouvert et les connexions authentiques, où vous êtes valorisé, accepté et respecté pour ce que vous êtes, vous permettant de prospérer tant personnellement que professionnellement. Voici comment nous visons à prévenir, arrêter et guérir les maladies et à garantir à chacun l'accès aux soins de santé aujourd'hui et pour les générations à venir. Rejoignez Roche, où chaque voix compte.

La position

The Cybersecurity Analyst investigates security incidents, performs vulnerability assessments, and contributes to improving security operations

You will be capable of independent work on defined tasks, independently handling less complex tasks and contributing to various stages of the analysis lifecycle

By taking ownership of delivering well-defined requirements and supporting the design of feasible security solutions, you will proactively identify solution-level issues and maintain a mindset of continuous improvement within the security domain

Description of the area
Job Responsibilities
Scope
  • Lead Privileged Access tools CyberArk SelfHosted & SaaS feature implementation, integration and automation. Provide consultations with stakeholders to identify security requirements, provide systems integrations, record and develop roadmap and implementation plans for strategic initiatives.

  • Actively work in an enterprise environment as part of the Privileged Access Management (PAM) team to collectively manage, automate and improve the PAM capabilities for business users and security staff.

  • Promptly respond to product needs and customer requests, implementing changes and enhancements.

  • Support and provide evidence for audits and compliance reviews teams.

  • Actively focus on self-development and create actionable plans to grow.

  • Occasional international travel is required.

  • Independently handles less complex tasks and provides input to solution design by defining and managing requirements for small-scale problem areas

  • Focuses on understanding the problem domain, recommending solution options, and proactively identifying solution-level issues, gaps, or inefficiencies to improve products or processes

Accountability/Problem Solving
  • Participate and lead troubleshooting efforts as part of 2nd or 3rd level support duties.

  • Provide 24x7 on-call support for major and critical issues, demonstrating flexibility regarding working hours.

  • Takes ownership of delivering well-defined requirements and supporting the design of feasible solutions for specific features or components

  • Independently analyzes less complex security technical problems, defines problem scope, contributes to identifying root causes, and provides solutions to a broad range of difficult problems

  • Evaluates change and technology impacts with increasing accuracy, diagnoses gaps, and applies analytical and logical reasoning independently to identify discrepancies and challenge assumptions

Stakeholder Management
  • Identifies key business, technical, and security stakeholders for assigned tasks, analyzing their needs and interests regarding security posture and risk

  • Primarily interacts within security product teams/squads and across Security Operations functions, while establishing rapport and managing realistic security expectations

  • Develops and delivers tailored communication for security tasks and incident updates, facilitates meetings, and proactively engages with stakeholders to elicit, clarify, and validate security requirements

Impact/Strategy
  • Contributes to projects or workgroups by providing well-analyzed requirements and supporting the design of solutions that align with business objectives within their specified area

  • Demonstrates growing autonomy and expertise within their specific domain by translating requirements into a strategic plan with supervision, and may identify opportunities for minor process improvements within their immediate scope

Complexity
  • Works on a product or larger contexts, handling requirements and analysis for specific features or components

  • Can navigate moderate levels of complexity in requirements and stakeholder landscapes

  • Begins to understand sources of influence and analyze business problems/opportunities within this product context, starting to map basic interconnections

Business/Technical ability
  • Stay up-to-date with the latest security tools and techniques and make recommendations for improvements, better design or best practices.

  • Understand, implement, and follow relevant concepts of ITIL, GxP, Product Management and Agile Methodologies. These include Request Management, Incident Management, Change Management, Problem Management, Document Management, Qualification and Validation and Product Management.

  • Maintain infrastructure using CI/CD methodologies.

  • Possesses a working knowledge of the relevant business domain and supporting technologies

  • Understands sources of influence, comprehending internal and external factors affecting the problem space, and is capable of identifying and analyzing basic business problems or opportunities holistically

Qualifications
Education / Experience
  • Robust experience working in a major global organization, preferably in a regulated industry. Bachelor’s Degree in computer science, engineering or related discipline or recognition of prior working experience, which is equivalent to industry accredited certification.

  • Process & ITIL: Solid understanding of enterprise security processes built around ITIL principles, including Incident, Problem, Change, and Request Management.

  • Working knowledge of relevant business domains and supporting cybersecurity technologies

  • Experience in conducting stakeholder interviews, synthesizing requirements, and mapping/analyzing current processes

  • Demonstrated ability to independently handle less complex tasks and contribute to various stages of the security and business analysis lifecycle

Technical Skills
  • Core Technical Skills: Strong hands-on technical skills with a development background, featuring a strong focus on Privileged Access Management and Secrets Management technologies—specifically CyberArk SaaS, Conjur, or HashiCorp Vault.

  • Scripting & Automation: Experience with RestAPI’s usage, Scripting with Python, PowerShell, Ansible and YAML as well as Docker usage.

  • Cloud & DevOps: Experience with DevOps and ability to provide IAC toolchain support. General knowledge in Cloud IAM (AWS, Azure and GCP) and Cloud Secrets Management experience will be an advantage.

  • Security Expertise: Deep expertise in secure development practices, with knowledge of Zero Trust principles and common web vulnerabilities (OWASP Top Ten). Technical IAM experience with robust hands-on skills in debugging and problem-solving across complex security workflows.

  • Network Security: Proficient in advanced network security concepts, including SSL/TLS protocols, cryptography, key exchanges, cipher suites, and trust validation.

  • Ability to apply tools, principles, concepts, and techniques related to requirements, data, usability, and process analysis in practical scenarios

  • Experience investigating security incidents, performing vulnerability assessments, and managing requirements for small-scale problem areas

  • Skill in evaluating change and technology impacts with increasing accuracy, and breaking down complex technical concepts with minimal guidance

Additional Qualifications
  • Communication & Mentorship: Effective communicator who can clearly articulate technical concepts to diverse audiences, including developers, cloud engineers, architects, and business stakeholders. You inspire and mentor a collaborative, security-first culture within the team, driving excellence at every level.

  • Innovation & Delivery: You champion secure, automated solutions that enhance developer efficiency and align with global security goals. You proactively identify and adopt emerging technologies to protect the enterprise against evolving cybersecurity threats. You consistently deliver high-impact results while thriving in a fast-paced, cross‑functional environment, and have a proven ability to balance strong customer focus with a dedication to operational excellence.

  • A mindset of continuous improvement with a proactive approach to identifying solution-level issues, gaps, or inefficiencies

  • Strong analytical and logical reasoning skills to identify discrepancies, challenge assumptions, and confidently present solutions

Qui nous sommes

Un avenir plus sain nous pousse à innover. Ensemble, plus de 100 000 employés à travers le monde sont dédiés à faire progresser la science et à garantir à chacun l'accès aux soins de santé aujourd'hui et pour les générations à venir. Nos efforts aboutissent à plus de 26 millions de personnes traitées avec nos médicaments et plus de 30 milliards de tests réalisés avec nos produits de Diagnostique. Nous nous encourageons mutuellement à explorer de nouvelles possibilités, à favoriser la créativité et à conserver nos grandes ambitions, afin de fournir des solutions de santé qui changent des vies et ont un impact mondial.

Construisons ensemble un avenir plus sain.

Roche est un employeur offrant l'équité en matière d'emploi.

Consigue la evaluación confidencial y gratuita de tu currículum.
o arrastra y suelta tu archivo aquí
Similar jobs

Puestos de trabajo similares que vale la pena comparar

Cybersecurity Engineer for Internal Network Defense
Cybersecurity Engineer for Internal Network Defense

Roche Holding AG • Madrid

Presencial
EUR 70.000 - 110.000
Privileged Access Management Developer (HashiVault Focus) - RDT Identity & Access Management
Privileged Access Management Developer (HashiVault Focus) - RDT Identity & Access Management

Roche Holding AG • Madrid

Presencial
EUR 42.000 - 62.000
Cybersecurity Analyst Intern
Cybersecurity Analyst Intern

Roche Holding AG • Sant Cugat del Vallès

Presencial
EUR 70.000 - 100.000
Technical Lead - Observability - RDT Digital Operations and Reliability
Technical Lead - Observability - RDT Digital Operations and Reliability

Roche Holding AG • Madrid

Presencial
EUR 90.000 - 130.000
Security Risk and Audit Specialist - RDT Information Security
Security Risk and Audit Specialist - RDT Information Security

Roche Holding AG • Madrid

Presencial
EUR 55.000 - 85.000
Expert DevSecOps Engineer (Expert Software Development Security Engineer)
Expert DevSecOps Engineer (Expert Software Development Security Engineer)

Roche Holding AG • Madrid

Presencial
EUR 90.000 - 120.000
IT Software Engineer - RDT Engineering Excellence & Experience
IT Software Engineer - RDT Engineering Excellence & Experience

Roche Holding AG • Madrid

Presencial
EUR 90.000 - 120.000
Data Advisory and Insights Specialist
Data Advisory and Insights Specialist

Roche Holding AG • Madrid

Presencial
EUR 70.000 - 100.000
IT Infrastructure Engineer
IT Infrastructure Engineer

Roche Holding AG • Madrid

Híbrido
EUR 52.000 - 76.000
Senior Specialist Directory Services - RDT Identity & Access Management
Senior Specialist Directory Services - RDT Identity & Access Management

Roche Holding AG • Madrid

Presencial
EUR 90.000 - 120.000