Security Engineer - Vulnerability & Exposure Management

Roche

Petaling Jaya

On-site

MYR 90,000 - 150,000

Full time

8 days ago
Application generator

A complete application in a minute — tailored resume and cover letter, ready to send.

Get past ATS filters

Job summary

Roche Malaysia seeks a Security Engineer in the MIR team to identify, assess and reduce cybersecurity risks across Roche’s global environment, protecting networks, systems, and users from evolving threats. You will triage vulnerabilities, drive remediation with infrastructure, cloud, and application teams, and enhance security tooling and automation through scripts and detection logic.

The role requires strong fundamentals in web, network and cloud security, experience with Python or JavaScript,

Qualifications

  • Associate degree or 5+ years in information security preferred.
  • Strong understanding of web, network, endpoint, and cloud security concepts.

Responsibilities

  • Triage, investigate, and respond to critical vulnerabilities in Roche systems.
  • Evaluate vulnerabilities from scanners and external programs; prioritize remediation.
  • Research emerging threats and assess exploitability against Roche’s attack surface.
  • Collaborate with infrastructure, cloud, application, and security teams to drive remediation actions.
  • Assess systems and web applications using automated and manual testing approaches.
  • Engineer and enhance vulnerability scanning, detection, automation, and monitoring capabilities.
  • Contribute to security monitoring and incident response activities in a global environment.
  • Develop scripts and automation workflows to improve operational efficiency.

Skills

Cybersecurity basics
Vulnerability management
Scripting in Python
Cloud security
Communications

Education

Associate Degree or higher

Tools

Python
JavaScript

Job description

At Roche you can show up as yourself, embraced for the unique qualities you bring. Our culture encourages personal expression, open dialogue, and genuine connections, where you are valued, accepted and respected for who you are, allowing you to thrive both personally and professionally. This is how we aim to prevent, stop and cure diseases and ensure everyone has access to healthcare today and for generations to come. Join Roche, where every voice matters.

The Position

The Global Security Monitoring & Incident Response (MIR) team at Roche is dedicated to protecting our networks, systems, applications, and users from constantly evolving cyber threats. As a Security Engineer within the Vulnerability & Exposure Management team, you will play a critical role in identifying, assessing, prioritizing, and reducing cybersecurity risks across Roche’s global environment.

This role goes beyond reviewing scanner outputs. You will help investigate critical vulnerabilities, assess exploitability, improve security tooling and automation capabilities, and partner with stakeholders globally to strengthen Roche’s security posture.

You will join a collaborative and highly technical cybersecurity team that values innovation, curiosity, continuous learning, and proactive risk reduction.

Your Opportunity

In this role, you will:

  • Triage, investigate, and respond to critical vulnerabilities impacting Roche systems and applications
  • Evaluate and prioritize vulnerabilities identified through security tools and external programs, including bug bounty initiatives
  • Research emerging threats and assess exploitability against Roche’s attack surface
  • Collaborate with infrastructure, cloud, application, and security teams to drive remediation activities
  • Assess company systems and web applications using automated and manual testing approaches
  • Engineer and enhance vulnerability scanning, detection, automation, and monitoring capabilities
  • Contribute to security monitoring and incident response activities within a global environment
  • Develop scripts, detection logic, templates, and automation workflows to improve operational efficiency
  • Support continuous improvement initiatives across vulnerability and exposure management processes
Who you are

You bring a strong cybersecurity foundation combined with analytical thinking, technical curiosity, and a proactive approach to solving complex security challenges.

You also bring:

  • Associate Degree in a relevant field or 5+ years of professional experience in information security, with demonstrated experience triaging, analyzing, and escalating security vulnerabilities
  • Strong understanding of web application, network, endpoint, and cloud security concepts, including vulnerability management or attack surface management within complex enterprise environments
  • Hands-on scripting or programming experience using languages such as Python, JavaScript, or Node.js, with familiarity in security tooling, detection logic, automation, or custom scripting
  • Experience validating vulnerabilities, assessing exploitability, and supporting security monitoring or incident response activities
  • Ability to communicate technical risks effectively to both technical and non-technical stakeholders, while balancing operational priorities and research initiatives
  • Passion for cybersecurity, continuous learning, and emerging security trends, with exposure to open-source security projects or modern AI-assisted engineering workflows considered advantageous
  • Professional fluency in English, with industry certifications related to offensive or application security (e.g., OSCP, GWAPT, OSWE) and enterprise cloud security experience viewed as strong assets
Who we are

A healthier future drives us to innovate. Together, more than 100’000 employees across the globe are dedicated to advance science, ensuring everyone has access to healthcare today and for generations to come. Our efforts result in more than 26 million people treated with our medicines and over 30 billion tests conducted using our Diagnostics products. We empower each other to explore new possibilities, foster creativity, and keep our ambitions high, so we can deliver life-changing healthcare solutions that make a global impact.

Let’s build a healthier future, together.

Roche is an Equal Opportunity Employer.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Security Engineer - Vulnerability & Exposure Management
Security Engineer - Vulnerability & Exposure Management

F. Hoffmann-La Roche AG • Petaling Jaya

On-site
MYR 90,000 - 150,000
Security Engineer - Vulnerability & Exposure Management
Security Engineer - Vulnerability & Exposure Management

Roche Services & Solutions Operations APAC • Selangor

On-site
MYR 90,000 - 150,000
Security Engineer - Vulnerability & Exposure Management
Security Engineer - Vulnerability & Exposure Management

Roche • Petaling Jaya

On-site
MYR 70,000 - 100,000
Vulnerability & Exposure Security Engineer — Threat Remediation
Vulnerability & Exposure Security Engineer — Threat Remediation

F. Hoffmann-La Roche AG • Petaling Jaya

On-site
MYR 90,000 - 150,000
Security Engineer – Vulnerability & Exposure Strategy
Security Engineer – Vulnerability & Exposure Strategy

Roche Services & Solutions Operations APAC • Selangor

On-site
MYR 90,000 - 150,000
Cybersecurity Analyst - Monitoring - Incident Response
Cybersecurity Analyst - Monitoring - Incident Response

Roche • Selangor

On-site
MYR 180,000 - 240,000
Security Engineer - Vulnerability & Exposure (Automation)
Security Engineer - Vulnerability & Exposure (Automation)

Roche • Petaling Jaya

On-site
MYR 90,000 - 150,000
Vulnerability & Monitoring Engineer: Incident Response
Vulnerability & Monitoring Engineer: Incident Response

Roche • Petaling Jaya

On-site
MYR 70,000 - 100,000
T&E Compliance Analyst
T&E Compliance Analyst

F. Hoffmann-La Roche AG • Petaling Jaya

On-site
MYR 67,000 - 112,000
Team Team Lead Engineering Operational Enablement
Team Team Lead Engineering Operational Enablement

Roche • Petaling Jaya

On-site
MYR 519,000 - 661,000