Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.
Roche Holding AG is seeking a Cybersecurity Engineer for Secure Access Network (Temporary, Fixed Term) in Warsaw. The role focuses on designing, deploying, and maintaining secure network segmentation using Fortinet and Palo Alto firewalls.
You will manage policies, VPNs, and migrations, while providing on-call support and staying ahead of threats. You should have a Bachelor’s in a related field and 3+ years with NGFWs, Fortinet and Palo Alto ecosystems.
At Roche you can show up as yourself, embraced for the unique qualities you bring. Our culture encourages personal expression, open dialogue, and genuine connections, where you are valued, accepted and respected for who you are, allowing you to thrive both personally and professionally. This is how we aim to prevent, stop and cure diseases and ensure everyone has access to healthcare today and for generations to come. Join Roche, where every voice matters.
Cybersecurity Engineer for Secure Access Network (Temporary, Fixed Term)
Description of the area
The Network Security team secures Roche’s global connectivity through policy-driven, automated infrastructure. We are seeking a Network Security Engineer to design, implement, and maintain secure network segmentation environments using Fortinet and Palo Alto firewalls. In this role, you will architect robust firewall solutions, build detailed implementation plans, and seamlessly integrate security controls into existing infrastructure. You will manage firewall deployments, handle complex policies, VPNs, and routing, while executing system migrations and platform upgrades. Additionally, you will troubleshoot advanced network issues, defend against emerging threats, and provide rotating on-call operational support.
This is a temporary, fixed-term position from 1 to 2 years
The Opportunity
Design and develop robust network segmentation strategies and architectures leveraging Fortinet and Palo Alto firewalls to meet business and security requirements.
Create detailed network diagrams, design documents, and implementation plans for new segmentation environments.
Collaborate with network architects to integrate firewall solutions seamlessly into the existing network infrastructure.
Configure, deploy, and manage Fortinet FortiGate and Palo Alto Networks firewalls (including Panorama for Palo Alto, FortiManager for Fortinet).
Implement firewall policies, NAT rules, VPNs (IPSec/SSL), routing, and other security features to enforce segmentation.
Perform migrations and upgrades of existing firewall infrastructure
Troubleshoot complex network and security issues related to firewall configurations and segmentation
Stay current with emerging threats, vulnerabilities, and security technologies.
Available for on‑call support on a rotating schedule.
Who you are:
Education/Experience
Bachelor's degree in Computer Science, Information Security, Cybersecurity, or a related field
3+ years of experience in designing, deploying, and supporting Next-Generation Firewalls with a strong networking background.
Extensive hands‑on experience with Fortinet (FortiGate, FortiManager, FortiAnalyzer, etc.) and a deep understanding of Fortinet's Security Fabric.
Extensive hands‑on experience with Palo Alto Networks (PA-Series, VM-Series, Panorama, App-ID, User-ID, WildFire, Threat Prevention, URL Filtering).
Solid understanding of Security concepts, trends and best practices with experience in validated environments.
Hands‑on technical security skills, operational background, and experience with security technologies and underlying infrastructure.
The ideal candidate will bring previous experience in Manufacturing environments.
Soft skills
Customer-oriented and service-focused.
Self‑motivated and independent.
Strong analytical skills.
Excellent written and spoken English.
Collaborative and proactive team player.
Ability to work in a global team.
Ability to perform well in high‑stress situations.
Additional qualifications
Certifications: Fortinet NSE 4, 5, 7, or 8 or Palo Alto Networks: PCNSA PCNSE
Other relevant certifications: CCNP Security, CISSP
Familiarity with Cloud Platforms such as AWS
Programming and Ops Skills: Python, Perl, Ruby, Powershell.
Agile and DevOps Toolsets: Jenkins, Ansible, Git, GitLab, Terraform
Agile framework / methodologies.
What you get:
Salary range 14 175-26 325 PLN grossbasedon the employment contract.
Annual bonus payment based on your performance.
Dedicated training budget (training, certifications, conferences, diversified career paths etc.).
Recharge Fridays (2 Fridays off per quarter available).
Take time Program (up to 3 months of leave to use for any purpose).
Vacation subsidy available.
Flex Location (possibility to perform our work from different places in the world for a certain period of time).
Take Time for Charity (additional paid leave of maximum 2 weeks to engage in the charity action of your choice).
Private healthcare (LuxMed packages), group life insurance (UNUM) and Multisport.
Stock share purchase additions.
Yearly sales of company laptops and cars and many more!
The expected salary range for this position, based on the primary location of Warsaw Grafit is 170,100.00 PLN - 315,900.00 PLN . Final compensation will be determined by a number of factors, including your skills, experience, qualifications, and location.
This position also offers an attractive benefits package.
Learn more about how we reward our employees at Roche.
A healthier future drives us to innovate. Together, more than 100’000 employees across the globe are dedicated to advance science, ensuring everyone has access to healthcare today and for generations to come. Our efforts result in more than 26 million people treated with our medicines and over 30 billion tests conducted using our Diagnostics products. We empower each other to explore new possibilities, foster creativity, and keep our ambitions high, so we can deliver life-changing healthcare solutions that make a global impact.
Let’s build a healthier future, together.
Roche is an Equal Opportunity Employer.