Cybersecurity Engineer for Network Security observability

Hace 4 días

Madrid, Madrid, España Roche Holding AG Jornada completa

Bei Roche kannst du ganz du selbst sein und wirst für deine einzigartigen Qualitäten geschätzt. Unsere Kultur fördert persönlichen Ausdruck, offenen Dialog und echte Verbindungen. Hier wirst du für das, was du bist, wertgeschätzt, akzeptiert und respektiert. Dies schafft ein Umfeld, in dem du sowohl persönlich als auch beruflich wachsen kannst. Gemeinsam wollen wir Krankheiten vorbeugen, stoppen und heilen und sicherstellen, dass jeder Zugang zur Gesundheitsversorgung hat – heute und in Zukunft. Werde Teil von Roche, wo jede Stimme zählt.

Die Position

The Network & Perimeter Security product makes Roche’s connectivity accessible and secure through actionable, policy-driven processes. The capabilities we provide enable Roche to identify, inspect, and mitigate network-based risks, manage regulatory compliance, and oversee egress/ingress traffic across all layers. Our solutions are primarily instantiated through leading-edge security platforms and automated orchestration. We work closely with Cloud, Infrastructure, and Incident Response teams to provide enterprise visibility into Roche’s network security posture.

You’ll be working within the Network Security Product area. This area is accountable for the end-to-end delivery of solutions—designing, building, and maintaining the technologies that protect Roche networks and the Internet, whether on-prem or cloud-based. This includes continuous improvement of capabilities like Internet Security Stack, DDoS Protection, Site-to-Site Connectivity (VPN), Network Access Control and Deep Packet Inspection to stay ahead of an ever-evolving threat landscape.

Job Description

As the Lead for Network Security Infrastructure Observability, you will be the primary architect and engineer responsible for the health, availability, and performance of our global security infrastructure. This is a hands‑on technical leadership role that requires a solid foundation in Network Security engineering. You will architect, design, build, and operate the monitoring frameworks that ensure our security platforms (Firewalls, NAC, ZTNA) are running at peak operational efficiency. While your focus is on Infrastructure Reliability, success in this role depends on your deep technical understanding of how security controls—such as packet inspection, encryption, and access policies—impact system performance. By bridging the gap between security hardware/software (Palo Alto, Fortinet, ISE) and modern observability toolchains (LogicMonitor, Python, IaC), you will ensure that the organization’s security "engine" is always visible, resilient, and perfectly tuned.

Job Responsibilities

1. Infrastructure Architecture, Design & Build

  • Security-Aware Monitoring Architecture: Architect and design a global visibility framework for understanding the key performance, health, and throughput indicators of core security appliances across services such as Edge Firewalls, Network Access Control (NAC), DDoS Mitigation, Network Authentication, Internal Network Segmentation, and VPNs.

  • Observability Engineering: Build and deploy the observability toolchain specifically optimized to monitor the hardware and virtualized instances of Palo Alto, Fortinet, and Cisco ISE.

  • LogicMonitor Development: Hands‑on creation and tuning of DataSources and ConfigSources to capture hardware-level security telemetry (CPU/Data Plane utilization, Session counts, Tunnel health, and HA synchronization).

  • Service Health Dashboarding: Design and build real‑time operational dashboards that provide a clear view of the health, performance, and compliance status of the global security infrastructure.

2. Infrastructure Operations & Evolution

  • Global Service Operations: Operate the global monitoring environment, ensuring the continuous health of the observability stack across diverse network segments and security zones.

  • Infrastructure-as-Code (IaC): Leverage APIs and automation (Python/GitLab) to automate the provisioning of monitoring for new security devices, ensuring a "security-first" approach to visibility.

  • Capacity & Performance Management: Analyze long‑term infrastructure trends to provide data‑driven recommendations for capacity scaling, especially as it relates to resource‑intensive security features like SSL Decryption and IPS.

  • Reliability Alerting: Establish and tune proactive alert thresholds that identify hardware or software degradation within the security stack before it impacts service delivery.

3. Operational Excellence & System Visibility

  • Infrastructure Diagnostics: Use tools like Wireshark and SNMP Walk to troubleshoot complex connectivity issues between the observability platform and security devices, resolving MIB/OID mismatches in secured management planes.

  • Technical Reliab