Full-Time

Senior Security Engineer

Updated on 8/1/2026

Roche

Roche

1-10 employees

Global pharmaceuticals and diagnostics company

No salary listed

Madrid, Spain

In Person

Category
IT & Security (1)
Required Skills
TCP/IP
PowerShell
Bash
Python
Incident Response
ServiceNow
CompTIA Security+
Threat modeling
Computer Networking
Java
Cybersecurity
.NET
C/C++

Get referred to Roche

See people who can refer or advise you

Requirements
  • Experience independently managing end-to-end security analysis tasks and leading the analysis of moderately complex cybersecurity incidents or vulnerabilities.
  • Demonstrated ability to effectively manage relationships with a diverse range of cross-functional stakeholders on medium to large-sized engagements, acting as a trusted advisor.
  • Proven track record of championing accountability by example, such as successfully taking on security incident lead and/or security project owner roles.
  • A minimum of 5 years of experience in the Information Technology Security field.
  • Very good knowledge of local manufacturing and automation systems in use according to current industry standards.
  • Hands-on experience with emerging artificial intelligence security standards and risk models, including secure enterprise-ready artificial intelligence productivity and engineering tools for log analysis, scripting, and threat modeling workflows.
  • Strong proficiency in independently applying tools, principles, and concepts related to requirements, data, usability, and process analysis within the security domain.
  • Ability to analyze technology fit and propose effective, strategically aligned cybersecurity solutions and controls.
Responsibilities
  • Take part in technical design reviews, integration, testing, and documentation activities concerning new operational technology systems or changes to existing manufacturing systems or infrastructure.
  • Support the development of Manufacturing Cybersecurity standards and baselines, serve as an Operational Technology Cybersecurity Advisor during the Operational Technology System planning phase, and support the Operational Technology System Risk Assessment process.
  • Leverage secure, corporate-compliant artificial intelligence accelerators and enterprise-ready platforms to automate routine log analysis, scripting, and threat modeling and minimize defensive response times.
  • Advise System Owners in selecting appropriate security measures to mitigate risk.
  • Coordinate operational technology services and activities delivered by vendors.
  • Review local technical designs as part of Manufacturing Cybersecurity Requests in ServiceNow.
  • Design and sustain Operational Technology Security Monitoring at the manufacturing site.
  • Provide technical support during the Incident Response process, including minimizing impact and conducting technical and forensic investigations into how a breach occurred and the extent of the damage.
  • Work closely with System Owners and the Cybersecurity Site Representative and facilitate cross-site collaboration on Manufacturing Cybersecurity topics.
  • Independently manage end-to-end security analysis tasks across various capabilities and contribute to more complex problems.
  • Identify security stakeholders across functional areas and manage relationships to build reliance through business and technical understanding, acting as a trusted advisor.
  • Act as a strategic influencer by defining and driving stakeholder engagement strategies for complex initiatives, facilitating workshops, resolving conflicts, and shaping stakeholder perspectives to align with project goals.
  • Translate requirements into strategic implementation plans aligned with overall business objectives and proactively shape team processes.
  • Manage business analysis activities on more complex projects or across multiple products within a domain.
  • Handle ambiguous requirements, navigate intricate stakeholder environments, and evaluate solution impacts considering immediate and longer-term implications within the domain.
  • Apply tools, principles, concepts, and techniques related to requirements, data, usability, and process analysis and manage interconnections to improve efficiency and effectiveness.
  • Champion accountability by taking on security incident lead and/or security project owner roles.
  • Mentor more junior team members and contribute to the development of security best practices.
  • Demonstrate understanding of the business domain, related technologies, and their interdependencies.
  • Analyze technology fit and propose effective, strategically aligned cybersecurity solutions and controls.
Desired Qualifications
  • A Bachelor's degree in Computing Engineering, Automation Engineering, or a similar field.
  • Expertise in anti-virus software, intrusion detection, firewalls, and content filtering in Operational Technology.
  • Knowledge of risk assessment tools, technologies, and methods.
  • Expertise in designing secure networks, systems, and application architectures.
  • Knowledge of disaster recovery and computer forensic tools, technologies, and methods.
  • Experience with system administration across multiple platforms and applications.
  • Knowledge of endpoint security solutions, including file integrity monitoring.
  • Deep understanding of cybersecurity terms and principles, including defense-in-depth, network segmentation, security monitoring and incident response, access management, Operational Technology patch management, secure remote access, and anti-malware protection.
  • Advanced knowledge of networking, including local area networks, wide area networks, industrial networking, and low-level Transmission Control Protocol/Internet Protocol networking.
  • Knowledge of Information Technology and Operational Technology infrastructure, including programmable logic controller security and protection.
  • Current knowledge of technology capabilities and trends and hacking techniques.
  • Experience with Java, .NET, C++, Python, Bash, and PowerShell.
  • One of the following security-related certifications: Certified Ethical Hacker, CompTIA Security+, Certified Information Systems Security Professional, ISA/IEC 62443 Cybersecurity Specialist, or Global Industrial Cyber Security Professional.
  • Knowledge of Roche Information Technology infrastructure and service deployment models.
  • Knowledge of Roche Information Technology Security Standards.

Roche is a global leader in pharmaceuticals and diagnostics. It develops medicines and diagnostic tools that help detect, monitor, and treat diseases, using research and biotechnology to drive new therapies and tests. Roche combines drug development with in-house diagnostic products to support personalized medicine, where treatments are tailored to individual patients based on test results. Its approach differs from many peers by integrating drug discovery with diagnostic capabilities and by expanding its research through strategic acquisitions (like Genentech) to strengthen its biotechnology and R&D capabilities. The company’s goal is to improve patient outcomes and healthcare worldwide by delivering reliable medicines, accurate diagnostic tests, and data-driven care.

Company Size

1-10

Company Stage

IPO

Headquarters

Basel, Switzerland

Founded

1896

Get referred to Roche

See people who can refer or advise you

Simplify Jobs

Simplify's Take

What believers are saying

  • cobas BV/CV clearance expands Roche’s molecular diagnostics menu in women’s health.
  • Susvimo’s European progress strengthens a differentiated continuous-delivery ophthalmology franchise.
  • Roche’s global scale across 100-plus countries supports commercialization and pipeline deployment.

What critics are saying

  • Susvimo still needs European Commission approval before Roche can monetize the label.
  • Diagnostics products face slow lab adoption and pricing pressure after technical clearance.
  • Patent expirations or biosimilar competition can rapidly erode blockbuster pharmaceutical revenue.

What makes Roche unique

  • Founded in Basel in 1896, Roche built quality-focused pharmaceuticals from the start.
  • Genentech acquisition in 2009 made Roche the world’s largest biotechnology company.
  • Roche leads in in-vitro diagnostics alongside medicines, enabling integrated care platforms.

Help us improve and share your feedback! Did you find this helpful?

Benefits

Performance Bonus

Company News

Dealroom.co
Apr 16th, 2026
SAGA company information, funding & investors

SAGA, providing cancer companion diagnostic testing of tissue and non-invasive monitoring of circulating tumor dna (ctdna). Here you'll find information about their funding, investors and team.

Yahoo Finance
Apr 13th, 2026
Roche receives CE mark for Elecsys NfL blood test to detect neuroinflammation in multiple sclerosis

Roche has received CE mark approval for its Elecsys Neurofilament Light Chain blood test to detect neuroinflammation in adults with relapsing remitting multiple sclerosis. The test measures NfL, a protein released during nerve cell injury, providing insight into neuroaxonal damage associated with the disease. Multiple sclerosis affects over 2.9 million people worldwide. Whilst early and regular monitoring is critical, patients often struggle to access routine MRI scans. The minimally invasive blood test offers a more accessible alternative, complementing clinical assessments and potentially enabling earlier intervention. The test runs on Roche's widely available cobas instruments, delivering standardised results and requiring only a simple blood sample. This reduces the need for patients to travel to specialist centres, making frequent monitoring more practical where traditional testing faces geographic, financial or logistical barriers.

Bizwatch
Apr 12th, 2026
Roche invests $20M in degrader-antibody conjugate platform via C4 Therapeutics deal worth up to $1B

Roche has partnered with C4 Therapeutics to develop degrader-antibody conjugates (DACs), marking a $20 million upfront payment with potential milestone payments exceeding $1 billion. The collaboration targets cancer therapeutics using C4's Torpedo platform. DACs represent a next-generation approach to antibody-drug conjugates (ADCs). Whilst ADCs attach cytotoxic drugs to antibodies, DACs use targeted protein degradation payloads to selectively eliminate specific proteins within cancer cells, potentially reducing toxicity and drug resistance whilst accessing previously difficult targets. Amongst Korean listed companies, Orum Therapeutics leads DAC development, having licensed ORM-6151 to Bristol Myers Squibb in 2023. Y-Biologics partnered with Ubix Therapeutics, whilst Oscotec is developing three DAC pipelines through subsidiary Genosco, targeting technology transfers after 2028.

Yahoo Finance
Mar 30th, 2026
Roche gets FDA clearance for cobas c703 and ISE neo lab testing units with 2,000 tests per hour

Roche has received FDA 510(k) clearance for its cobas c703 and cobas ISE neo analytical units, designed to enhance laboratory efficiency through increased automation and testing capacity. The units are part of Roche's cobas pro integrated solutions platform. The cobas c703 delivers up to 2,000 tests per hour with 70 reagent positions, doubling clinical chemistry throughput whilst reducing reagent reloads. The cobas ISE neo provides up to 1,800 tests per hour with automated maintenance, reducing hands-on time and plastic waste compared to previous systems. Both units feature monthly operator maintenance to improve uptime and help laboratories address staffing shortages and growing test volumes. Roche has over 4,000 cobas analysers installed across the United States.

Yahoo Finance
Mar 30th, 2026
Roche launches cobas MPX-E assay, 4-in-1 donor screening test for HIV, HCV, HBV and HEV

Roche has launched the cobas MPX-E assay, a four-in-one donor screening test that simultaneously detects HIV, Hepatitis C, B and E viruses. The test is now available in countries accepting the CE mark. The assay consolidates detection of four major viral targets into a single workflow, improving laboratory efficiency and reducing costs. It features dual-target detection for HIV-1 and enhanced sensitivity for Hepatitis E, which causes an estimated 20 million infections and 70,000 deaths annually worldwide. The test runs on Roche's fully automated cobas x800 systems, which process over 10 million tests monthly across laboratories globally. The ready-to-load reagents enable up to eight hours of walk-away time. The nucleic acid testing blood screening market is valued at approximately 800 million Swiss francs globally, with an expected annual growth rate of 2% through 2029.