Senior Security Engineer
hace 7 días
Madrid
ph3Senior Security EngineerbrPosition /h3pThe Senior Security Engineer plays a vital role in protecting Roche Manufacturing systems and networks against cybersecurity threats. This role is responsible for local architecture and engineering support, helping system owners and administrators keep their manufacturing environment up to date with the latest Roche Manufacturing Cybersecurity standards, baselines and industry best practices. /ph3Job Responsibilities /h3pTaking part in technical design reviews, integration, testing, and documentation activities concerning new OT systems and/or changes to existing manufacturing system or infrastructure; supporting development of Manufacturing Cybersecurity standards and baselines; OT Cybersecurity Advisor during OT System planning phase and OT System Risk Assessment process; leveraging secure, corporate‑compliant AI accelerators and enterprise‑ready platforms to automate routine log analysis, scripting, and threat modeling, effectively minimizing defensive response times against machine‑speed cyber threats; advising System Owners in selecting appropriate security measures to mitigate risk; coordinating OT services and activities delivered by Vendors; reviewing local technical designs as part of Manufacturing Cybersecurity Requests (in ServiceNow); designing and sustaining OT Security Monitoring (IIDS) at the Manufacturing Site; providing technical support during Incident Response process including steps to minimize the impact, conducting a technical and forensic investigation into how the breach happened and the extent of the damage; and working closely with System Owners, Cybersecurity Site Representative and acting as a catalyst for cross‑site collaboration on topics related to Manufacturing Cybersecurity. /pulliIndependently manages end‑to‑end security analysis tasks across various capabilities and contributes to more complex problems. /liliMentors more junior team members and contributes to the development of security best practices. /liliIdentifies a diverse range of security stakeholders across functional areas and effectively manages relationships to build reliance through deep business and technical understanding, acting as a trusted advisor. /liliActs as a strategic influencer, defining and driving stakeholder engagement strategies for complex initiatives, facilitating workshops, resolving conflicts, and proactively shaping stakeholder perspectives to align with project goals. /liliDemonstrates strong and consistent performance across diverse products, with an impact that typically extends to a specific product, initiative, or cluster. /liliTranslates requirements into strategic implementation plans that align with overall business objectives, and takes a proactive role in shaping team processes. /liliManages business analysis activities on more complex projects or across multiple products within a domain; capable of handling ambiguous requirements, navigating intricate stakeholder environments, and evaluating solution impacts considering both immediate and longer‑term implications within the domain. /liliDemonstrates a strong understanding of the business domain, related technologies, and their interdependencies. /liliIndependently applies tools, principles, concepts, and techniques related to requirements, data, usability, and process analysis within the security domain. /li /ulh3Qualifications /h3ulliExperience independently managing end‑to‑end security analysis tasks and leading the analysis of moderately complex cybersecurity incidents or vulnerabilities. /liliDemonstrated ability to effectively manage relationships with a diverse range of cross‑functional stakeholders on medium to large‑sized engagements, acting as a trusted advisor. /liliProven track record of championing accountability by example, such as successfully taking on security incident lead and/or security project owner roles. /liliBachelor’s degree in Computing Engineering, Automation Engineering or similar is an asset. /liliMinimum 5 years of experience in the IT Security field. /liliStrong proficiency in independently applying tools, principles, and concepts related to requirements, data, usability, and process analysis within the security domain. /liliAbility to analyze technology fit and propose effective, strategically aligned cybersecurity solutions and controls. /li /ulh3Technical Skills /h3ulliMinimum 5 years of experience in the IT Security field. /liliVery good knowledge about local manufacturing and automation systems in use according to the current industry standards is an asset. /liliHands‑on experience with emerging AI security standards and risk models. /liliExperience utilizing secure, enterprise‑ready AI productivity and engineering tools to automate routine log analysis, scripting, and threat modeling workflows to close the defensive time‑gap against attackers. /liliKnowledge of risk assessment tools, technologies and methods. /liliExpertise in designing secure networks, systems and application architectures. /liliDisaster recovery, computer forensic tools, technologies and methods. /liliSystem administration, supporting multiple platforms and applications. /liliEndpoint security solutions, including file integrity monitoring. /liliDeep understanding of cybersecurity terms and principles (defense‑in‑depth, network segmentation, security monitoring and incident response, access management, OT patch management, secure remote access, anti‑malware protection, etc.). /liliAdvanced knowledge of networking (LAN/WAN) and industrial networking, including significant low‑level networking experience with the TCP/IP (Transmission Control Protocol/Internet Protocol). /liliSolid knowledge of IT and OT infrastructure, including PLC security and protection. /liliCurrent knowledge of technology capabilities and trends; types, and techniques of hacking attacks. /liliProficiency in Java, .NET, C++, Python, Bash, PowerShell. /liliOne of five potential security‑related certifications (Certified Ethical Hacker (CEH), CompTIA Security+, Certified Information System Security Professional (CISSP), ISA/IEC 62443 Cybersecurity Specialist certification, Global Industrial Cyber Security Professional (GICSP)). /liliSolid knowledge of IT infrastructure and service deployment model within Roche. /liliGood knowledge of the Roche IT Security Standards. /li /ulh3Additional Qualifications /h3ulliExpertise in anti‑virus software, intrusion detection, firewalls and content filtering in OT. /liliKnowledge of risk assessment tools, technologies, and methods. /liliExpertise in designing secure networks, systems and application architectures. /liliDisaster recovery, computer forensic tools, technologies, and methods. /liliSystem administration, supporting multiple platforms and applications. /liliEndpoint security solutions, including file integrity monitoring. /liliDeep understanding of cybersecurity terms and principles (defense‑in‑depth, network segmentation, security monitoring and incident response, access management, OT patch management, secure remote access, anti‑malware protection, etc.). /liliAdvanced knowledge of networking (LAN/WAN) and industrial networking including significant low‑level networking experience with the TCP/IP (Transmission Control Protocol/Internet Protocol). /liliSolid knowledge on IT and OT infrastructure, including PLC security and protection. /liliCurrent knowledge of technology capabilities and trends; types, and techniques of hacking attacks. /liliJava, .NET, C++, Python, Bash, PowerShell. /liliCertification: Certified Ethical Hacker (CEH), CompTIA Security+, Certified Information System Security Professional (CISSP), ISA/IEC 62443 Cybersecurity Specialist certification, Global Industrial Cyber Security Professional (GICSP). /liliKnowledge of the Roche IT Security Standards. /li /ulpEqual Opportunity Employer. /p /p #J-18808-Ljbffr