Talent.com
Roche
Cybersecurity Engineer for Network SecurityRoche • madrid, comunidad de madrid, Spain
Cybersecurity Engineer for Network Security

Cybersecurity Engineer for Network Security

Roche • madrid, comunidad de madrid, Spain
Hace 3 días
Descripción del trabajo

Job Responsibilities

  • Design & Architecture: Lead the high‑level and low‑level design (HLD/LLD) for global Cisco ISE deployments and Wired Access Control (WAC) strategies to ensure seamless, identity‑based security.
  • Palo Alto SME: Serve as the primary engineer for Palo Alto NGFW architectures, including advanced threat prevention, decryption, and secure egress/ingress traffic management.
  • Continuous Improvement: Proactively identify gaps in the current security posture and implement technical enhancements to NAC policies, SGT (TrustSec) propagation, and firewall rule‑sets.
  • Build & Implementation: Act as the lead implementer for complex global migrations and new feature rollouts across the network security stack.
  • Observability Framework Engineering.
  • Full‑Stack Development: Architect and develop a custom framework (front‑end and back‑end) to provide a "single pane of glass" for infrastructure health.
  • Inventory & Integration: Build automated integrations with external data sources (CMDB, IPAM, etc.) to maintain a real‑time, dynamic inventory of all network assets and security nodes.
  • Telemetry Logic: Design custom logic to ingest and visualize telemetry from ISE, WAC, and Palo Alto using APIs, SNMP, and Syslog.
  • Operational Excellence & Visibility.
  • Technical Subject Matter Expertise: Serve as the lead engineer for complex network security escalations, providing root‑cause analysis and implementing long‑term, automated architectural fixes.
  • Security Observability: Develop dashboards and reporting to provide real‑time visibility into the "connected landscape," identifying insecure nodes or unauthorized devices before they can affect the network.
  • Automation & Orchestration: Manage security policies as code while continuously improving automation workflows and cross‑platform orchestration to eliminate manual friction, reduce operational overhead, and ensure consistent, high‑speed security enforcement.
  • Self‑Service & Enablement: Design and build self‑service capabilities that empower internal teams to consume network security controls autonomously and securely.

Qualifications

  • Educational Background: Bachelor’s degree in Computer Science, Software Engineering, Information Security, or a related technical field.
  • Network Access Control Mastery: 3+ years of hands‑on experience in designing, implementing, and managing enterprise‑grade NAC solutions, specifically Cisco ISE.
  • Perimeter & Inspection Expertise: Proven track record in configuring and maintaining Palo Alto Next‑Generation Firewalls (NGFW), including SSL decryption and threat prevention.
  • Automation Engineering: Proven experience using Ansible, Terraform, or Python to manage network security infrastructure at scale.
  • Large‑Scale Infrastructure: Experience managing security controls in complex, global environments involving thousands of diverse device profiles (IoT, Medical, Corporate).
  • Regulated Industry: Experience working in highly regulated environments (e.g., Pharmaceuticals, Healthcare, or Finance) is a significant plus.

Technical Skills

  • Cisco ISE Specialist: Expert‑level knowledge of Cisco ISE, including hands‑on experience with TrustSec, Dot1x, MAB, and profiling.
  • Coding & Integration: Strong scripting skills in Python, PowerShell, or Bash to develop self‑service tools and custom API integrations between security platforms.
  • API & Integration: Deep experience with REST APIs for integrating security platforms with external information sources.
  • Segmentation Technologies: Proficiency in network virtualization and segmentation techniques (such as TrustSec, SGTs, or VRFs) applied to security use cases.
  • Palo Alto Mastery: Proven track record in deploying and troubleshooting Palo Alto Firewalls in complex HA environments (Active/Active and Active/Passive).
  • Network Foundations: Deep understanding of RADIUS, TACACS+, and core routing/switching as they relate to security enforcement.
  • Monitoring Stack: Advanced knowledge of LogicMonitor, Splunk, or similar tools, specifically for creating custom DataSources and dashboards.
  • Architectural Mindset: Ability to design "Defense in Depth" flows that connect device identity to granular network permissions.
  • Skills below will be considered a plus:
    • Infrastructure as Code (IaC): Proficiency in Terraform and GitHub to design and manage reproducible, version‑controlled network security configurations.
    • Engineering & Orchestration: Proven ability to build CI/CD pipelines and automated workflows that streamline cross‑platform security operations and eliminate manual friction.
    • Enterprise Networking: Solid foundation in enterprise networking (L2/L3), including advanced knowledge of routing protocols (BGP, OSPF) and switching (VLANs, VXLAN) to ensure seamless security policy integration.

Leadership Skills

  • Communication: Strong ability to build trust with network and infrastructure experts and explain complex security policy concepts to non‑technical stakeholders.
  • Innovation & Curiosity: A relentless passion for staying ahead of threat actors by researching emerging network security trends and automated enforcement techniques.
  • Thriving in Ambiguity: Ability to navigate global complexity and drive clarity when translating high‑level security requirements into functional network policies.
  • Self‑Starter: Proven ability to manage technical workstreams from concept to production with minimal supervision, taking full ownership of the NAC product lifecycle.

Additional Qualifications

  • Demonstrated ability to mentor colleagues with less experience and provide guidance on cybersecurity best practices and analysis techniques.
  • Strong facilitation, communication, and conflict resolution skills to ensure alignment across multiple product squads and complex stakeholder networks.
  • Demonstrated interpersonal, collaborative and commitment to operational excellence skills.

Roche is an Equal Opportunity Employer.

#J-18808-Ljbffr

Crear una alerta de empleo para esta búsqueda

Cybersecurity Engineer for Network Security • madrid, comunidad de madrid, Spain