About this role
Job title: Cybersecurity Engineer for Network Security
About the Role Roche seeks a Network Security Subject Matter Expert to design, build, and operate the security infrastructure protecting Roche networks across on-prem and cloud environments. The role focuses on Cisco ISE, Wired Access Control, and Palo Alto NGFW, and includes developing a custom observability framework for deep visibility into security health and asset inventory.
What You'll Do
- SME for Secure Access (ISE, WAC, Palo Alto): design & architecture (HLD/LLD) for global Cisco ISE deployments and WAC strategies to ensure seamless, identity-based security; Palo Alto NGFW architectures, including advanced threat prevention, decryption, and secure egress/ingress traffic management; identify gaps and implement improvements to NAC policies, SGT propagation, and firewall rule-sets; lead complex global migrations and feature rollouts.
- Observability Framework Engineering: Full-Stack development to architect a custom framework for a single pane of glass for infrastructure health; build automated integrations with external data sources (CMDB, IPAM) to maintain a real-time inventory; design telemetry logic to ingest and visualize data from ISE, WAC, and Palo Alto using APIs, SNMP, and Syslog.
- Operational Excellence & Visibility: provide technical leadership for network security escalations, develop dashboards and reporting for real-time visibility, instrument security policies as code, automate workflows and cross-platform orchestration to reduce manual work, and build self-service capabilities for internal teams.
What We're Looking For
- Educational Background: Bachelor's degree in Computer Science, Software Engineering, Information Security, or a related field.
- NAC Mastery: 3+ years designing, implementing, and managing enterprise-grade NAC solutions, specifically Cisco ISE.
- Perimeter & Inspection Expertise: Proven experience configuring and maintaining Palo Alto NGFWs, including SSL decryption and threat prevention.
- Automation Engineering: Experience with Ansible, Terraform, or Python to manage network security infrastructure at scale.
- Large-Scale Infrastructure: Experience managing security controls in complex, global environments with thousands of device profiles.
- Regulated Industry: Experience in regulated environments (Pharma/Healthcare/Finance) is a plus.
- Technical Skills: Cisco ISE specialist with TrustSec, Dot1x, MAB, Profiling; strong scripting in Python, PowerShell, Bash; API integrations and REST APIs; segmentation technologies (TrustSec, SGTs, VRFs); Palo Alto mastery.