About this role
Job title: Senior Cybersecurity Engineer for Secure Access Network
About the Role The Senior Cybersecurity Engineer (Network Security) acts as the primary Subject Matter Expert for Secure Access Network Services, driving the evolution of NAC, identity-driven security, segmentation and authentication across Roche's global enterprise. The role ensures the network remains resilient and compliant through Roche's Defense in Depth strategy within a Zero Trust framework.
What You'll Do
- Act as the primary Subject Matter Expert (SME) for Secure Access technologies, evaluating and selecting emerging security tools.
- Drive the long-term technical roadmap for network access aligned with Roche's Zero Trust architecture.
- Partner with business units to translate security requirements into actionable, scalable technical initiatives and policies.
- Provide mentorship and technical leadership to junior engineers.
- Design, deploy, and maintain authentication solutions (802.1X, EAP-TLS, EAP-TEAP, RADIUS, TACACS+, SAML, MFA).
- Integrate security platforms with enterprise IdPs to enable seamless authentication flows.
- Architect and manage highly available authentication services for Roche's global workforce.
- Lead end-to-end lifecycle management of Cisco ISE deployments (upgrades, capacity planning).
- Develop endpoint profiling techniques and implement advanced access control (Dot1x, MAB, Guest Access, posture-based authorization).
- Design and oversee Cisco TrustSec and SGT-based micro-segmentation to reduce the attack surface.
- Serve as senior escalation point for complex incidents; perform root-cause analysis.
- Develop observability, monitoring, and reporting dashboards; ensure security compliance.
- Advocate for IaC and security automation; build API-driven integrations and self-service capabilities.
- Collaborate with globally distributed product squads and stakeholders to deliver integrated security solutions.
What We're Looking For
- Bachelor’s degree in Computer Science, Software Engineering, Information Security, or related field.
- 5+ years of hands-on NAC design, implementation, and management, specifically Cisco ISE.
- Proven experience deploying Palo Alto NGFW with SSL decryption and threat prevention.
- Automation experience using Ansible, Terraform and Python.
- Experience managing security controls in large, global environments with diverse device profiles (IoT, Medical, Corporate).
- Experience in regulated industries (Pharmaceuticals, Healthcare, Finance) is a significant plus.
- Technical Skills: Cisco ISE expert (TrustSec, Dot1x, MAB, Profiling, Guest Portals, REST APIs, complex policies, EAP-TLS, EAP-TEAP); strong understanding of RADIUS/TACACS+; Enterprise PKI and certificate lifecycle management.
- Segmentation Technologies: proficiency in network virtualization and segmentation.
Nice to Have
- Experience in highly regulated environments is a significant plus.
Compensation & Benefits
- Salary and benefits not disclosed in the posting.