Roche fosters diversity, equity and inclusion, representing the communities we serve. When dealing with healthcare on a global scale, diversity is an essential ingredient to success. We believe that inclusion is key to understanding people's varied healthcare needs. Together, we embrace individuality and share a passion for exceptional care. Join Roche, where every voice matters.
The Position Data security and privacy are key success factors in our digital transformation and essential to reach our ambitions. You are inspired to contribute to the overall Roche Diagnostics vision by applying end-to-end Division-wide product security and privacy operations to keep our products and services secure and privacy compliant throughout the entire lifecycle. You believe in the potential of science, technology, data and insights to improve the standard of care for humankind and you are eager to help navigate through unchartered territory to lift this potential.
You will be responsible Define security and privacy requirements for Roche products, medical devices or health/clinical solutions both in the cloud and on-premises during all product software development lifecycle.Contribute to the development and support implementation of security and privacy risk management framework across the product lifecycle.Support in the definition, implementation and maintenance of product security and privacy control measures for a product or platform, considering changes in technology, regulations and customer needs.Manage vulnerabilities at all technology layers during pre and post market activities of the product or platform, making sure they are fixed in a timely manner.Support the security testing activities (SCA, SAST, DAST, IAC, etc.) for a given product, helping to automate execution and deliverables and support on the remediation activities.Conduct planning and coordination of external security testing activities (verification & validation) and remediation plans (e.g. pentest).Support security and privacy related documentation with high quality for internal and external compliance.Support security incident response and forensic activities working directly with the Roche Intelligence and Defense teams.Drive security and privacy awareness and knowledge across all departments involved in the product development and operations activities. Your profile BA/BS in Engineering, Computer Science or relevant area of study required.Security industry certifications such as SANS GIAC (GCIH, GPEN, GCIA, GCFA, etc.), CEH, CISSP, CSSP, CISA, etc.Minimum of 7+ years of related work experience in security engineering, security operations, vulnerability management or application security.Demonstrated experience working with product software development and cloud platform teams, preferably in international companies in the healthcare or regulated industries.In-depth experience in analyzing product security posture, threat and risk landscape, performing threat modeling and defining adequate security and data privacy controls to mitigate risks.Demonstrated soft skills: problem solving, analytical mindset, communication, teamwork, flexibility and adaptability.Best in class attitude; challenge status constructively and contribute to improvements; results oriented; ability to influence; solution oriented mindset; problem solving, flexibility and adaptability.Excellent interpersonal skills with high cross-cultural sensitivity; ability to collaborate and communicate across multiple international teams; commitment to working as a team player across Business Areas and Divisions.Fluent in English on a business level with excellent verbal and written skills; other languages welcome, but not required.Travel % required (if applicable): maximum 20% Who we are At Roche, more than 100,000 people across 100 countries are pushing back the frontiers of healthcare. Working together, we've become one of the world's leading research-focused healthcare groups. Our success is built on innovation, curiosity and diversity.
Roche is an Equal Opportunity Employer.
#J-18808-Ljbffr