At Roche you can show up as yourself, embraced for the unique qualities you bring. Our culture encourages personal expression, open dialogue, and genuine connections, where you are valued, accepted and respected for who you are, allowing you to thrive both personally and professionally. This is how we aim to prevent, stop and cure diseases and ensure everyone has access to healthcare today and for generations to come. Join Roche, where every voice matters.
The PositionAbout the Team
You will join the Enterprise Privileged Access Management (PAM) team—a multicultural, global group focused on Identity and Access Management (IAM). While your primary technical focus will be HashiCorp Vault, you will be part of a broader team that collectively manages and supports a diverse enterprise security landscape, including CyberArk and Red Hat IDM.
In this role, you will work with growing autonomy on defined tasks, contribute to various stages of the product lifecycle, and proactively identify solution-level improvements within the PAM domain.
Job Responsibilities
1. Vault Development & Automation
Implement secret management features, integrations, and automation with a primary focus on HashiCorp Vault.
Develop and deploy automation scripts using Python, PowerShell, Ansible, and YAML to streamline day-to-day operations.
Build self-service portals and APIs to facilitate effortless secret usage, empowering application teams and embedding DevSecOps principles into access workflows.
2. Pipeline Integration
Enhance and maintain Infrastructure-as-Code (IaC) toolchains.
Leverage DevOps and CI/CD tools (Jenkins, GitLab, GitHub Actions, Terraform) to integrate secure workflows into major cloud platforms (AWS, Azure, GCP).
3. Operations & Support Excellence
Serve as a Tier 3 technical contact, participating in and leading troubleshooting efforts for complex infrastructure and security tools.
Follow and implement relevant ITIL, GxP, Product Management, and Agile methodologies (Request, Incident, Change, and Problem Management).
Proactively monitor systems for performance, capacity, and vulnerability management.
Provide 24x7 support for major and critical issues (requires flexibility regarding working hours).
4. Stakeholder Management & Collaboration
Collaborate with a global team to improve capabilities for business users and security staff across Vault, CyberArk, and Red Hat IDM.
Identify and engage key technical and business stakeholders to elicit, clarify, and validate security requirements.
Deliver tailored communication, facilitate meetings, and provide clear incident updates.
Qualifications
Minimum Requirements
Education: Bachelor’s Degree in Computer Science, Engineering, a related discipline, or equivalent industry-accredited certifications.
Experience: 1–3 years of experience in an IT operations or security role, preferably within a global organization or regulated environment.
Secrets Management: Strong understanding of PAM concepts, with hands-on experience in HashiCorp Vault.
Automation & Scripting: Proficiency with REST APIs, infrastructure automation (Ansible, Terraform), scripting (Python, PowerShell), and Docker.
Cloud & DevOps: Experience with DevOps practices, IaC toolchain support, and general knowledge of Cloud IAM (AWS, Azure, or GCP).
Language: Strong spoken and written English.
Preferred (Bonus) Skills
Additional PAM Tools: Knowledge or experience supporting CyberArk and/or Red Hat IDM (including Unix Access Management and LDAP).
Network Security: Familiarity with network security concepts, including SSL/TLS protocols, cryptography, key exchanges, cipher suites, and trust validation.
Security Frameworks: Strong grasp of secure development practices, Zero Trust principles, and common web vulnerabilities.
Core Competencies
Communication: Excellent negotiation, documentation, and interpersonal skills; ability to articulate complex technical concepts to both developers and business stakeholders.
Innovation & Autonomy: A mindset for championing secure, automated solutions that enhance developer efficiency, with a proven ability to handle moderate complexity and navigate stakeholder landscapes.
Mentorship: Ability to actively mentor junior teammates and foster a security-first culture.
Who we are
A healthier future drives us to innovate. Together, more than 100’000 employees across the globe are dedicated to advance science, ensuring everyone has access to healthcare today and for generations to come. Our efforts result in more than 26 million people treated with our medicines and over 30 billion tests conducted using our Diagnostics products. We empower each other to explore new possibilities, foster creativity, and keep our ambitions high, so we can deliver life-changing healthcare solutions that make a global impact.
Let’s build a healthier future, together.
Roche is an Equal Opportunity Employer.
Skills Required
- Working knowledge of relevant business domains and supporting cybersecurity technologies.
- Experience investigating security incidents and performing vulnerability assessments.
- Experience conducting stakeholder interviews, synthesizing requirements, and mapping/analyzing processes.
- Ability to independently handle less complex tasks and contribute to stages of the security and business analysis lifecycle.
- Ability to apply tools, principles, and techniques related to requirements, data, usability, and process analysis.
- Skill in evaluating change and technology impacts and breaking down complex technical concepts.
- Strong analytical and logical reasoning and a continuous improvement mindset.
Roche Compensation & Benefits Highlights
The following summarizes recurring compensation and benefits themes identified from responses generated by popular LLMs to common candidate questions about Roche and has not been reviewed or approved by Roche.
-
Retirement Support — U.S. materials describe a 401(k) with both matching and an additional company contribution, supported by formal plan documents and true‑up features. This structure is positioned as a standout element of the total package, particularly at Genentech.
-
Leave & Time Off Breadth — Time‑off provisions include substantial vacation, a year‑end shutdown, and a paid six‑week sabbatical after six years. These elements indicate a recharge‑oriented approach within the U.S. offering.
-
Healthcare Strength — Company materials emphasize comprehensive medical, dental, vision, and mental‑health resources alongside well‑being programs. Benefits pages consistently highlight breadth across core health coverage elements.
Roche Insights
What We Do
Roche is a global pioneer in pharmaceuticals and diagnostics focused on advancing science to improve people’s lives. The combined strengths of pharmaceuticals and diagnostics under one roof have made Roche the leader in personalised healthcare – a strategy that aims to fit the right treatment to each patient in the best way possible. Roche is the world’s largest biotech company, with truly differentiated medicines in oncology, immunology, infectious diseases, ophthalmology and diseases of the central nervous system. Roche is also the world leader in in vitro diagnostics and tissue-based cancer diagnostics, and a frontrunner in diabetes management. Founded in 1896, Roche continues to search for better ways to prevent, diagnose and treat diseases and make a sustainable contribution to society. The company also aims to improve patient access to medical innovations by working with all relevant stakeholders. Thirty medicines developed by Roche are included in the World Health Organization Model Lists of Essential Medicines, among them life-saving antibiotics, antimalarials and cancer medicines. Roche has been recognised as the Group Leader in sustainability within the Pharmaceuticals, Biotechnology & Life Sciences Industry ten years in a row by the Dow Jones Sustainability Indices (DJSI).

.png)




