Expert DevSecOps Engineer (Expert Software Development Security Engineer)

Posted 10 Days Ago
Be an Early Applicant
Madrid, Comunidad de Madrid, ESP
In-Office
Senior level
Healthtech • Biotech • Pharmaceutical
The Role
Lead design and implementation of DevSecOps frameworks and automated security testing (SAST, SCA, container scanning, IaC). Drive threat modeling, supply chain security, tool integration, stakeholder influence, and mentor engineers while aligning practices with enterprise security and compliance.
Summary Generated by Built In

At Roche you can show up as yourself, embraced for the unique qualities you bring. Our culture encourages personal expression, open dialogue, and genuine connections,  where you are valued, accepted and respected for who you are, allowing you to thrive both personally and professionally. This is how we aim to prevent, stop and cure diseases and ensure everyone has access to healthcare today and for generations to come. Join Roche, where every voice matters.

The Position

As an Expert DevSecOps Engineer, acting as a Software Development Security Expert, you will  sit at the intersection of software and security engineering. You are accountable for designing robust software development security frameworks, handling ambiguous security and compliance requirements, managing complex stakeholder landscapes, and mentoring junior engineers. You will also collaborate with the area architect in defining the long-term architecture for software engineering security solutions.

Description of the area:

Engineering Excellence & Experience (E3) enables engineers to explore, plan, design, code, build, test, and deploy software packages in a reliable, secure, automated, and consistent manner across our different business areas. This includes providing facilitated access to automated, composable infrastructure consumable through Infrastructure as Code (IaC) and APIs, both on-premises and in the public cloud.

Within E3, you will join the Embedded Security & Testing Team, which champions the integration of testing and security concepts throughout the software development lifecycle. Specifically, the Code Quality, Security, and Testing Engineering team combines best practices and modern solutions to ensure that all code generated is secure and of the highest quality. The team provides a range of DevSecOps components fit for diverse technical complexities, delivers Proofs of Concept (PoCs), and supports internal adoption both during and after implementation.

Job Responsibilities:Scope:
  • Provides expert-level leadership and strategic guidance in DevSecOps area, including Threat Modelling, Code Quality, SAST, Secret Scanning, Software Composition Analysis, IaC Scanning, License Compliance, Dependency Management, Container Image Scanning, API Security and Container Runtime Scanner.

  • Participate in the definition of  Software Security best practices, ensuring consistency, traceability, and alignment with enterprise standards

  • Leads DevSecOps efforts on strategic activities and provides guidance to less experienced members.

Problem Solving:
  • Leads the analysis of complex and strategic business problems, defining the problem space and driving comprehensive root cause analysis that may span organizational boundaries

  • Works on unusually complex problems, provides highly innovative solutions, and applies expert-level analytical and logical reasoning to proactively identify strategic opportunities and risks

Stakeholder Management & Strategic Influence:
  • Builds and maintains strong relationships with key stakeholders and cultivates collaboration across the organization

  • Elicits and analyzes complex stakeholder needs with expertise, and influences business stakeholders to inform and make the right decisions

  • Shapes strategy as a trusted advisor to leadership, acting as an influential partner and organizational trust builder

  • Recommends and guides the implementation of optimal strategies, transitions, and future states, fostering a culture of strategic innovation and continuous improvement within their product line or domain

Leadership, Accountability & Mentorship:
  • Evaluates strategic solution alternatives through rigorous risk assessment and value analysis, ensuring key initiatives align with overall organizational objectives, and recommends optimal technology solutions to drive business transformation.

  • Is accountable for deliverables on significant projects, ensuring alignment with strategic objectives, defining strategic solution scope, and managing complexity

  • Mentors colleagues, helps others develop expertise and skills, and provides guidance to other Experts

  • Actively contributes to organizational development, including showing leadership in Communities of Practice (CoPs).

  • Understands and balances strict security compliances without slowing down developers.

Qualifications & Experience:Required Technical Experience:
  • Education: Bachelor’s or Master’s degree in Computer Science, Software Engineering, or a related technical field (or equivalent practical experience).

  • DevSecOps Expertise: Minimum of 8-10+ years of progressive experience, including 3+ years of specialization in building DevSecOps frameworks from scratch.

  • Be a hands-on tools agnostic technical expert on the DevSecOps Enablement tools to support Product and Application teams in deploying and using DevSecOps Enablement tooling across SDLC, including but not limited to: SonarQube, GHAS, Sysdig, Snyk,  IriusRisk, JFrog Xray, NowSecure, etc. 

  • Design and implement automated security testing guardrails (SAST, SCA, Container scanning, etc.) directly into DevOps workflows to enable frictionless, secure software delivery. 

  • Experienced in self-service DevOps platforms to automate security via templates for product team

  • Solid understanding of supply chain security to secure software packages, libraries, container images, etc. via security tools, processes and automations. 

Core Competencies & Soft Skills:
  • Analytical Thinking: Advanced logical reasoning skills to identify hidden software defects, quality risks, and architectural gaps.
  • Navigating Ambiguity: Proven ability to manage business analysis activities on complex projects where requirements are highly fluid or loosely defined.

  • Strategic Influencing: Exceptional communication skills with a track record of driving consensus among cross-functional stakeholders (Product Owners, Developers, and Business Leads).

  • Systems Thinking: Ability to manage interdependencies, handling the interconnections between various internal and external processes to improve overall delivery efficiency.

 

 

Who we are

A healthier future drives us to innovate. Together, more than 100’000 employees across the globe are dedicated to advance science, ensuring everyone has access to healthcare today and for generations to come. Our efforts result in more than 26 million people treated with our medicines and over 30 billion tests conducted using our Diagnostics products. We empower each other to explore new possibilities, foster creativity, and keep our ambitions high, so we can deliver life-changing healthcare solutions that make a global impact.


Let’s build a healthier future, together.

Roche is an Equal Opportunity Employer.

Skills Required

  • Bachelor's or Master's degree in Computer Science, Software Engineering, or related field (or equivalent experience)
  • 8-10+ years progressive experience in software and security engineering
  • 3+ years specialization building DevSecOps frameworks from scratch
  • Hands-on experience with SonarQube, GHAS, Sysdig, Snyk, IriusRisk, JFrog Xray, NowSecure (or similar tools)
  • Design and implement automated security testing guardrails (SAST, SCA, container scanning) into CI/CD workflows
  • Experience with Infrastructure as Code (IaC) and IaC scanning integrations
  • Solid understanding of software supply chain security, dependency management, and license compliance
  • Experience enabling self-service DevOps platforms and automation templates for product teams
  • Proven stakeholder management, strategic influencing, and ability to translate complex security requirements
  • Mentorship experience and ability to lead and guide less experienced engineers

Roche Compensation & Benefits Highlights

The following summarizes recurring compensation and benefits themes identified from responses generated by popular LLMs to common candidate questions about Roche and has not been reviewed or approved by Roche.

  • Retirement Support U.S. materials describe a 401(k) with both matching and an additional company contribution, supported by formal plan documents and true‑up features. This structure is positioned as a standout element of the total package, particularly at Genentech.
  • Leave & Time Off Breadth Time‑off provisions include substantial vacation, a year‑end shutdown, and a paid six‑week sabbatical after six years. These elements indicate a recharge‑oriented approach within the U.S. offering.
  • Healthcare Strength Company materials emphasize comprehensive medical, dental, vision, and mental‑health resources alongside well‑being programs. Benefits pages consistently highlight breadth across core health coverage elements.

Roche Insights

Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
Provincia de Buenos Aires
93,797 Employees
Year Founded: 1896

What We Do

Roche is a global pioneer in pharmaceuticals and diagnostics focused on advancing science to improve people’s lives. The combined strengths of pharmaceuticals and diagnostics under one roof have made Roche the leader in personalised healthcare – a strategy that aims to fit the right treatment to each patient in the best way possible. Roche is the world’s largest biotech company, with truly differentiated medicines in oncology, immunology, infectious diseases, ophthalmology and diseases of the central nervous system. Roche is also the world leader in in vitro diagnostics and tissue-based cancer diagnostics, and a frontrunner in diabetes management. Founded in 1896, Roche continues to search for better ways to prevent, diagnose and treat diseases and make a sustainable contribution to society. The company also aims to improve patient access to medical innovations by working with all relevant stakeholders. Thirty medicines developed by Roche are included in the World Health Organization Model Lists of Essential Medicines, among them life-saving antibiotics, antimalarials and cancer medicines. Roche has been recognised as the Group Leader in sustainability within the Pharmaceuticals, Biotechnology & Life Sciences Industry ten years in a row by the Dow Jones Sustainability Indices (DJSI).

Similar Jobs

Celonis Logo Celonis

Intern Business Development (Spanish-Speaking)

Big Data • Information Technology • Productivity • Software • Analytics • Business Intelligence • Consulting
Hybrid
Madrid, Comunidad de Madrid, ESP
3000 Employees

Celonis Logo Celonis

Intern Business Development (German-Speaking)

Big Data • Information Technology • Productivity • Software • Analytics • Business Intelligence • Consulting
Hybrid
Madrid, Comunidad de Madrid, ESP
3000 Employees

ServiceNow Logo ServiceNow

Consultant

Artificial Intelligence • Cloud • HR Tech • Information Technology • Productivity • Software • Automation
Hybrid
Madrid, Comunidad de Madrid, ESP
29000 Employees

Ericsson Logo Ericsson

Product Manager

Cloud • Information Technology • Internet of Things • Machine Learning • Software • Cybersecurity • Infrastructure as a Service (IaaS)
In-Office
5 Locations
88000 Employees

Similar Companies Hiring

Sailor Health Thumbnail
Healthtech • Social Impact • Telehealth
New York City, NY
20 Employees
Granted Thumbnail
Artificial Intelligence • Healthtech • Insurance • Mobile • Financial Services
New York, New York
23 Employees
OneImaging Thumbnail
Healthtech
Miami, FL
62 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account