At Roche you can show up as yourself, embraced for the unique qualities you bring. Our culture encourages personal expression, open dialogue, and genuine connections, where you are valued, accepted and respected for who you are, allowing you to thrive both personally and professionally. This is how we aim to prevent, stop and cure diseases and ensure everyone has access to healthcare today and for generations to come. Join Roche, where every voice matters.
The PositionAs the Principal Enterprise Identity Engineer, you are the ultimate technical authority and visionary for our global Enterprise Identity Management (EIM) and Identity Governance and Administration (IGA) landscape. Moving beyond individual contribution, you will define the multi-year identity strategy, driving zero-trust initiatives across a highly complex, global ecosystem.
Operating at the highest levels of our technical ladder, you will bridge the gap between executive business strategy and deep technical execution. You will architect resilient, massively scalable identity frameworks, mentor senior engineering talent, and lead cross-functional transformations that protect our most critical global assets while enabling frictionless business operations.
Job Responsibilities
Lead the multi-year roadmap and end-to-end technical strategy for enterprise identity, aligning IGA architectures with global security policies and zero-trust frameworks.
Establish and enforce enterprise-wide architecture patterns, engineering standards, and reusable frameworks across identity, cloud, and infrastructure domains.
Architect and oversee the deployment of next-generation, SailPoint-based EIM solutions that operate flawlessly at a massive, distributed scale.
Translate complex security paradigms and regulatory requirements into actionable, board-level technical strategies.
Pioneer the adoption of emerging identity technologies, including decentralized identity, advanced ML-driven access analytics, and complex microservice/API integrations.
Act as the technical cornerstone for the identity organization, mentoring senior engineers and leading Tier 4 escalation and root-cause analysis for catastrophic or highly complex systemic issues.
Qualifications and Core Expertise
Minimum of 12 years of hands-on engineering experience in Cybersecurity and Identity Management, with at least 5 years operating at an enterprise architecture or principal level.
5+ years of experience steering identity strategies in highly regulated, multinational enterprise environments (Healthcare, Finance, or similar industries highly preferred).
Deep-tier technical expertise in SailPoint (IdentityNow/IdentityIQ), encompassing enterprise-scale design, custom development, performance tuning, and global deployment.
Expert-level proficiency in Java and Python for developing highly complex connectors, custom rules, and automated workflows.
Proven track record of architecting integration solutions across complex multi-cloud environments (AWS, Azure, GCP) and profound familiarity with CI/CD pipelines, DevOps methodologies, and microservices.
Deep, authoritative understanding of RBAC, PBAC, Segregation of Duties (SoD), and advanced access governance frameworks.
Exceptional executive presence with the ability to communicate deeply technical concepts to non-technical C-suite stakeholders and lead distributed global engineering teams autonomously.
Education & Certifications
Degree: Bachelor’s or Advanced degree (Master’s preferred) in Computer Science, Cyber Security, Information Technology, or a related field.
Required Certifications: CISSP, CISM, or CIAM is strongly preferred for this leadership level.
Technical Certifications: Advanced certifications in AWS/Azure/GCP Architecture or SailPoint highly desirable.
#RDT
Who we are
A healthier future drives us to innovate. Together, more than 100’000 employees across the globe are dedicated to advance science, ensuring everyone has access to healthcare today and for generations to come. Our efforts result in more than 26 million people treated with our medicines and over 30 billion tests conducted using our Diagnostics products. We empower each other to explore new possibilities, foster creativity, and keep our ambitions high, so we can deliver life-changing healthcare solutions that make a global impact.
Let’s build a healthier future, together.
Roche is an Equal Opportunity Employer.
Skills Required
- Minimum of 12 years of hands-on engineering experience in Cybersecurity and Identity Management, with at least 5 years at an enterprise architecture or principal level
- 5+ years steering identity strategies in highly regulated, multinational enterprise environments (Healthcare, Finance, or similar preferred)
- Deep-tier technical expertise in SailPoint (IdentityNow/IdentityIQ), including enterprise-scale design, custom development, performance tuning, and global deployment
- Expert-level proficiency in Java and Python for developing complex connectors, custom rules, and automated workflows
- Proven experience architecting integrations across multi-cloud environments (AWS, Azure, GCP) and familiarity with CI/CD pipelines, DevOps methodologies, and microservices
- Deep understanding of RBAC, PBAC, Segregation of Duties (SoD), and advanced access governance frameworks
- Ability to translate complex security and regulatory requirements into board-level technical strategies and communicate to C-suite stakeholders
- Experience mentoring senior engineers and leading Tier 4 escalation and root-cause analysis for catastrophic or highly complex systemic issues
- Bachelor's degree in Computer Science, Cyber Security, Information Technology, or related field (Master's preferred)
- Certifications: CISSP, CISM, or CIAM (strongly preferred)
- Advanced technical certifications in AWS/Azure/GCP Architecture or SailPoint (highly desirable)
Roche Compensation & Benefits Highlights
The following summarizes recurring compensation and benefits themes identified from responses generated by popular LLMs to common candidate questions about Roche and has not been reviewed or approved by Roche.
-
Retirement Support — U.S. materials describe a 401(k) with both matching and an additional company contribution, supported by formal plan documents and true‑up features. This structure is positioned as a standout element of the total package, particularly at Genentech.
-
Leave & Time Off Breadth — Time‑off provisions include substantial vacation, a year‑end shutdown, and a paid six‑week sabbatical after six years. These elements indicate a recharge‑oriented approach within the U.S. offering.
-
Healthcare Strength — Company materials emphasize comprehensive medical, dental, vision, and mental‑health resources alongside well‑being programs. Benefits pages consistently highlight breadth across core health coverage elements.
Roche Insights
What We Do
Roche is a global pioneer in pharmaceuticals and diagnostics focused on advancing science to improve people’s lives. The combined strengths of pharmaceuticals and diagnostics under one roof have made Roche the leader in personalised healthcare – a strategy that aims to fit the right treatment to each patient in the best way possible. Roche is the world’s largest biotech company, with truly differentiated medicines in oncology, immunology, infectious diseases, ophthalmology and diseases of the central nervous system. Roche is also the world leader in in vitro diagnostics and tissue-based cancer diagnostics, and a frontrunner in diabetes management. Founded in 1896, Roche continues to search for better ways to prevent, diagnose and treat diseases and make a sustainable contribution to society. The company also aims to improve patient access to medical innovations by working with all relevant stakeholders. Thirty medicines developed by Roche are included in the World Health Organization Model Lists of Essential Medicines, among them life-saving antibiotics, antimalarials and cancer medicines. Roche has been recognised as the Group Leader in sustainability within the Pharmaceuticals, Biotechnology & Life Sciences Industry ten years in a row by the Dow Jones Sustainability Indices (DJSI).







