At Roche you can show up as yourself, embraced for the unique qualities you bring. Our culture encourages personal expression, open dialogue, and genuine connections, where you are valued, accepted and respected for who you are, allowing you to thrive both personally and professionally. This is how we aim to prevent, stop and cure diseases and ensure everyone has access to healthcare today and for generations to come. Join Roche, where every voice matters.
The PositionThe Global Security Monitoring & Incident Response (MIR) team at Roche is dedicated to protecting our networks, systems, applications, and users from constantly evolving cyber threats. As a Security Engineer within the Vulnerability & Exposure Management team, you will play a critical role in identifying, assessing, prioritizing, and reducing cybersecurity risks across Roche’s global environment.
This role goes beyond reviewing scanner outputs. You will help investigate critical vulnerabilities, assess exploitability, improve security tooling and automation capabilities, and partner with stakeholders globally to strengthen Roche’s security posture.
You will join a collaborative and highly technical cybersecurity team that values innovation, curiosity, continuous learning, and proactive risk reduction.
Your OpportunityIn this role, you will:
Triage, investigate, and respond to critical vulnerabilities impacting Roche systems and applications
Evaluate and prioritize vulnerabilities identified through security tools and external programs, including bug bounty initiatives
Research emerging threats and assess exploitability against Roche’s attack surface
Collaborate with infrastructure, cloud, application, and security teams to drive remediation activities
Assess company systems and web applications using automated and manual testing approaches
Engineer and enhance vulnerability scanning, detection, automation, and monitoring capabilities
Contribute to security monitoring and incident response activities within a global environment
Develop scripts, detection logic, templates, and automation workflows to improve operational efficiency
Support continuous improvement initiatives across vulnerability and exposure management processes
You bring a strong cybersecurity foundation combined with analytical thinking, technical curiosity, and a proactive approach to solving complex security challenges.
You also bring:
Associate Degree in a relevant field or 5+ years of professional experience in information security, with demonstrated experience triaging, analyzing, and escalating security vulnerabilities
Strong understanding of web application, network, endpoint, and cloud security concepts, including vulnerability management or attack surface management within complex enterprise environments
Hands-on scripting or programming experience using languages such as Python, JavaScript, or Node.js, with familiarity in security tooling, detection logic, automation, or custom scripting
Experience validating vulnerabilities, assessing exploitability, and supporting security monitoring or incident response activities
Ability to communicate technical risks effectively to both technical and non-technical stakeholders, while balancing operational priorities and research initiatives
Passion for cybersecurity, continuous learning, and emerging security trends, with exposure to open-source security projects or modern AI-assisted engineering workflows considered advantageous
Professional fluency in English, with industry certifications related to offensive or application security (e.g., OSCP, GWAPT, OSWE) and enterprise cloud security experience viewed as strong assets
Who we are
A healthier future drives us to innovate. Together, more than 100’000 employees across the globe are dedicated to advance science, ensuring everyone has access to healthcare today and for generations to come. Our efforts result in more than 26 million people treated with our medicines and over 30 billion tests conducted using our Diagnostics products. We empower each other to explore new possibilities, foster creativity, and keep our ambitions high, so we can deliver life-changing healthcare solutions that make a global impact.
Let’s build a healthier future, together.
Roche is an Equal Opportunity Employer.
Skills Required
- Associate degree in a relevant field or 5+ years of professional information security experience
- Experience triaging, analyzing, and escalating security vulnerabilities
- Strong understanding of web application, network, endpoint, and cloud security concepts
- Experience with vulnerability management or attack surface management in complex enterprise environments
- Hands-on scripting or programming experience with Python, JavaScript, or Node.js
- Experience validating vulnerabilities and assessing exploitability
- Experience supporting security monitoring or incident response activities
- Ability to communicate technical risks to technical and non-technical stakeholders
- Professional fluency in English
- Passion for cybersecurity, continuous learning, and emerging security trends
- Exposure to open-source security projects or modern AI-assisted engineering workflows
- Industry certifications such as OSCP, GWAPT, or OSWE
- Enterprise cloud security experience
Roche Compensation & Benefits Highlights
The following summarizes recurring compensation and benefits themes identified from responses generated by popular LLMs to common candidate questions about Roche and has not been reviewed or approved by Roche.
-
Retirement Support — U.S. materials describe a 401(k) with both matching and an additional company contribution, supported by formal plan documents and true‑up features. This structure is positioned as a standout element of the total package, particularly at Genentech.
-
Leave & Time Off Breadth — Time‑off provisions include substantial vacation, a year‑end shutdown, and a paid six‑week sabbatical after six years. These elements indicate a recharge‑oriented approach within the U.S. offering.
-
Healthcare Strength — Company materials emphasize comprehensive medical, dental, vision, and mental‑health resources alongside well‑being programs. Benefits pages consistently highlight breadth across core health coverage elements.
Roche Insights
What We Do
Roche is a global pioneer in pharmaceuticals and diagnostics focused on advancing science to improve people’s lives. The combined strengths of pharmaceuticals and diagnostics under one roof have made Roche the leader in personalised healthcare – a strategy that aims to fit the right treatment to each patient in the best way possible. Roche is the world’s largest biotech company, with truly differentiated medicines in oncology, immunology, infectious diseases, ophthalmology and diseases of the central nervous system. Roche is also the world leader in in vitro diagnostics and tissue-based cancer diagnostics, and a frontrunner in diabetes management. Founded in 1896, Roche continues to search for better ways to prevent, diagnose and treat diseases and make a sustainable contribution to society. The company also aims to improve patient access to medical innovations by working with all relevant stakeholders. Thirty medicines developed by Roche are included in the World Health Organization Model Lists of Essential Medicines, among them life-saving antibiotics, antimalarials and cancer medicines. Roche has been recognised as the Group Leader in sustainability within the Pharmaceuticals, Biotechnology & Life Sciences Industry ten years in a row by the Dow Jones Sustainability Indices (DJSI).
.png)







