Senior Network Security Engineer for Edge Network Security
At Roche you can show up as yourself, embraced for the unique qualities you bring. Our culture encourages personal expression, open dialogue, and genuine connections, where you are valued, accepted and respected for who you are, allowing you to thrive both personally and professionally. This is how we aim to prevent, stop and cure diseases and ensure everyone has access to healthcare today and for generations to come. Join Roche, where every voice matters.
The Position
The Opportunity:
As a Senior Cybersecurity Engineer (Edge Network Security), you will play a pivotal role in the end-to-end lifecycle of our perimeter and cloud security products. Your primary focus will be the global engineering, adoption, and optimization of our Edge security stack, including Next-Generation Firewalls (NGFW), DDoS mitigation, and Zero Trust Network Access (ZTNA). You are a technical implementer responsible for designing robust, high-availability architectures that protect our global network from external threats while enabling secure, seamless access to multi-cloud environments.
Responsibilities:
Perimeter Defense: Lead the deployment, configuration, and maintenance of Next-Generation Firewalls (Palo Alto, Fortinet) ensuring high availability and optimal inspection across global entry points.
Zero Trust Transition: Architect and implement ZTNA solutions moving beyond legacy VPNs, focusing on granular, application-level access and identity-aware security policies.
Multi-Cloud Security & DDoS Mitigation: Engineer cloud-native security controls across AWS, Azure, and GCP; design DDoS protection strategies (Cloudflare, Akamai) and threat prevention policies (SSL decryption, IPS/IDS).
Product Evolution: Oversee Edge solutions from initial design through global rollout, identifying emerging trends in SASE and Edge computing.
Troubleshooting & Observability: Serve as lead engineer for complex network escalations using deep-packet analysis; develop telemetry and monitoring dashboards for edge traffic.
On-Call Support: Participate in a rotating on-call schedule to ensure continuous availability of global edge security services.
Who you are:
You hold a Bachelor’s degree in Computer Science, Software Engineering, Information Security, or a related technical field or equivalent work experience.
You possess 5+ years of hands-on experience designing and managing enterprise-grade Firewall environments (specifically Palo Alto and/or Fortinet, including TLS inspection, WildFire, Threat Prevention, and GlobalProtect).
You bring proven experience with DDoS Mitigation services (e.g., Cloudflare, Akamai, or F5) and modern Zero Trust / ZTNA frameworks.
You have a deep understanding of core networking protocols (BGP, OSPF, DNS, TLS/SSL).
You have a strong understanding of multi-cloud network security (AWS, Azure, or GCP)
You have experience operating in complex, global enterprise environments (including regulated industries like Pharma/Healthcare).
Preferred:
Certifications: Palo Alto Networks PCNSE/PCNSA, Fortinet NSE, Cisco CCNP Security, or CISSP.
Familiarity with Infrastructure as Code (Terraform, GitHub) or scripting (Python, Go) to build custom automation and API integrations.
Relocation benefits are not available for this posting.
Who we are
A healthier future drives us to innovate. Together, more than 100’000 employees across the globe are dedicated to advance science, ensuring everyone has access to healthcare today and for generations to come. Our efforts result in more than 26 million people treated with our medicines and over 30 billion tests conducted using our Diagnostics products. We empower each other to explore new possibilities, foster creativity, and keep our ambitions high, so we can deliver life-changing healthcare solutions that make a global impact.
Let’s build a healthier future, together.
Roche is an Equal Opportunity Employer.