Senior Software Engineer, Cybersecurity
At Roche you can show up as yourself, embraced for the unique qualities you bring. Our culture encourages personal expression, open dialogue, and genuine connections, where you are valued, accepted and respected for who you are, allowing you to thrive both personally and professionally. This is how we aim to prevent, stop and cure diseases and ensure everyone has access to healthcare today and for generations to come.
About the role
A healthier future drives us to innovate. To continuously advance science and ensure everyone has access to the healthcare they need today and for generations to come. Creating a world where we all have more time with the people we love. That’s what makes us Roche.
We are seeking a driven Senior Software Engineer in Cybersecurity to join our team at Roche Tissue Diagnostics (RTD) as our Cybersecurity Champion Lead. In this pivotal role, you will work directly with software product development teams to provide guidance and oversight on secure design patterns, risk assessments, and vulnerability analysis. Beyond individual projects, you will also lead department-level initiatives for our cybersecurity uplift program and work directly with the Roche Product Security & Privacy Organization (PSPO).
Responsibilities
- Contribute as a Subject Matter Expert to cybersecurity risk assessments for the RTD product portfolio, including risk identification, risk analysis and verification of risk mitigations.
- Consult development teams in analyzing potential impacts and exposure of vulnerabilities.
- Contribute technical knowledge to development teams about secure design patterns and the right use of security technologies.
- Create and review documentation of security concepts, secure designs and plans to maintain the secure state of the product portfolio throughout its lifecycle.
- Manage and oversee penetration tests with internal product teams and external service providers. Assess and track mitigation strategies.
- Collaborate with Roche’s Product Security and Privacy Operations group to disseminate process updates and state of the art best practices to product development teams.
- Prepare and deliver presentations of product security posture results to large and diverse internal audiences.
Requirements
- BS degree and at least 8 years of related experience or equivalent in a directly related discipline or equivalent combination of education and experience.
- MS degree in directly related discipline + 4 years of related experience required; OR, PhD degree in a directly related discipline + 2 years of related experience required.
- Prior experience in secure software development.
- Cybersecurity certification(s) desired, but not required (e.g. CISA, CISM, CISSP).
- Experience in Cloud security concepts and with medical devices, especially IVD systems, desired.
- Knowledge about Windows and .Net technology stack (Java and Linux are a plus).
- Knowledge of cybersecurity regulations, laws and standards for the medical device industry.
- Driven, self-starter with good planning and organizational skills and a strong attention to detail.
Pay
The expected salary range for this position based on the primary location of Tucson, AZ is $104,000 - $193,100. Actual pay will be determined based on experience, qualifications, geographic location, and other job-related factors permitted by law. A discretionary annual bonus may be available based on individual and Company performance.
Benefits
This position qualifies for the benefits detailed at the link provided below.
Relocation benefits are not available for this job posting.