Lifelancer logo
LifelancerPosted 2 weeks ago

Senior Security Engineer - Manufacturing Cybersecurity

RemoteSpain

Full TimeSenior LevelSmall

Job Summary

Lead local architecture and engineering support for Roche Manufacturing systems, conducting technical design reviews, integration testing, and documentation for new OT systems. Develop cybersecurity standards and baselines, coordinate vendor OT services, and design security monitoring (IIDS) at the Manufacturing Site. Provide incident response support, including forensic investigations to minimize breach impact, and advise system owners on risk mitigation strategies. Independently manage end-to-end security analysis tasks and mentor junior team members while acting as a trusted advisor to diverse stakeholders. Leverage secure AI accelerators to automate log analysis and threat modeling, reducing defensive response times against machine-speed cyber threats. Collaborate cross-site on Manufacturing Cybersecurity initiatives to drive strategic implementation plans aligned with business objectives.

Required Qualifications

  • Minimum 5 years of experience in the IT Security field
  • Experience independently managing end-to-end security analysis tasks
  • Leading the analysis of moderately complex cybersecurity incidents or vulnerabilities
  • Demonstrated ability to effectively manage relationships with a diverse range of cross-functional stakeholders
  • Proven track record of championing accountability by example, such as successfully taking on security incident lead and/or security project owner roles
  • Hands-on experience with emerging AI security standards and risk models
  • Experience utilizing secure, enterprise-ready AI productivity and engineering tools to automate routine log analysis, scripting, and threat modeling workflows
  • Ability to analyze technology fit and propose effective, strategically aligned cybersecurity solutions and controls
  • Expertise in anti-virus software, intrusion detection, firewalls and content filtering in OT
  • Knowledge of risk assessment tools, technologies and methods
  • Expertise in designing secure networks, systems and application architectures
  • Disaster recovery, computer forensic tools, technologies and methods
  • System administration, supporting multiple platforms and applications
  • Endpoint security solutions, including file integrity monitoring
  • Deep understanding of cybersecurity terms and principles (defense-in-depth, network segmentation, security monitoring and incident response, access management, OT patch management, secure remote access, anti-malware protection etc.)
  • Advanced knowledge on networking (LAN/WAN) and industrial networking including significant low-level networking experience with the TCP/IP (Transmission Control Protocol/Internet Protocol)
  • Solid knowledge on IT and OT infrastructure, including PLC security and protection
  • Current knowledge of technology capabilities and trends; types, and techniques of hacking attacks
  • Java, Net, C++, Python, bash, power shell
  • One of five potential security-related certifications (Certified Ethical Hacker (CEH), CompTIA Security+, Certified Information System Security Professional (CISSP), ISA/IEC 62443 Cybersecurity Specialist certification, Global Industrial Cyber Security Professional (GICSP))
  • Solid knowledge on IT infrastructure and service deployment model within Roche
  • Good knowledge of the Roche IT Security Standards

Desired Qualifications

  • Bachelor's degree in Computing Engineering, Automation Engineering or similar is an asset
  • Very good knowledge about local manufacturing and automation systems in use according to the current industry standards is an asset

Hiring someone like this?

Get your role in front of qualified candidates on Sorce.

Get started

Apply to this job in one click with Sorce

Apply on Sorce