Roche Posted August 10, 2026

Cybersecurity Analyst Intern

Sant Cugat del Vallès, Barcelona, Spain FULL_TIME
Information Technology Intern/Fellow/Postdoc

Roche is the source of truth for this posting and owns the application process. We surface normalized context and market comparison you won't find on the original listing.

About this opportunity

At Roche you can show up as yourself, embraced for the unique qualities you bring. Our culture encourages personal expression, open dialogue, and genuine connections,  where you are valued, accepted and respected for who you are, allowing you to thrive both personally and professionally. This is how we aim to prevent, stop and cure diseases and ensure everyone has access to healthcare today and for generations to come. Join Roche, where every voice matters.

The Position

Threat & Vulnerability Analyst (Product Security)

The Opportunity

At Roche, we believe that secure products build trust and save lives. As a Threat & Vulnerability Analyst, you will play a pivotal role in safeguarding our healthcare products, software platforms, and medical technology ecosystem.

You will be responsible for identifying, evaluating, and reporting security vulnerabilities across product lines while leveraging cutting-edge automation and AI-driven methodologies. Working at the intersection of cybersecurity, engineering, and product innovation, you will serve as a trusted security partner to product development teams: helping them understand security risks, prioritize remediations, and continuously strengthen our security posture.

Key Responsibilities

Vulnerability Assessment & Analysis: Perform end-to-end security assessments on product components and software stacks, identifying potential security flaws, exposure points, and software risks.

Automation & AI Integration: Contribute actively to the automation of Software Bill of Materials (SBOM) vulnerability management workflows and help pioneer AI-augmented vulnerability assessment frameworks to scale security operations.

Cross-Stakeholder Reporting: Translate complex technical vulnerabilities into clear, actionable risk reports for engineering, product management, and leadership teams.

Product Team Enablement & Remediation Support: Partner directly with product teams to help them comprehend vulnerability root causes and potential impact, collaborate on pragmatic and effective remediation strategies, and assist in prioritizing fixes within development roadmaps.

Continuous Improvement: Track emerging threat vectors, zero-days, and security industry standards (such as CVSS, NIST, OWASP) to continuously refine assessment criteria and automated tooling.

Who You Are

You are a proactive, analytical cybersecurity professional who thrives on solving complex technical challenges and communicating security concepts to both technical and non-technical audiences.

Qualifications & Skills:

Experience: Proven experience in threat and vulnerability management, product security, application security, or software security analysis.

Technical Knowledge: Strong understanding of vulnerability scoring systems (e.g., CVSS), Software Bill of Materials (SBOM) management, software composition analysis (SCA), and common vulnerability frameworks (CVE/CWE).

Automation & Scripting: Demonstrated ability or strong interest in automating security workflows (e.g., Python, Bash, CI/CD integrations) and applying emerging AI/ML technologies to security assessments.

Remediation Strategy: Ability to guide engineering teams through root-cause analysis and realistic fix prioritization without compromising delivery velocity.

Communication & Influence: Excellent written and verbal communication skills, with a track record of building positive, consultative relationships with software and product teams.

 

 

Who we are

A healthier future drives us to innovate. Together, more than 100’000 employees across the globe are dedicated to advance science, ensuring everyone has access to healthcare today and for generations to come. Our efforts result in more than 26 million people treated with our medicines and over 30 billion tests conducted using our Diagnostics products. We empower each other to explore new possibilities, foster creativity, and keep our ambitions high, so we can deliver life-changing healthcare solutions that make a global impact.

Let’s build a healthier future, together.

Roche is an Equal Opportunity Employer.

Job details

Seniority
Intern/Fellow/Postdoc
Function
Information Technology
Therapeutic area
Not listed
Location
Sant Cugat del Vallès, Barcelona, Spain
Employment type
FULL_TIME

How this role compares

Computed from every other active Information Technology role in our database, not just this employer's listings.

We currently track 55 comparable Intern/Fellow/Postdoc Information Technology roles across 9 biopharma companies.

55Comparable roles tracked
54Currently active
9Companies hiring similar roles
7Countries represented

Salary context

5 of 55 peers report a salary range (USD, annualized)

Peers share this role's job function and a matching or adjacent seniority level -- not necessarily the same therapeutic area or country.

This roleSubject Not listed on this posting
Lowest disclosed · Associate Software Engineer I · AbbVie $58,656/yr – $103,500/yr
Highest disclosed · Advisor Clinical Tech Systems Engineering · Lilly $162,000/yr – $268,400/yr
Peer group range $81,078 – $215,200 (median $175,875)

Where these roles are based

Top locations among the 55 comparable roles

India40
United States8
Canada2
Portugal2
Spain1
Greece1

+ 1 more countries

Seniority mix

55 of 55 peers have a known seniority level

Associate52
Intern/Fellow/Postdoc3

Therapeutic area mix

0 of 55 peers have a known therapeutic area; the rest are genuinely unlabeled, not hidden

No peers with a known therapeutic area yet.

Similar opportunities

The closest matches from our peer group, ranked by how similar they are, not how well you'd qualify for them -- treat this as market context, not a guaranteed shortlist; a weak match is labeled as one below.

60%similar
Roche Sant Cugat del Vallès, Barcelona, Spain Intern/Fellow/Postdoc
Same function Same seniority Same country
45%similar
Amgen British Columbia ULC Burnaby, Canada Intern/Fellow/Postdoc
Same function Same seniority
45%similar
Merck Rahway, New Jersey, United States Intern/Fellow/Postdoc
Same function Same seniority
35%similar
Pfizer Hellas AE Greece-Thessaloniki Chortiatis, Greece Associate
Same function Adjacent seniority
35%similar
Amgen Technology Pvt Ltd. Hyderabad, India Associate
Same function Adjacent seniority
35%similar
Amgen Technology Pvt Ltd. Hyderabad, India Associate
Same function Adjacent seniority

How we calculate "similar"

No black box, no LLM guesswork: a deterministic score built from four normalized attributes. Here's this role's own peer group at different match levels, so you can see the mechanism, not just the result.

Every comparison starts from the same 100-point budget: 25 for working in the same function, 40 for the same therapeutic area, 20 for the same or adjacent seniority, 15 for the same country. A dimension we can't confirm on both sides contributes nothing, never a guess, never a free pass.

60%
Manual Software Test Engineer intern
Roche · Sant Cugat del Vallès, Barcelona, Spain · Intern/Fellow/Postdoc
Function Therapeutic area Seniority Country
35%
Associate, Cyber Resilience
Pfizer Hellas AE · Greece-Thessaloniki Chortiatis, Greece · Associate
Function Therapeutic area Adjacent seniority Country
35%
Associate IS Engineer
Amgen Capability Center Portugal Ltda · Lisbon, Portugal · Associate
Function Therapeutic area Adjacent seniority Country
35%
Automation Support Associate
Amgen Capability Center Portugal Ltda · Lisbon, Portugal · Associate
Function Therapeutic area Adjacent seniority Country
Unmatched or unknown dimensions score exactly the same: 0 points, never a partial guess. A role we know almost nothing about beyond its function bottoms out at 25%; it never inflates to 100% just because there's little to compare against. Seniority uses a defined ladder (Associate → Manager → Associate Director → Senior → Principal → Director → Senior Director → Executive/VP) so "Director" and "Senior Director" count as adjacent, but "Director" and "Executive/VP" do not.