PBAC Operations Engineer - RDT Identity & Access Management
About this opportunity
At Roche you can show up as yourself, embraced for the unique qualities you bring. Our culture encourages personal expression, open dialogue, and genuine connections, where you are valued, accepted and respected for who you are, allowing you to thrive both personally and professionally. This is how we aim to prevent, stop and cure diseases and ensure everyone has access to healthcare today and for generations to come. Join Roche, where every voice matters.
The Position
The Opportunity:
As a Senior Cybersecurity Engineer in the IAM space, you will serve as the technical owner of our Policy Based Access Control (PBAC) infrastructure. In this role, you will lead the design, implementation, and tactical lifecycle management of core authorization components to ensure they are scalable, resilient, and deeply integrated across a hybrid global landscape.
Key Responsibilities:
Infrastructure Ownership & Strategy: Architect and maintain core PBAC components (PDP/PEP) for high availability. Lead the transition from initial use cases to enterprise-wide adoption, establishing global standards for policy-based authorization.
Policy as Code (PaC) & DevOps: Drive the shift to PaC by designing automated CI/CD pipelines for versioning, testing, and deploying authorization logic like software.
Integration & Consulting: Act as a primary consultant for global application and data owners to securely integrate systems via RESTful APIs, SQL/JDBC, and LDAP.
Problem Solving & Analytics: Lead the analysis of complex, highly ambiguous technical problems across organizational boundaries, driving comprehensive root-cause analysis and proactive risk mitigation.
Stakeholder & Vendor Management: Partner with product managers, global developers, and senior management to design secure, user-friendly PBAC flows. Manage production environments using ITIL principles and coordinate with external vendors and Managed Service Providers (MSPs).
Leadership & Continuous Improvement: Mentor team members, build expertise across the organization, and champion business process improvements within Communities of Practice (CoPs).
Who You Are:
Education: Bachelor's degree in a relevant technical field or equivalent work experience
Experience: 8–15 years in IT/Security, with 5+ years strictly focused on Identity & Access Management (IAM) and specific expertise in PBAC/ABAC within large enterprise environments.
Technical Mastery: Advanced, hands-on knowledge of XACML, decentralized policy management, and modern web frameworks under Zero Trust principles (RBAC and ABAC).
IAM & DevOps Foundations: Highly proficient in SAML, OAuth, OIDC, SSO, and IGA. Experience writing custom integrations in Java or Python and deploying via Git-based CI/CD pipelines.
Architectural Mindset: Strong advocate for systems thinking and enterprise-wide consulting advice. You prioritize configurable, "off-the-shelf" capabilities over heavy customization for long-term maintainability.
Communication: Fluent in English with exceptional interpersonal skills to navigate complex conflicts, build global consensus, and translate architectural concepts for non-technical stakeholders.
Preferred Qualifications:
Regulated Environments: Deep familiarity with data privacy regulations such as GDPR.
Operational Frameworks: Experience working within Agile methodologies and applying ITIL frameworks in cross-functional global team structures.
Relocation benefits are not available for this posting.
Who we are
A healthier future drives us to innovate. Together, more than 100’000 employees across the globe are dedicated to advance science, ensuring everyone has access to healthcare today and for generations to come. Our efforts result in more than 26 million people treated with our medicines and over 30 billion tests conducted using our Diagnostics products. We empower each other to explore new possibilities, foster creativity, and keep our ambitions high, so we can deliver life-changing healthcare solutions that make a global impact.
Let’s build a healthier future, together.
Roche is an Equal Opportunity Employer.
Job details
How this role compares
Computed from every other active Information Technology role in our database, not just this employer's listings.
We currently track 1097 comparable Information Technology roles across 55 biopharma companies.
Salary context
143 of 1097 peers report a salary range (USD, annualized)
Peers share this role's job function. This posting doesn't list a seniority level, so peers aren't narrowed by seniority either -- the range below may span more levels than usual.
Where these roles are based
Top locations among the 1097 comparable roles
+ 23 more countries
Seniority mix
612 of 1097 peers have a known seniority level
Therapeutic area mix
1 of 1097 peers have a known therapeutic area; the rest are genuinely unlabeled, not hidden
Similar opportunities
The closest matches from our peer group, ranked by how similar they are, not how well you'd qualify for them -- treat this as market context, not a guaranteed shortlist; a weak match is labeled as one below.
How we calculate "similar"
No black box, no LLM guesswork: a deterministic score built from four normalized attributes. Here's this role's own peer group at different match levels, so you can see the mechanism, not just the result.
Every comparison starts from the same 100-point budget: 25 for working in the same function, 40 for the same therapeutic area, 20 for the same or adjacent seniority, 15 for the same country. A dimension we can't confirm on both sides contributes nothing, never a guess, never a free pass.
0 points, never a partial guess. A role we know almost nothing about beyond its function bottoms out at 25%; it never inflates to 100% just because there's little to compare against. Seniority uses a defined ladder (Associate → Manager → Associate Director → Senior → Principal → Director → Senior Director → Executive/VP) so "Director" and "Senior Director" count as adjacent, but "Director" and "Executive/VP" do not.