Roche Posted August 13, 2026

Security Engineer - Manufacturing Cybersecurity

Madrid, Spain FULL_TIME
Information Technology

Roche is the source of truth for this posting and owns the application process. We surface normalized context and market comparison you won't find on the original listing.

About this opportunity

At Roche you can show up as yourself, embraced for the unique qualities you bring. Our culture encourages personal expression, open dialogue, and genuine connections,  where you are valued, accepted and respected for who you are, allowing you to thrive both personally and professionally. This is how we aim to prevent, stop and cure diseases and ensure everyone has access to healthcare today and for generations to come. Join Roche, where every voice matters.

The Position

The Security Engineer plays a vital role in protecting Roche Manufacturing systems and networks against cybersecurity threats. This role provides local architecture and engineering support, assisting system owners and administrators in keeping their manufacturing environment up to date with the latest Roche Manufacturing Cybersecurity standards, baselines and industry best practices.

Taking part in technical design reviews, integration, testing, and documentation activities concerning new OT systems and/or changes to existing manufacturing system or infrastructure

Supporting development of Manufacturing Cybersecurity standards and baselines OT Cybersecurity Advisor during OT System planning phase and OT System Risk Assessment process

Leveraging secure, corporate-compliant AI accelerators and enterprise-ready platforms to automate routine log analysis, scripting, and threat modeling, effectively minimizing defensive response times against machine-speed cyber threats.

Advising System Owners in selecting appropriate security measures to mitigate risk

Coordinating of OT services and activities delivered by Vendors

Reviewing local technical designs as part of Manufacturing Cybersecurity Requests (in ServiceNow)

Designing and sustaining OT Security Monitoring (IIDS) at the Manufacturing Site

Providing technical support during Incident Response process including steps to minimize the impact, conducting a technical and forensic investigation into how the breach happened and the extent of the damage

Working closely with System Owners, Cybersecurity Site Representative and is a catalyst for cross-site collaboration on topics related to Manufacturing Cybersecurity​

Job Responsibilities

The Security Engineer is a member of the Manufacturing Cybersecurity Engineering team led by the Head of Manufacturing Cybersecurity Engineering and part of the Security Platforms subfunction in the Information Security function at Roche

Supports end-to-end security analysis tasks under the supervision of senior engineers and contributes to team goals

Actively learns from senior team members and participates in the application of security best practices

Stakeholder Management

Assists in communicating security requirements to stakeholders and collaborates effectively with cross-functional team members

Supports stakeholder engagement activities and contributes to workshops and meetings to align with project objectives

Impact/Strategy

Demonstrates consistent performance on assigned tasks within specific products or defined project modules.

Contributes to the implementation of plans that align with team objectives and actively participates in established team processes.

Complexity

Supports business analysis activities on assigned project components or specific tasks within a domain.

Handles clearly defined requirements under guidance, engages with identified stakeholders, and contributes to the evaluation of immediate solution impacts.

Business/Technical ability

Demonstrates a developing understanding of the business domain, related technologies, and their interdependencies.

Applies foundational tools, principles, concepts, and techniques related to requirements, data, and process analysis under supervision to support efficiency and effectiveness.

Qualifications

Education / Experience

Foundational knowledge of cybersecurity principles and a strong eagerness to develop technical security skills in a manufacturing environment

Demonstrated potential to collaborate effectively within a team and build productive relationships with stakeholders

Commitment to learning and taking ownership of assigned tasks within security projects or incident support

Bachelor’s degree in Computing Engineering, Automation Engineering or similar is an asset.

Technical Skills

0-3 years of experience in the IT or Cyber Security field

Some knowledge about local manufacturing and automation systems in use according to the current industry standards is an asset.

Familiarity with emerging AI security standards and risk models. Eagerness to utilize secure, enterprise-ready AI productivity and engineering tools to assist in routine log analysis, scripting, and threat modeling workflows

Developing ability to apply tools, principles, and concepts related to requirements, data, usability, and process analysis within the security domain under supervision

Ability to support the analysis of technology fit and contribute to the evaluation of effective, strategically aligned cybersecurity solutions and controls.

Additional Qualifications

The following skills and/or qualifications are an asset

Expertise in anti-virus software, intrusion detection, firewalls and content filtering in OT

Knowledge of risk assessment tools, technologies and methods

Expertise in designing secure networks, systems and application architectures

Disaster recovery, computer forensic tools, technologies and methods

System administration, supporting multiple platforms and applications

Endpoint security solutions, including file integrity monitoring

Deep understanding of cybersecurity terms and principles (defense-in-depth, network segmentation, security monitoring and incident response, access management, OT patch management, secure remote access, anti-malware protection etc.)

Advanced knowledge on networking (LAN/WAN) and industrial networking including significant low-level networking experience with the TCP/IP (Transmission Control Protocol/Internet Protocol)

Solid knowledge on IT and OT infrastructure, including PLC security and protection

Current knowledge of technology capabilities and trends; types, and techniques of hacking

attacks

Java, Net, C++, Python, bash, power shell

One of five potential security-related certifications (Certified Ethical Hacker (CEH), CompTIA Security+, Certified Information System Security Professional (CISSP), ISA/IEC 62443 Cybersecurity Specialist certification, Global Industrial Cyber Security Professional (GICSP))

Solid knowledge on IT infrastructure and service deployment model within Roche

We support a flexible work environment  with an expectation of working from the office approximately 40% of the time (typically two days per week Office presence required).

Please note that relocation assistance is not provided for this position; candidates must already be authorized to work and live within commuting distance.

 

 

Who we are

A healthier future drives us to innovate. Together, more than 100’000 employees across the globe are dedicated to advance science, ensuring everyone has access to healthcare today and for generations to come. Our efforts result in more than 26 million people treated with our medicines and over 30 billion tests conducted using our Diagnostics products. We empower each other to explore new possibilities, foster creativity, and keep our ambitions high, so we can deliver life-changing healthcare solutions that make a global impact.

Let’s build a healthier future, together.

Roche is an Equal Opportunity Employer.

Job details

Seniority
Not listed
Function
Information Technology
Therapeutic area
Not listed
Location
Madrid, Spain
Employment type
FULL_TIME

How this role compares

Computed from every other active Information Technology role in our database, not just this employer's listings.

We currently track 1097 comparable Information Technology roles across 55 biopharma companies.

1097Comparable roles tracked
1035Currently active
55Companies hiring similar roles
29Countries represented

Salary context

143 of 1097 peers report a salary range (USD, annualized)

Peers share this role's job function. This posting doesn't list a seniority level, so peers aren't narrowed by seniority either -- the range below may span more levels than usual.

This roleSubject Not listed on this posting
Lowest disclosed · Senior Data Security Engineer (Insider Risk Management – Engineering) · AbbVie $0/hr – $0/hr (≈ $0–$0/yr)
Highest disclosed · Senior Director, Targets and Mechanisms Solutions · Pfizer $230,900/yr – $384,800/yr
Peer group range $0 – $307,850 (median $165,900)

Where these roles are based

Top locations among the 1097 comparable roles

India507
United States241
Spain105
Poland72
Portugal32
China13

+ 23 more countries

Seniority mix

612 of 1097 peers have a known seniority level

Senior290
Manager135
Associate52
Principal50
Associate Director39
Director28
Senior Director13
Intern/Fellow/Postdoc4
Executive/VP1

Therapeutic area mix

1 of 1097 peers have a known therapeutic area; the rest are genuinely unlabeled, not hidden

Oncology1

Similar opportunities

The closest matches from our peer group, ranked by how similar they are, not how well you'd qualify for them -- treat this as market context, not a guaranteed shortlist; a weak match is labeled as one below.

40%similar
Roche Sant Cugat del Vallès, Barcelona, Spain
Same function Same country
40%similar
Roche Sant Cugat del Vallès, Barcelona, Spain Senior
Same function Same country
40%similar
Novartis Barcelona Gran Vía, Spain
Same function Same country
40%similar
Novartis Barcelona Gran Vía, Spain Associate Director
Same function Same country
40%similar
Novartis Barcelona Gran Vía, Spain Associate Director
Same function Same country
40%similar
Novartis Barcelona Gran Vía, Spain Associate Director
Same function Same country

How we calculate "similar"

No black box, no LLM guesswork: a deterministic score built from four normalized attributes. Here's this role's own peer group at different match levels, so you can see the mechanism, not just the result.

Every comparison starts from the same 100-point budget: 25 for working in the same function, 40 for the same therapeutic area, 20 for the same or adjacent seniority, 15 for the same country. A dimension we can't confirm on both sides contributes nothing, never a guess, never a free pass.

40%
Lead Software Engineer (Rust)
Roche · Sant Cugat del Vallès, Barcelona, Spain · Seniority not listed
Function Therapeutic area Seniority Country
40%
Associate Director Business Analysis (GCO)
Novartis · Barcelona Gran Vía, Spain · Associate Director
Function Therapeutic area Seniority Country
40%
Snr. Specialist, Platform Services - Data, Digital & IT
Novartis · Barcelona Gran Vía, Spain · Seniority not listed
Function Therapeutic area Seniority Country
40%
Associate Director, Solution Design Expert (Advanced Therapies)
Novartis · Barcelona Gran Vía, Spain · Associate Director
Function Therapeutic area Seniority Country
Unmatched or unknown dimensions score exactly the same: 0 points, never a partial guess. A role we know almost nothing about beyond its function bottoms out at 25%; it never inflates to 100% just because there's little to compare against. Seniority uses a defined ladder (Associate → Manager → Associate Director → Senior → Principal → Director → Senior Director → Executive/VP) so "Director" and "Senior Director" count as adjacent, but "Director" and "Executive/VP" do not.