Senior Network Security Engineer for Edge Network Security
Indexed description
The Position
The Opportunity:
As a Senior Cybersecurity Engineer (Edge Network Security), you will play a pivotal role in the end-to-end lifecycle of our perimeter and cloud security products. Your primary focus will be the global engineering, adoption, and optimization of our Edge security stack, including Next-Generation Firewalls (NGFW), DDoS mitigation, and Zero Trust Network Access (ZTNA). You are a technical implementer responsible for designing robust, high-availability architectures that protect our global network from external threats while enabling secure, seamless access to multi-cloud environments.
Responsibilities:
- Perimeter Defense: Lead the deployment, configuration, and maintenance of Next-Generation Firewalls (Palo Alto, Fortinet) ensuring high availability and optimal inspection across global entry points
- Zero Trust Transition: Architect and implement ZTNA solutions moving beyond legacy VPNs, focusing on granular, application-level access and identity-aware security policies
- Multi-Cloud Security & DDoS Mitigation: Engineer cloud-native security controls across AWS, Azure, and GCP; design DDoS protection strategies (Cloudflare, Akamai) and threat prevention policies (SSL decryption, IPS/IDS)
- Product Evolution: Oversee Edge solutions from initial design through global rollout, identifying emerging trends in SASE and Edge computing
- Troubleshooting & Observability: Serve as lead engineer for complex network escalations using deep-packet analysis; develop telemetry and monitoring dashboards for edge traffic
- On-Call Support: Participate in a rotating on-call schedule to ensure continuous availability of global edge security services
- You hold a Bachelor’s degree in Computer Science, Software Engineering, Information Security, or a related technical field or equivalent work experience
- You possess 5+ years of hands-on experience designing and managing enterprise-grade Firewall environments (specifically Palo Alto and/or Fortinet, including TLS inspection, WildFire, Threat Prevention, and GlobalProtect)
- You bring proven experience with DDoS Mitigation services (e.g., Cloudflare, Akamai, or F5) and modern Zero Trust / ZTNA frameworks
- You have a deep understanding of core networking protocols (BGP, OSPF, DNS, TLS/SSL)
- You have a strong understanding of multi-cloud network security (AWS, Azure, or GCP)
- You have experience operating in complex, global enterprise environments (including regulated industries like Pharma/Healthcare)
- Certifications: Palo Alto Networks PCNSE/PCNSA, Fortinet NSE, Cisco CCNP Security, or CISSP
- Familiarity with Infrastructure as Code (Terraform, GitHub) or scripting (Python, Go) to build custom automation and API integrations
A healthier future drives us to innovate. Together, more than 100’000 employees across the globe are dedicated to advance science, ensuring everyone has access to healthcare today and for generations to come. Our efforts result in more than 26 million people treated with our medicines and over 30 billion tests conducted using our Diagnostics products. We empower each other to explore new possibilities, foster creativity, and keep our ambitions high, so we can deliver life-changing healthcare solutions that make a global impact.
Let’s build a healthier future, together.
Roche is an Equal Opportunity Employer.
Create a free Caio profile to unlock more results and save your role and location preferences.
Unlock free search