Empleo / Roche

Roche

Senior Identity And Access Management Engineer - Cloud Environment

Ubicación
Madrid
Jornada
Jornada completa
Publicada
hace 3 meses

La oferta

En Roche puedes ser tú mismo y sentirte valorado por tus cualidades únicas. Nuestra cultura fomenta la expresión personal, el diálogo abierto y las conexiones genuinas, donde eres valorado, aceptado y respetado por lo que eres, permitiéndote prosperar tanto de manera personal como profesionalmente. Así es como buscamos prevenir, detener y curar enfermedades y asegurarnos de que todos tengan acceso a la atención sanitaria hoy y para las futuras generaciones. Únete a Roche, donde cada voz importa. La posición Job description The Security and Cybersecurity Analyst serves as a trusted advisor and independent leader who drives the analysis of moderately complex cybersecurity incidents and technical problems By bridging deep business and technical understanding, you will manage end-to-end security analysis tasks across multiple products within a domain You will shape stakeholder perspectives, champion accountability by taking on security incident lead or project owner roles, and foster continuous improvement in security operations and best practices Description of the area The Identity Management Support Team manages and operates the solutions and components used to provide customers with Directory and Identity Management Services using SailPoint. We are part of a global Roche Digital Technology group (RDT). Job Responsibilities In this role, you are mainly responsible for the multi-cloud Identity Management environment, focusing specifically on Azure and Google Cloud Platform (GCP), while maintaining consistency with AWS. This includes the design of new solutions, consultancy, maintenance, performance, tactical lifecycle management and continuous improvement of the underlying technologies. Scope - Strong background in IAM concepts at design level and evolution in Cloud environments, Azure and/or GCP. - Contributes to the design of new solutions based on SailPoint and PingFederate, AD, Privilege Access Management. - Design and implement Centralized Role-Based Access Control (RBAC) based on Cloud Adoption Framework (CAF) principles. - Access Governance and Controls: Enforce strong security controls across cloud environments, including Multi-Factor Authentication (MFA) and Identity Protection. Implement Least Privilege policies, often involving custom roles and organizational-level controls. Implement IAM Deny Policies to strictly block high-risk actions, ensuring separation of duties - Automation and Infrastructure-as-Code (IaC): Drive the core value of "Automate as much as possible". Design and implement IAM infrastructure using IaC, leveraging Terraform. For Azure, this mandates IaC using Terraform and Azure Verified Modules (AVM) with CI/CD pipelines in GitLab - Privileged Access Management (PAM): Design and support Just-in-Time (JIT) Access mechanisms, ensuring no standing privileges for administrators, using tools like Cyberark for Just-in-Time access - Operational Excellence: Act as an expert in the release management activities, providing 2nd and 3rd level support for the Identity Management Infrastructure. Proactively monitor systems for performance, availability, and capacity management - Actively focus on self-development in creating actionable plans to improve. Stakeholder Management - Consultancy and Collaboration: Act as a mentor and reference, working closely with stakeholders to provide the right level of consultancy. Ensure regular interactions with the Managed Service Provider - Acts as a strategic influencer, defining and driving stakeholder engagement strategies for complex initiatives, facilitating workshops, resolving conflicts, and proactively shaping stakeholder perspectives to align with project goals Impact/Strategy - Demonstrates strong and consistent performance across diverse products, with an impact that typically extends to a specific product, initiative, or cluster - Translates requirements into strategic implementation plans that align with overall business objectives, and takes a proactive role in shaping team processes, often contributing to Communities of Practice (CoPs) Complexity - Manages business analysis activities on more complex projects or across multiple products within a domain - Capable of handling ambiguous requirements, navigating intricate stakeholder environments, and evaluating solution impacts considering both immediate and longer-term implications within the domain Business/Technical ability - Demonstrates a strong understanding of the business domain, related technologies, and their interdependencies - Can independently apply tools, principles, concepts, and techniques related to requirements, data, usability, and process analysis, effectively managing interconnections to improve overall efficiency and effectiveness Qualifications Education / Experience - 5-7 years of experience working in a major global organization, preferably in a regulated industry and in providing solutions aligned with standards, security, validation, capacity and high availability. - Bachelor’s Degree in computer science, engineering or related discipline; or recognition of prior working experience which is equivalent. - Industry accredited certification is desirable. Willingness to continually acquire and maintain the technical skills appropriate to the requirements of this position. - Demonstrated ability to effectively manage relationships with a diverse range of cross-functional stakeholders on medium to large-sized engagements, acting as a trusted advisor - Proven track record of championing accountability by example, such as successfully taking on security incident lead and/or security project owner roles Technical Skills - Strong hands-on technical skills with an IT operations background. Expert knowledge on infrastructure technologies, business processes and applications with a focus on Sailpoint IQ Identity Governance and Access Identity Management technologies and PingFederate. Cloud Platform skills: - Expertise in GCP Identity and Access Management (IAM), including Identity Synchronization, Service Account binding/federation, and organizational policy enforcement. - Expertise in Azure IAM/RBAC, including implementing centralized RBAC designs, Azure Policy, and alignment with the Azure Cloud Adoption Framework (CAF). - Experience applying cloud governance principles (e.g., Azure Policy, IAM Deny Policies) to ensure consistent governance and security across multi-cloud workloads​ ​ Automation and DevOps: - Experience with Infrastructure-as-Code (IaC) tools, particularly Terraform, for platform building and management. - Experience implementing governance as code and integrating automated workflows via CI/CD pipelines (e.g., GitLab). - Strong understanding of Computer Systems Validation and working experience in a validated environment. - Good understanding of IT Security systems and landscape with in-depth knowledge of Directories, Identity Management and Privileged Access Management technologies. - Strong proficiency in independently applying tools, principles, and concepts related to requirements, data, usability, and process analysis within the security domain - Advanced analytical and logical reasoning skills to identify security patterns, threats, and discrepancies, driving comprehensive root cause analysis - Ability to analyze technology fit and propose effective, strategically aligned cybersecurity solutions and controls Additional Qualifications - Proactive, collaborative and supportive approach when interacting with colleagues. - Committed to operational excellence, with willingness to cross-train and to learn additional technical expertise. - Strong customer focus and a highly responsive service delivery and support ethic. - Adaptable to change in a large organization. - Excellent communication, negotiation and documentation skills. - Proven interpersonal skills to interact effectively with individuals in multiple countries and in varying cultures. - Strong verbal and written English. - Demonstrated ability to mentor colleagues with less experience and provide guidance on cybersecurity best practices and analysis techniques - Proactive contribution to organizational development, including identifying process improvements and actively participating in Communities of Practice (CoPs) - Strong facilitation, communication, and conflict resolution skills to ensure alignment across multiple product squads and complex stakeholder networks Quienes somos Alcanzar un futuro más saludable es lo que nos impulsa a innovar. Juntos, más de 100.000 empleados en todo el mundo están dedicados a avanzar en la ciencia, asegurando que todos tengan acceso a la atención sanitaria hoy y para las futuras generaciones. Nuestros esfuerzos resultan en más de 26 millones de personas tratadas con nuestros medicamentos y más de 30 mil millones de pruebas realizadas con nuestros productos de Diagnósticos. Nos damos apoyo mutuamente para explorar nuevas posibilidades, fomentar la creatividad y mantener altas nuestras ambiciones, para poder ofrecer soluciones sanitarias que cambian la vida e impactan a nivel global. Construyamos juntos un futuro más saludable. Roche es una empresa que ofrece igualdad de oportunidades.