Senior Network Security Engineer for Edge Network Security — Roche
- Location
- Rolle
- Contract
- full-time
- Posted
- 38 days ago
Role overview
At Roche you can show up as yourself, embraced for the unique qualities you bring.
Our culture encourages personal expression, open dialogue, and genuine connections, where you are valued, accepted and respected for who you are, allowing you to thrive both personally and professionally.
This is how we aim to prevent, stop and cure diseases and ensure everyone has access to healthcare today and for generations to come.
- At Roche you can show up as yourself, embraced for the unique qualities you bring.
- Our culture encourages personal expression, open dialogue, and genuine connections, where you are valued, accepted and respected for who you are, allowing you to thrive both personally and professionally.
- Perimeter Defense: Lead the deployment, configuration, and maintenance of Next-Generation Firewalls (Palo Alto, Fortinet) ensuring high availability and optimal inspection across global entry points.
Main responsibilities
- Perimeter Defense: Lead the deployment, configuration, and maintenance of Next-Generation Firewalls (Palo Alto, Fortinet) ensuring high availability and optimal inspection across global entry points.
Application process
- Zero Trust Transition: Architect and implement ZTNA solutions moving beyond legacy VPNs, focusing on granular, application-level access and identity-aware security policies.
- Multi-Cloud Security & DDoS Mitigation: Engineer cloud-native security controls across AWS, Azure, and GCP; design DDoS protection strategies (Cloudflare, Akamai) and threat prevention policies (SSL decryption, IPS/IDS).
- Product Evolution: Oversee Edge solutions from initial design through global rollout, identifying emerging trends in SASE and Edge computing.
- Troubleshooting & Observability: Serve as lead engineer for complex network escalations using deep-packet analysis; develop telemetry and monitoring dashboards for edge traffic.
- On-Call Support: Participate in a rotating on-call schedule to ensure continuous availability of global edge security services. Who you are:
- You hold a Bachelor’s degree in Computer Science, Software Engineering, Information Security, or a related technical field or equivalent work experience.
- You possess 5+ years of hands-on experience designing and managing enterprise-grade Firewall environments (specifically Palo Alto and/or Fortinet , including TLS inspection, WildFire, Threat Prevention, and GlobalProtect).
- You bring proven experience with DDoS Mitigation services (e.g., Cloudflare, Akamai, or F5) and modern Zero Trust / ZTNA frameworks.
Additional details
- Join Roche, where every voice matters.
- On-Call Support: Participate in a rotating on-call schedule to ensure continuous availability of global edge security services.
- You have experience operating in complex, global enterprise environments (including regulated industries like Pharma/Healthcare).
- Relocation benefits are not available for this posting. A healthier future drives us to innovate.
Notes and original content
- The Position
- The Opportunity:
- Responsibilities:
- Who you are:
- Relocation benefits are not available for this posting.
- Who we are
- A healthier future drives us to innovate.
Questions about this listing
What salary does Roche offer for this role?
Roche lists CHF 85'500 - 129'500 gross per year for this position in Rolle. This is the salary published in the original listing (or, when the employer omits a figure, a realistic estimate for the role and sector) — the calculator on this site converts it to your actual net take-home once cross-border tax and social contributions are applied.
Is this a full-time role, and what type of contract does Roche offer?
This listing is a full-time position. The contract type shown here comes directly from the employer's original posting; always confirm exact hours, notice period and probation length with Roche during the application process, since these details can vary by role even within the same contract category.
Do I need a cross-border work permit for a role in Vaud?
EU/EFTA residents living in the border zone of the country adjoining Canton Vaud can apply for a G permit; the Swiss employer files it with that canton's migration office after the contract is signed. Border-zone rules and processing times vary by neighbouring country and canton, so confirm the specifics with Vaud's cantonal migration office or with HR during the application.
How do I apply for this position at Roche?
Use the "Apply now" button on this page — it links directly to Roche's original listing at roche.wd3.myworkdayjobs.com, so your application goes straight to the employer's own applicant-tracking system. Frontaliere Ticino does not collect or forward applications itself.