Roche Posted July 11, 2026

Senior Cloud Security Engineer

Madrid, Spain FULL_TIME
Information Technology Senior

Roche is the source of truth for this posting and owns the application process. We surface normalized context and market comparison you won't find on the original listing.

About this opportunity

At Roche you can show up as yourself, embraced for the unique qualities you bring. Our culture encourages personal expression, open dialogue, and genuine connections,  where you are valued, accepted and respected for who you are, allowing you to thrive both personally and professionally. This is how we aim to prevent, stop and cure diseases and ensure everyone has access to healthcare today and for generations to come. Join Roche, where every voice matters.

The Position

We are a high-performing cybersecurity team tasked with protecting the organization’s computing environments. While our historical stronghold has been managing enterprise Endpoint Detection and Response (EDR), Application Control, and Secure Data Erasure, we are now expanding our focus to secure our dynamic, cloud-native environments.

We are looking for a Cloud Security Engineer specializing in Cloud Workload Protection. You will be responsible for securing IaaS, PaaS, containers, and serverless architectures. Working alongside your senior endpoint security colleagues, you will bridge the gap between traditional endpoint defense and modern cloud infrastructure, ensuring our threat detection and application governance standards are seamlessly extended to the cloud.

Job Responsibilities

Cloud Workload Protection (CWPP): Architect, deploy, and manage Cloud Workload Protection Platforms (e.g., Prisma Cloud, Microsoft Defender for Cloud, Wiz, or Aqua) across our multi-cloud environment (AWS, Azure, and/or GCP).

Container & Kubernetes Security: Implement runtime defense, vulnerability scanning, and configuration hardening for containerized applications and orchestration platforms (EKS, AKS, GKE).

Extending Core Services to the Cloud: Adapt our existing strategies for EDR and Application Control to function effectively in ephemeral, cloud-native workloads without degrading performance.

DevSecOps Integration: Embed security controls directly into CI/CD pipelines (Shift-Left), ensuring images, registries, and Infrastructure as Code (IaC) templates are scanned and secured before deployment.

Automated Remediation: Develop automated response playbooks for cloud misconfigurations and workload alerts using serverless functions and native cloud APIs.

Qualifications

Education / Experience / Technical Skills

Bachelor’s degree in Computer Science, Software Engineering, Cybersecurity, or equivalent practical experience.

3+ years of dedicated experience securing public cloud workloads, with a strong understanding of the shared responsibility model.

Deep technical knowledge of Docker, Kubernetes, and container orchestration. You should know how to secure a pod, restrict container privileges, and manage network policies.

Proven, hands-on experience deploying and tuning commercial or open-source cloud security platforms (CWPP / CNAPP).

Strong grasp of cloud-native networking (VPCs, Security Groups) and Identity and Access Management (least-privilege roles, service accounts).

Proficiency in written and spoken English (C1 or above level).

Additional Qualifications

Bridge Builder: Ability to collaborate closely with DevOps and Cloud Engineering teams, acting as an enabler rather than a roadblock.

Strategic Thinker: Capacity to look at our existing on-premise security policies and intelligently adapt them for ephemeral cloud environments.

Adaptable: Comfortable working in a highly dynamic cybersecurity environment where priorities can shift based on emerging needs.

Team Player: Ability to collaborate effectively with internal and external team mates and stakeholders.

Mentorship: Willingness to cross-train our existing senior endpoint engineers on cloud-native security concepts, while learning from their deep endpoint telemetry expertise.

 

 

Who we are

A healthier future drives us to innovate. Together, more than 100’000 employees across the globe are dedicated to advance science, ensuring everyone has access to healthcare today and for generations to come. Our efforts result in more than 26 million people treated with our medicines and over 30 billion tests conducted using our Diagnostics products. We empower each other to explore new possibilities, foster creativity, and keep our ambitions high, so we can deliver life-changing healthcare solutions that make a global impact.

Let’s build a healthier future, together.

Roche is an Equal Opportunity Employer.

Job details

Seniority
Senior
Function
Information Technology
Therapeutic area
Not listed
Location
Madrid, Spain
Employment type
FULL_TIME

How this role compares

Computed from every other active Information Technology role in our database, not just this employer's listings.

We currently track 378 comparable Senior Information Technology roles across 34 biopharma companies.

378Comparable roles tracked
355Currently active
34Companies hiring similar roles
21Countries represented

Salary context

45 of 378 peers report a salary range (USD, annualized)

Peers share this role's job function and a matching or adjacent seniority level -- not necessarily the same therapeutic area or country.

This roleSubject Not listed on this posting
Lowest disclosed · Senior Data Security Engineer (Insider Risk Management – Engineering) · AbbVie $0/hr – $0/hr (≈ $0–$0/yr)
Peer group range $0 – $224,445 (median $151,100)

Where these roles are based

Top locations among the 378 comparable roles

India196
United States78
Spain22
Poland14
Portugal10
Greece9

+ 15 more countries

Seniority mix

378 of 378 peers have a known seniority level

Senior289
Principal50
Associate Director39

Therapeutic area mix

0 of 378 peers have a known therapeutic area; the rest are genuinely unlabeled, not hidden

No peers with a known therapeutic area yet.

Similar opportunities

The closest matches from our peer group, ranked by how similar they are, not how well you'd qualify for them -- treat this as market context, not a guaranteed shortlist; a weak match is labeled as one below.

60%similar
Roche Sant Cugat del Vallès, Barcelona, Spain Senior
Same function Same seniority Same country
60%similar
Roche Madrid, Spain Senior
Same function Same seniority Same country
60%similar
Roche Madrid, Spain Senior
Same function Same seniority Same country
60%similar
Roche Sant Cugat del Vallès, Barcelona, Spain Senior
Same function Same seniority Same country
60%similar
Roche Madrid, Spain Senior
Same function Same seniority Same country
60%similar
Roche Sant Cugat del Vallès, Barcelona, Spain Senior
Same function Same seniority Same country

How we calculate "similar"

No black box, no LLM guesswork: a deterministic score built from four normalized attributes. Here's this role's own peer group at different match levels, so you can see the mechanism, not just the result.

Every comparison starts from the same 100-point budget: 25 for working in the same function, 40 for the same therapeutic area, 20 for the same or adjacent seniority, 15 for the same country. A dimension we can't confirm on both sides contributes nothing, never a guess, never a free pass.

60%
Senior Software Developer/Scrum Master C#
Roche · Sant Cugat del Vallès, Barcelona, Spain · Senior
Function Therapeutic area Seniority Country
60%
Senior DevOps Automation Engineer
Roche · Sant Cugat del Vallès, Barcelona, Spain · Senior
Function Therapeutic area Seniority Country
60%
Senior Software Engineer
Roche · Sant Cugat del Vallès, Barcelona, Spain · Senior
Function Therapeutic area Seniority Country
60%
Senior DevOps Mobile Engineer
Roche · Sant Cugat del Vallès, Barcelona, Spain · Senior
Function Therapeutic area Seniority Country
Unmatched or unknown dimensions score exactly the same: 0 points, never a partial guess. A role we know almost nothing about beyond its function bottoms out at 25%; it never inflates to 100% just because there's little to compare against. Seniority uses a defined ladder (Associate → Manager → Associate Director → Senior → Principal → Director → Senior Director → Executive/VP) so "Director" and "Senior Director" count as adjacent, but "Director" and "Executive/VP" do not.