Senior Cybersecurity Engineer (Network Security)
Summary
Senior Cybersecurity Engineer designs and secures enterprise network infrastructure for a global pharma company, implementing Zero Trust and Defense-in-Depth strategies with Cisco ISE, Palo Alto firewalls, and automation tools.
We're currently recruiting for a Senior Cybersecurity Engineer to join a global pharmaceutical company. As a Senior Cybersecurity Engineer, you will be responsible for securing enterprise network infrastructure across on-premises and cloud environments. The role focuses on driving Zero Trust and Defense-in-Depth initiatives, enhancing Network Access Control, identity-based security, and authentication services to ensure secure and compliant connectivity worldwide.
Responsibilities
Act as the Subject Matter Expert (SME) for Secure Access and Network Security technologies, driving the evolution of network access services in alignment with Roche’s Zero Trust and Defense in Depth security strategies
Design, implement, and maintain Network Access Control (Cisco ISE) and identity-based authentication solutions, including protocols such as 802.1X, RADIUS, TACACS+, SAML, MFA, EAP-TLS, and EAP-TEAP
Lead network segmentation and access control initiatives, including Cisco TrustSec, SGT-based micro-segmentation, endpoint profiling, and policy enforcement, while ensuring high availability and platform optimization
Drive operational excellence through incident resolution, root cause analysis, monitoring and reporting, infrastructure automation (IaC), API integrations, and collaboration with global teams to deliver secure and scalable network security solutions
Requirements
5+ years of experience in Cybersecurity / Network Security, with strong hands-on expertise in designing, implementing, and managing enterprise-grade Network Access Control (Cisco ISE) solutions.
Expert knowledge of Cisco ISE, including TrustSec, Dot1x, MAB, Profiling, Guest Access, RADIUS, TACACS+, EAP-TLS, EAP-TEAP, and identity-based access control technologies.
Proven experience with Palo Alto Next-Generation Firewalls (NGFW), including deployment, administration, troubleshooting, SSL decryption, threat prevention, and high-availability environments.
Strong automation and infrastructure engineering skills using Python, Ansible, Terraform, APIs, and CI/CD tools such as GitHub or GitLab.
Solid understanding of enterprise networking concepts (L2/L3, VLANs, VXLAN, BGP, OSPF), network segmentation, and security architecture principles, with experience working in large-scale, global enterprise environments.
Experience in regulated industries such as Pharmaceuticals, Healthcare, or Finance is considered a strong advantage