Jobs and Careers
RO
Fusion - Sub Chapter Lead Threat and Vulnerability Mgmt
RocheSant Cugat del Vallès, Spainfull_timeVerifiedPosted 2 Aug 2024
About the role
<p><span>Roche fosters diversity, equity and inclusion, representing the communities we serve. When dealing with healthcare on a global scale, diversity is an essential ingredient to success. We believe that inclusion is key to understanding people’s varied healthcare needs. Together, we embrace individuality and share a passion for exceptional care. Join Roche, where every voice matters.</span></p><p></p><h3></h3><h2>The Position</h2><p><b><span>Role Purpose</span></b></p><p><br/><span> </span><span>As the Threat and Vulnerability Management Subchapter Lead you will lead a team of experienced security experts within the PSPO Intelligence & Defense chapter, that manages product vulnerabilities on all technology layers and coordinates vulnerability response globally. In this role you will be responsible to ensure product threat and vulnerability management capabilities are in place, applied consistently and developed further to foster Roche’s product security resilience. You are responsible for developing and implementing the Subchapter strategy in alignment with the Diagnostics product security strategy.</span><br/><span> </span> </p><p></p><p><b><span>You will be responsible </span></b></p><ul><li><p><span>Lead the PSPO Intelligence & Defense, Threat and Vulnerability Management Subchapter – a global team of experienced technical security experts</span></p></li><li><p><span>End-to-end accountable for operational vulnerability management activities, prioritization and coordination of tasks during identification, assessment, and remediation of security vulnerabilities.</span></p></li><li><p><span>Develop, operate and manage the subchapter’s capabilities to identify emerging threats and identify vulnerabilities in our products.</span></p></li><li><p><span>Implement and maintain the necessary processes, technology and skills required to respond to threats and vulnerabilities effectively.</span></p></li><li><p><span>Implement and maintain a fit for purpose threat intelligence mechanism to enable efficient prioritization of vulnerability remediation efforts.</span></p></li><li><p><span>Develop and operate a product bug bounty program in cooperation with the Penetration Testing Subchapter</span></p></li><li><p><span>Lead, mentor and coach across chapters and help others develop expertise and skills. Evangelize security and privacy developing Security Champions across departments.</span></p></li><li><p><span>Interfacing with key decision makers to ensure processes are adopted across the organization, applied consistently and correctly, and to ensure overall organizational readiness.</span></p></li><li><p><span>Gather and report on threat intelligence, detect & manage vulnerabilities, and conduct vulnerability assessments.</span></p></li><li><p><span>Representing the organization as a subject matter expert when communicating and coordinating with internal (program/product managers, LCTs) and external stakeholders (FDA, CISA, BSI, etc.) during coordinated vulnerability disclosure.</span></p></li><li><p><span>Lead global cross-functional or cross-chapter projects that deliver strategic product security capability for the Division and stay abreast of new technology trends inside and outside the Division.</span></p></li><li><p><span>Operating independently and highly autonomously, holding yourself accountable to proactively fulfill tasks and achieve results within assigned timelines. Providing solutions to highly complex, significant, and complex issues; developing solutions based on in-depth technical knowledge, company policies, or defined process paths.</span></p></li><li><p><span>Understanding strategic priorities of PSPO responding to requests with appropriate urgency and with an organized approach.</span></p></li><li><p><span>Developing and managing the budget; ensuring goals, deadlines, and budgets are met.</span></p></li><li><p><span>Travel % required (if applicable): 10-20%</span></p></li></ul><p><br/> </p><p><b><span>Your profile</span></b></p><ul><li><p><span>Education: BS degree in Business, Information Systems, Computer Science or a directly related discipline + 8 years of relevant experience in similar roles OR MS degree in directly related discipline + 6 years of relevant experience in similar roles OR PhD degree in directly related discipline + 4 years of relevant experience in similar roles</span></p></li><li><p><span>Professional experience/duration: 4 years with PhD degree / 6 years with MS degree / 8 years with BS degree</span></p></li><li><p><span>Industry-relevant Certifications including: CEH, CISSP, CISA, CISM, LA ISO27001, SANS GIAC (GCIH, GPEN, GCIA, GCFA and others).</span></p></li><li><p><span>Specialist knowledge: Cyber Threat Intelligence, Vulnerability Management, DevSecOps</span></p></li></ul><p></p><p><b><span>Locations</span></b></p><p></p><p><span>You will be based in Sant Cugat, Spain / Pune, India / Rotkreuz, Switzerland / Santa Clara, California, USA (off-site) . At t
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s