Description
At Roche, you can be yourself and will be valued for your unique qualities. Our culture fosters personal expression, open dialogue, and genuine connections. Here, you are appreciated, accepted, and respected for who you are—creating an environment where you can grow both personally and professionally. Together, we aim to prevent, stop, and cure diseases and ensure that everyone has access to healthcare—today and in the future. Join Roche, where every voice matters.
The Position
Threat\& Vulnerability Analyst (Product Security)
The Opportunity
At Roche, we believe that secure products build trust and save lives. As a Threat\& Vulnerability Analyst, you will play a pivotal role in safeguarding our healthcare products, software platforms, and medical technology ecosystem.
You will be responsible for identifying, evaluating, and reporting security vulnerabilities across product lines while leveraging cutting\-edge automation and AI\-driven methodologies. Working at the intersection of cybersecurity, engineering, and product innovation, you will serve as a trusted security partner to product development teams: helping them understand security risks, prioritize remediations, and continuously strengthen our security posture.
Key Responsibilities
* Vulnerability Assessment\& Analysis: Perform end\-to\-end security assessments on product components and software stacks, identifying potential security flaws, exposure points, and software risks.
* Automation\& AI Integration: Contribute actively to the automation of Software Bill of Materials (SBOM) vulnerability management workflows and help pioneer AI\-augmented vulnerability assessment frameworks to scale security operations.
* Cross\-Stakeholder Reporting: Translate complex technical vulnerabilities into clear, actionable risk reports for engineering, product management, and leadership teams.
* Product Team Enablement\& Remediation Support: Partner directly with product teams to help them comprehend vulnerability root causes and potential impact, collaborate on pragmatic and effective remediation strategies, and assist in prioritizing fixes within development roadmaps.
* Continuous Improvement: Track emerging threat vectors, zero\-days, and security industry standards (such as CVSS, NIST, OWASP) to continuously refine assessment criteria and automated tooling.
Who You Are
You are a proactive, analytical cybersecurity professional who thrives on solving complex technical challenges and communicating security concepts to both technical and non\-technical audiences.
**Qualifications\& Skills:**
* Experience: Proven experience in threat and vulnerability management, product security, application security, or software security analysis.
* Technical Knowledge: Strong understanding of vulnerability scoring systems (e.g., CVSS), Software Bill of Materials (SBOM) management, software composition analysis (SCA), and common vulnerability frameworks (CVE/CWE).
* Automation\& Scripting: Demonstrated ability or strong interest in automating security workflows (e.g., Python, Bash, CI/CD integrations) and applying emerging AI/ML technologies to security assessments.
* Remediation Strategy: Ability to guide engineering teams through root\-cause analysis and realistic fix prioritization without compromising delivery velocity.
* Communication\& Influence: Excellent written and verbal communication skills, with a track record of building positive, consultative relationships with software and product teams.
Who We Are
A healthier future drives us to innovate. More than 100,000 employees worldwide work together to achieve scientific breakthroughs and ensure that everyone has access to healthcare—today and for future generations. Through our commitment, over 26 million people are treated with our medicines and more than 30 billion tests are performed using our diagnostic products. We encourage each other to explore new possibilities, foster creativity, and set ambitious goals to deliver life-changing healthcare solutions.
Together, we can shape a healthier future.
Roche is an equal opportunity employer.