Roche, a global healthcare leader with over 100,000 employees worldwide, is seeking a Senior Software Engineer specializing in Cybersecurity for their Tissue Diagnostics (RTD) division in Tucson, AZ. This role represents a unique opportunity to impact healthcare through secure software development and cybersecurity expertise.
The position involves working with a dynamic team of Software Architecture and Development professionals who are developing next-generation diagnostic products while maintaining the security of existing solutions. As a Subject Matter Expert, you'll be instrumental in shaping the security posture of medical devices and diagnostic systems, combining software engineering expertise with cybersecurity best practices.
The role offers a competitive salary range of $103,500 - $192,300, reflecting the senior-level expertise required. The ideal candidate will bring 8+ years of relevant experience, with a strong foundation in secure software development and knowledge of medical device security regulations. Experience with Windows, .NET, Java, and cloud security concepts is valued, as is familiarity with IVD systems.
Key responsibilities include conducting cybersecurity risk assessments, consulting on vulnerability management, implementing secure design patterns, and managing penetration testing programs. You'll collaborate with various teams and stakeholders, including Roche's Product Security and Privacy Operations group, to ensure robust security practices across the product portfolio.
At Roche, you'll be part of a culture that values personal expression, open dialogue, and genuine connections. The company's mission to prevent, stop, and cure diseases while ensuring universal healthcare access provides a meaningful context for your work. This role offers the opportunity to directly impact patient care by ensuring the security and integrity of critical diagnostic systems.
The position requires a blend of technical expertise, security knowledge, and strong communication skills, as you'll be presenting security findings to diverse audiences and working across multiple teams. While certifications like CISSP are desired, the focus is on practical experience and the ability to drive security improvements in a medical device context.