Roche Diagnostics India Pvt Ltd

Network Security Engineer

Roche Diagnostics India Pvt Ltd
Pune
Not disclosed
Work from OfficeWork from Office
Full TimeFull Time
Min. 4 yearsMin. 4 years

Job Description

Security Analyst - RDT Information Security

At Roche you can show up as yourself, embraced for the unique qualities you bring. Our culture encourages personal expression, open dialogue, and genuine connections,  where you are valued, accepted and respected for who you are, allowing you to thrive both personally and professionally. This is how we aim to prevent, stop and cure diseases and ensure everyone has access to healthcare today and for generations to come. Join Roche, where every voice matters.

The Position

Security Analyst - Penetration Testing

Exp- 4 to 7 yers

Location- Pune

Position Overview

We are seeking an experienced Security Analyst to join our cybersecurity team. In this role, you will conduct comprehensive penetration testing and vulnerability assessments across our diverse technology landscape, identifying and documenting security risks to strengthen our overall security posture.

Primary Responsibilities

  • Conduct thorough penetration testing of  web applications, mobile applications, and AI/LLM system using industry-standard tools and methodologies

  • Perform hands-on security assessments and identify vulnerabilities in web-based systems and APIs

  • Execute practical penetration tests against target systems, documenting real-world findings and exploitation methods

  • Develop and execute custom exploitation payloads and attack scenarios

  • Analyze application logic, authentication mechanisms, and access control implementations

  • Collaborate with development and infrastructure teams to define scope, validate findings and track remediation efforts

  • Maintain detailed testing documentation, evidence of assessments, and proof of concept demonstrations

  • Participate in security reviews and contribute to threat modeling exercises

  • Stay current with emerging web application security threats and attack vectors

  • Quickly adapt to new tools, technologies, and emerging security challenges in the threat landscape

Required Qualifications

Certifications (Mandatory - at least one of the following)

  • OSCP (Offensive Security Certified Professional) or

  • CPTS (Certified Penetration Testing Specialist) or

  • OSCE (Offensive Security Certified Expert) or

  • Equivalent recognized penetration testing certification

Experience & Technical Skills

Primary Expertise (Web Application and LLM - Hands-On Required):

  • 3+ years of demonstrated hands-on experience in web application penetration testing

  • Proven ability to identify and exploit real-world vulnerabilities in production and pre-production environments

  • Practical expertise with OWASP Top 10 vulnerabilities, including SQL Injection, XSS, CSRF, authentication bypass, and API security flaws

  • Proficiency with web security testing tools (Burp Suite, OWASP ZAP, Postman, etc.)

  • Experience bypassing security controls and WAF implementations

  • Hands-on experience with API penetration testing (REST, GraphQL, SOAP)

  • Practical expertise with LLM security assessments, including prompt injection, model manipulation, and output validation weaknesses.

  • Understanding of LLM vulnerabilities including prompt injection, jailbreaking, data leakage, and model poisoning attacks

  • Experience evaluating guardrails, content filters, and safety mechanisms in AI systems 

  • Proficiency with LLM security testing frameworks (e.g., OWASP Top 10 for LLM Applications)

  • Familiarity with LLM penetration testing tools (e.g., Claud CLI, PRFU, Garak, promptfoo, etc.)

Required Secondary Skills (Hands-On Demonstrated):

  • Mobile Penetration Testing: Practical hands-on experience testing iOS and Android applications, including runtime analysis, reverse engineering, and security assessment of mobile APIs

  • Cloud Security: Hands-on experience conducting security assessments on public cloud environments (e.g., AWS, Azure, GCP), including services like EC2, S3, Lambda, IAM, RDS, and cloud misconfiguration identification.

Core Competencies:

  • Strong understanding of networking, encryption, authentication, and authorization mechanisms

  • Analyze and understand complex system architectures to develop targeted penetration testing methodologies and identify underlying vulnerabilities

  • Ability to write clear, professional penetration test reports with actionable remediation guidance

  • Excellent communication skills for presenting findings to both technical and non-technical stakeholders

  • Attention to detail and strong analytical mindset

  • Ethical hacking mindset with commitment to responsible disclosure

  • Quick learner with demonstrated ability to rapidly master new tools and technologies

  • Adaptive mindset with readiness to learn emerging security domains and evolving attack methodologies

Preferred Qualifications

  • Bachelor's degree in Computer Science, Cybersecurity, Information Security, or equivalent hands-on experience

  • Hands-on practical experience with thick client application penetration testing (binary analysis, memory manipulation, process injection)

  • Additional security certifications (CEH, GWAPT, GPEN, GIAC Security Essentials, etc.)

  • Hands-on experience with containerization security (Docker, Kubernetes)

  • Practical experience with CI/CD pipeline security assessments

  • Experience in compliance-driven penetration testing (PCI-DSS, HIPAA, SOC 2)

  • Active or past participation in legitimate bug bounty programs with demonstrated results

  • Experience developing custom exploitation tools and scripts

  • Proven track record of self-directed learning and skill development in security domains

  • Experience adapting existing tools and methodologies to novel security challenges

Required Technical Proficiencies

  • Penetration testing frameworks and methodologies (NIST, OWASP, PTES)

  • Advanced network analysis and packet inspection tools

  • Vulnerability scanning, assessment, and exploitation tools

  • Python scripting for exploitation and tool development

  • Linux/Unix command-line proficiency and bash scripting

  • Practical knowledge of common security vulnerabilities and real-world exploitation techniques

  • Burp Suite (or equivalent) advanced usage and configuration

  • Mobile debugging tools and frameworks

  • Cloud security assessment tools and techniques

Soft Skills

  • Problem-solving and critical thinking with hands-on troubleshooting ability

  • Strong written and verbal communication (English)

  • Ability to work collaboratively in a global team environment

  • Time management and ability to handle multiple concurrent assessments

  • Professional judgment and ethical responsibility

  • Quick learner with ability to acquire and apply new technical knowledge rapidly

  • Adaptability and flexibility in approaching diverse security challenges

  • Proactive self-learner with initiative to stay ahead of emerging security threats and technologies

  • Curiosity-driven approach to exploring new attack vectors and security domains

 

 

Who we are

A healthier future drives us to innovate. Together, more than 100’000 employees across the globe are dedicated to advance science, ensuring everyone has access to healthcare today and for generations to come. Our efforts result in more than 26 million people treated with our medicines and over 30 billion tests conducted using our Diagnostics products. We empower each other to explore new possibilities, foster creativity, and keep our ambitions high, so we can deliver life-changing healthcare solutions that make a global impact.


Let’s build a healthier future, together.

Roche is an Equal Opportunity Employer.

Experience Level

Mid Level

Job role

Work location
Work locationPune DIA, India
Department
DepartmentIT & Information Security
Role / Category
Role / CategoryIT Security
Employment type
Employment typeFull Time
Shift
ShiftDay Shift

Job requirements

Experience
ExperienceMin. 4 years

About company

Name
NameRoche Diagnostics India Pvt Ltd
Job posted by Roche Diagnostics India Pvt Ltd

Similar jobs you can apply for

Manufacturing / Production

Senior Engineer

Ha Brick
Hinjewadi, Pune
₹35,000 - ₹40,000
Work from Office
Full Time
Min. 3 years
Basic English
Edugenius Softwares

Hardware Engineer

Edugenius Softwares
Pune
₹12,000 - ₹15,000
Work from Office
Full Time
Any experience
Basic English
Orcatech Enterprises

Site Installation Coordinator

Orcatech Enterprises
Nanded, Pune
₹12,000 - ₹15,000
Work from Office
Full Time
Any experience
No English Required
Saber Softech Private Limited

Hardware Engineer

Saber Softech Private Limited
Yerawada, Pune
₹15,000 - ₹25,000
Work from Office
Full Time
Min. 6 months
Basic English
Saiyash Technologies

Desktop Support Engineer

Saiyash Technologies
Parvati Paytha, Pune
₹20,000 - ₹30,000
Field Job
Full Time
Any experience
Basic English

Hardware Engineer

Sharp Enterprises
Kothrud, Pune
Not disclosed
Field Job
Part Time
Full Time
Any experience
Basic English

You can expect a minimum salary of 0 INR. The salary offered will depend on your skills, experience and performance in the interview.

The candidate should have completed the required education and people who have 4 to 7 years are eligible to apply for this job. You can apply for more jobs in Pune to get hired quickly.

The candidate should have sound communication skills and sound communication skills for this job.

Both Male and Female candidates can apply for this job.

No, it's not a work from home job and can't be done online. You can explore and apply for other work from home jobs in Pune at apna.

No work-related deposit needs to be made during your employment with the company.

Go to the apna app and apply for this job. Click on the apply button and call HR directly to schedule your interview.

The last date to apply for this job is . For more details, download apna app and find Full Time jobs in Pune . Through apna, you can find jobs in 64 cities across India. Join NOW!