hirly

Roche

Principal Enterprise Identity Engineer

Madrid

See how you match this job — and similar ones. Free.

Upload your resume and hirly scores it against this role at Roche first, then against similar open jobs, and shows where you fit and why.

PDF or DOCX, up to 12MB. No sign-up to see your matches.

Get past the screening software and onto a recruiter's desk

hirly rewrites your resume for this job — matching the keywords and skills in the posting, moving your most relevant experience to the top, and writing a cover letter to fit. About 30 seconds.

  • Keywords matched to this posting
  • Fit score before you apply
  • Cover letter included

Matched against 2.5M live jobs from 200,000+ employers in 200+ countries.

Tailor my resume for this job →

Apply from your AI assistant

Connect hirly to Claude and ask it to apply to this job. hirly tailors your resume, fills the employer’s form and asks before sending. ChatGPT: manual setup today.

Some employer sites stop an application at a CAPTCHA or sign-in and hand it back with a link. Applying needs a paid plan. Works with any assistant that supports MCP.

hirly's read of this role

Seniority
Lead / management
Country
ES
Work mode
On-site / unstated
First seen by hirly
3 Oct 2026

Derived automatically from the posting. Upload your resume above to see how the role scores against it.

the posting

At Roche you can show up as yourself, embraced for the unique qualities you bring. Our culture encourages personal expression, open dialogue, and genuine connections, where you are valued, accepted and respected for who you are, allowing you to thrive both personally and professionally. This is how we aim to prevent, stop and cure diseases and ensure everyone has access to healthcare today and for generations to come. Join Roche, where every voice matters.

The Position

As the Principal Enterprise Identity Engineer, you are the ultimate technical authority and visionary for our global Enterprise Identity Management (EIM) and Identity Governance and Administration (IGA) landscape. Moving beyond individual contribution, you will define the multi-year identity strategy, driving zero-trust initiatives across a highly complex, global ecosystem.

Operating at the highest levels of our technical ladder, you will bridge the gap between executive business strategy and deep technical execution. You will architect resilient, massively scalable identity frameworks, mentor senior engineering talent, and lead cross-functional transformations that protect our most critical global assets while enabling frictionless business operations.

Job Responsibilities

Lead the multi-year roadmap and end-to-end technical strategy for enterprise identity, aligning IGA architectures with global security policies and zero-trust frameworks.

Establish and enforce enterprise-wide architecture patterns, engineering standards, and reusable frameworks across identity, cloud, and infrastructure domains.

Architect and oversee the deployment of next-generation, SailPoint-based EIM solutions that operate flawlessly at a massive, distributed scale.

Translate complex security paradigms and regulatory requirements into actionable, board-level technical strategies.

Pioneer the adoption of emerging identity technologies, including decentralized identity, advanced ML-driven access analytics, and complex microservice/API integrations.

Act as the technical cornerstone for the identity organization, mentoring senior engineers and leading Tier 4 escalation and root-cause analysis for catastrophic or highly complex systemic issues.

Qualifications and Core Expertise

Minimum of 12 years of hands-on engineering experience in Cybersecurity and Identity Management, with at least 5 years operating at an enterprise architecture or principal level.

5+ years of experience steering identity strategies in highly regulated, multinational enterprise environments (Healthcare, Finance, or similar industries highly preferred).

Deep-tier technical expertise in SailPoint (IdentityNow/IdentityIQ), encompassing enterprise-scale design, custom development, performance tuning, and global deployment.

Expert-level proficiency in Java and Python for developing highly complex connectors, custom rules, and automated workflows.

Proven track record of architecting integration solutions across complex multi-cloud environments (AWS, Azure, GCP) and profound familiarity with CI/CD pipelines, DevOps methodologies, and microservices.

Deep, authoritative understanding of RBAC, PBAC, Segregation of Duties (SoD), and advanced access governance frameworks.

Exceptional executive presence with the ability to communicate deeply technical concepts to non-technical C-suite stakeholders and lead distributed global engineering teams autonomously.

Education & Certifications

Degree: Bachelor’s or Advanced degree (Master’s preferred) in Computer Science, Cyber Security, Information Technology, or a related field.

Required Certifications: CISSP, CISM, or CIAM is strongly preferred for this leadership level.

Technical Certifications: Advanced certifications in AWS/Azure/GCP Architecture or SailPoint highly desirable.

#RDT

Who we are

A healthier future drives us to innovate. Together, more than 100’000 employees across the globe are dedicated to advance science, ensuring everyone has access to healthcare today and for generations to come. Our efforts result in more than 26 million people treated with our medicines and over 30 billion tests conducted using our Diagnostics products. We empower each other to explore new possibilities, foster creativity, and keep our ambitions high, so we can deliver life-changing healthcare solutions that make a global impact.

Let’s build a healthier future, together.

Roche is an Equal Opportunity Employer.

Original posting on Roche's site ↗

Browse similar roles

Want this one?

Upload your resume and hirly rewrites it for this job and writes the cover letter — in about thirty seconds, before you sign up.

Tailor my resume for this job