hirly

Roche

Systems Design/Architecture Engineer

India

See how you match this job — and similar ones. Free.

Upload your resume and hirly scores it against this role at Roche first, then against similar open jobs, and shows where you fit and why.

PDF or DOCX, up to 12MB. No sign-up to see your matches.

Get past the screening software and onto a recruiter's desk

hirly rewrites your resume for this job — matching the keywords and skills in the posting, moving your most relevant experience to the top, and writing a cover letter to fit. About 30 seconds.

  • Keywords matched to this posting
  • Fit score before you apply
  • Cover letter included

Matched against 2.3M live jobs from 200,000+ employers in 200+ countries.

Tailor my resume for this job →

hirly's read of this role

Role family
Engineering
Seniority
Mid level
Country
IN
Work mode
On-site / unstated
First seen by hirly
23 Sept 2026

Derived automatically from the posting. Upload your resume above to see how the role scores against it.

the posting

At Roche you can show up as yourself, embraced for the unique qualities you bring. Our culture encourages personal expression, open dialogue, and genuine connections, where you are valued, accepted and respected for who you are, allowing you to thrive both personally and professionally. This is how we aim to prevent, stop and cure diseases and ensure everyone has access to healthcare today and for generations to come. Join Roche, where every voice matters.

The Position Senior Software Engineer — Identity & Customer Platform (CIAM)

Experience: 3–5 years | Stack: Java 21 · Spring Boot · Keycloak · AWS · React/TypeScript

  • About the role
  • You'll build and operate the services behind our Customer Identity & Access Management (CIAM) platform — authentication, authorisation, user account management, and the migration of legacy identity systems onto Keycloak. This is a polyglot, multi-repo environment: most of the weight is backend Java, with meaningful frontend and infrastructure work alongside it.
  • What you'll do

Design and ship backend services in Java 21 / Spring Boot (REST via Spring MVC, Jersey/JAX-RS, and Spring Cloud Gateway on WebFlux).

Extend Keycloak 26 through custom SPIs, authentication flows, and themes; contribute to realm configuration managed as code.

Build event-driven and data-backed features on AWS — SQS/SNS, S3, Secrets Manager — with PostgreSQL and Liquibase schema migrations.

Drive the strangler-pattern migration of legacy identity services with zero-downtime cutovers.

Design API contracts first (OpenAPI/springdoc, generated clients, contract diffing in CI) and keep them backward compatible.

Write meaningful tests at every level: JUnit 5, AssertJ, Mockito, ArchUnit, Testcontainers (Postgres + LocalStack), WireMock, REST Assured.

Own your services in production: Datadog APM/RUM, Micrometer/OpenTelemetry, structured JSON logging, and on-call participation.

Ship through GitHub Actions pipelines with SonarQube quality gates, JaCoCo coverage, CycloneDX SBOMs, and strict Gradle dependency locking.

Review peers' code and participate in architecture decisions — not just implement tickets.

Must have (4–5 years)

4+ years of professional JVM development, with recent work on Java 17/21 and Spring Boot.

Solid grasp of OAuth 2.0, OIDC, JWT, and SAML — you can explain authorization code + PKCE, token exchange, and refresh token rotation without looking them up.

Hands-on relational database work: schema design, indexing, query tuning, and versioned migrations (Liquibase or Flyway).

Practical AWS experience running production workloads (messaging, storage, secrets, IAM).

Docker and container-based local development; comfort with Docker Compose and Testcontainers.

Strong automated testing discipline — you treat tests as part of the deliverable, not an afterthought.

Git-based trunk/feature-branch workflow, CI/CD pipelines, and code review as a daily habit.

Clear written communication in English; ability to document decisions and trade-offs.

Strongly preferred

Direct Keycloak experience (custom providers, SPIs, admin client, theming) or comparable IdP work (Auth0, Gigya, Okta, ForgeRock).

Gradle (Kotlin DSL) in a multi-module / platform-BOM setup.

React 18 + TypeScript with Vite — enough to own a full vertical slice through the UI.

Node.js/Express services in TypeScript.

Kubernetes and Helm; Terraform for infrastructure and IdP configuration as code.

Observability practice: dashboards, SLOs, alerting, and debugging distributed traces.

Experience in a regulated environment (healthcare/life sciences, GxP, HIPAA/GDPR) — data privacy is a first-class concern here.

Nice to have

Python (tooling/automation), Ruff/pytest.

Playwright or Cypress end-to-end testing; visual regression testing.

Performance/load testing (k6, JMeter).

Application security background: OWASP Top 10, SAST/DAST, dependency and SBOM hygiene.

Who we are A healthier future drives us to innovate. Together, more than 100’000 employees across the globe are dedicated to advance science, ensuring everyone has access to healthcare today and for generations to come. Our efforts result in more than 26 million people treated with our medicines and over 30 billion tests conducted using our Diagnostics products. We empower each other to explore new possibilities, foster creativity, and keep our ambitions high, so we can deliver life-changing healthcare solutions that make a global impact.

Let’s build a healthier future, together.

Roche is an Equal Opportunity Employer.

Original posting on Roche's site ↗

Want this one?

Upload your resume and hirly rewrites it for this job and writes the cover letter — in about thirty seconds, before you sign up.

Tailor my resume for this job