PBAC Operations Engineer - RDT Identity & Access Management
Roche · Pune/Pimpri-Chinchwad Area
- Experience5–9 yrs
- SalaryNot disclosed
- Work modeonsite
- Levelsenior
- Posted18 Sept 2026
About Roche
Roche is hiring in Pune/Pimpri-Chinchwad Area in pharma biotech. This role looks for around 5+ years of experience.
Skills
- Policy Based Access Control
- identity and access management
- XACML
- Policy as Code
- SAML
- OAuth
- OIDC
- Single Sign-On
- Identity Governance and Administration
- Java
- Python
- Git
- CI/CD pipelines
- Zero Trust security
- RESTful APIs
- SQL
- JDBC
- LDAP
- ITIL
- GDPR
The role
A security engineer at a global healthcare technology company designs and operates policy-based access control infrastructure, applying identity and access management and Zero Trust security to protect enterprise systems. The work integrates authorization services through RESTful APIs and automates policy deployment with CI/CD pipelines.
Full job description
At Roche you can show up as yourself, embraced for the unique qualities you bring. Our culture encourages personal expression, open dialogue, and genuine connections, where you are valued, accepted and respected for who you are, allowing you to thrive both personally and professionally. This is how we aim to prevent, stop and cure diseases and ensure everyone has access to healthcare today and for generations to come. Join Roche, where every voice matters.
The Position
PBAC Operations Engineer - RDT Identity & Access Management
Location: Pune
As part of Roche Digital Technology (RDT), our Identity and Access Management (IAM) team protects the organization’s global digital assets by developing and operating sophisticated security platforms. We work at the forefront of identity governance, fine-grained authorization, and hybrid cloud security to support users and business-critical systems in a highly regulated global healthcare ecosystem.
As a PBAC Operations Engineer in the Identity and Access Management (IAM) space, you will be part of a global team responsible for the design, implementation, and lifecycle management of our Policy Based Access Control (PBAC) infrastructure. You will play a critical role in protecting our information and assets by moving beyond traditional access models toward a dynamic, fine-grained authorization framework that supports our global Zero Trust strategy. In this role, you will be the technical owner of the PBAC infrastructure, ensuring it is scalable, resilient, and deeply integrated into the Roche digital ecosystem.
The Opportunity
In this role, you will lead complex PBAC implementations and shape the future of dynamic authorization across our global enterprise. You will:
Architect and maintain core PBAC components (PDP/PEP) across a hybrid global landscape to ensure high availability, resilience, and performanceLead the transition from initial use cases to enterprise-wide adoption while defining organization-wide standards for policy-based authorizationAct as the primary technical consultant for application and data owners to seamlessly integrate systems via RESTful APIs, SQL/JDBC, and LDAPDrive the shift to Policy as Code (PaC) by designing automated pipelines for versioning, testing, and deploying authorization logic like softwareOwn the tactical lifecycle of the platform, including version upgrades, security patching, continuous performance tuning, and managing external Managed Service Providers (MSPs)Streamline onboarding processes for new assets, ensuring strict alignment with global security standards, ITIL change principles, and regulatory requirements such as GDPRBridge the gap between vendor capabilities and internal business requirements while navigating complex stakeholder networks across global cluster squadsCollaborate with product managers and developers to resolve unusually complex problems and create secure, user-friendly authorization flows
Who you are
We are looking for an expert technical leader who combines deep IAM expertise with strong stakeholder alignment skills. To excel in this role, you bring:
Experience: 5–9 years of experience in IT/Security, with 4+ years dedicated to IAM and specific expertise in PBAC/ABAC within large enterprise environmentsEducation: A Bachelor's degree in a technical field is required; a Master's degree or Ph.D. is preferredTechnical Mastery: Advanced knowledge of XACML, Policy as Code (PaC), and decentralized policy management alongside standard IAM protocols (SAML, OAuth, OIDC, SSO, and IGA)Development & DevOps: Proficiency in Java or Python for custom integrations, paired with hands-on experience using Git and CI/CD pipelines for secure code deploymentArchitectural Mindset: Strong advocacy for Zero Trust principles, prioritizing configurable off-the-shelf capabilities over custom builds for long-term maintainabilityConsulting & Analysis: Proven ability to apply systems thinking to complex business problems, conducting root cause analysis, eliciting requirements, and advising senior leadershipCommunication & Collaboration: Excellent English communication skills to explain complex concepts to non-technical stakeholders, mentor team members, and navigate dynamic cross-functional environments
Call to Action
Ready to bring your unique qualities to Roche and make an impact? Apply now and join us in our mission to shape the future of healthcare.
#RDT2026
Who we are
A healthier future drives us to innovate. Together, more than 100’000 employees across the globe are dedicated to advance science, ensuring everyone has access to healthcare today and for generations to come. Our efforts result in more than 26 million people treated with our medicines and over 30 billion tests conducted using our Diagnostics products. We empower each other to explore new possibilities, foster creativity, and keep our ambitions high, so we can deliver life-changing healthcare solutions that make a global impact.
Let’s build a healthier future, together.
Roche is an Equal Opportunity Employer.