OpenAIRemote · San Francisco$401k-$536kjust now
RochePosted 3w ago
AI and Automation Engineer-Information Security Governance at Roche scores 65 out of 100 on AI centrality, which makes it AI Level 3 of 4 (Works on AI) on this board. The level measures how much of the work is AI, not seniority.
AI in this role
At Roche you can show up as yourself, embraced for the unique qualities you bring. Our culture encourages personal expression, open dialogue, and genuine connections, where you are valued, accepted and respected for who you are, allowing you to thrive both personally and professionally. This is how we aim to prevent, stop and cure diseases and ensure everyone has access to healthcare today and for generations to come. Join Roche, where every voice matters.
The Position
The Information Security & Privacy By Design team is the engine behind Roche’s security governance. We design, deliver, and support the digital frameworks that protect our organization, including IRAAM (Information Risk Assessment And Mitigation), PETRA (Policy Exceptions Tool for Risk Assessment ), OIA (Outsourcing Impact Assessment), and our cutting-edge GenAI security agents.
As an AI & Automation Engineer, you are the vital architect bridging the gap between high-level security expertise and scalable, self-service execution. Your mission is to democratize security and privacy knowledge by building intelligent agents and low-code tools that empower Roche employees. You don’t just manage risk; you build the "digital brains" that make risk management proactive, intuitive, and frictionless.
You are an "implementer" who thrives on turning strategic advice into functional code. You believe that security governance is most effective when it is invisible, automated, and powered by data.
Description of the Area
The Information Security & Privacy By Design team makes Roche’s information security governance accessible through actionable processes. The capabilities we provide enable Roche to identify, assess, monitor, and mitigate information risks, manage regulatory compliance, and oversee third-party and personal data processing risks. Our processes are primarily instantiated in the ServiceNow IRM Platform. We work closely with Information Security, Privacy, Risk & Compliance, and IT teams to provide enterprise visibility into Roche’s information risk posture.
You’ll be working within the Information Security Governance (ISG) area. ISG is responsible for defining the strategic agenda for information security and privacy topics at the Roche Group level. This is realized within the global Information Security Management System (ISMS) which aligns business and IT strategies, business and technical projects, policies, standards, directives, procedures, governance, legal / regulatory, compliance, and other requirements at a global level.
The Information Security & Privacy by Design area is accountable for co-developing, in collaboration with key stakeholders, and stewardship of the strategic direction of the Information Risk Assessment processes based on organizational objectives, industry practices and legal / regulatory requirements - e.g IRAAM, PETRA, OIA. This includes oversight, awareness, direction and continuous improvement to the end-to-end processes and their relevant risk modules in alignment with the global ISMS, corporate directives and Roche management systems (e.g. privacy, quality, risk).
Job Responsibilities
1. AI Solution Development & Knowledge Engineering
Security AI Stewardship: Own the development and roadmap of internal AI-based advisory tools. You will transform static security policies and KB articles into interactive, intelligent agents.
Retrieval Augmented Generation (RAG): Build and optimize data pipelines to ingest diverse sources—including Google Docs, ServiceNow KB articles, and slide decks—into AI models to ensure accurate, grounded advisory.
Prompt Engineering & Tuning: Continuously refine LLM performance to ensure security and privacy advice is technically sound, brand-aligned, and user-friendly.
2. Low-Code & Automation Engineering
Self-Service Platforms: Leverage Roche’s low-code platforms( e.g. LEAP Outsystems or similar) to build front-end interfaces that provide employees with 24/7 security guidance.
Workflow Automation: Identify manual bottlenecks in the IRAAM/PETRA/OIA workflows and engineer automated solutions to streamline the user journey.
Infrastructure Maintenance: Maintain and optimize essential operational tools (e.g., Google Apps Script used for the Security Expert Review Triage) ensuring reliable data aggregation from Snowflake, Thoughtspot, and ServiceNow.
3. Operational Excellence & Support
Technical Support: Act as the primary technical contact for AI and automation tool incidents, troubleshooting issues and coordinating with platform teams for permanent fixes.
User Enablement: Support the Information Security Coordinator (ISC) network and end-users, ensuring they understand how to maximize the value of our automated security tools.
Performance Monitoring: Analyze tool usage and AI response accuracy, using data insights to propose continuous feature enhancements.
4. Evangelism & Partnership
Expert Collaboration: Partner with Security and Privacy Experts to "translate" their deep knowledge into logic-based automation and AI workflows.
AI Frontier Leadership: Act as a subject matter expert within the team, researching emerging AI trends and machine learning applications that can assist in threat identification and policy analysis.
Qualifications
Experience
AI/ML Engineering: 3–5 years of hands-on experience in AI/ML applications and workflow automation.
RAG & LLM Integration: Proven ability to engineer data pipelines and mitigate AI hallucinations to ensure highly accurate, grounded outputs.
Low-Code Development: Prior experience with Outsystems (Roche LEAP) or similar enterprise-grade low-code technologies.
Regulated Industry: Experience working in regulated environments (Pharmaceutical, Healthcare, or Finance) is a plus.
Education
Bachelor’s degree in Computer Science, Software Engineering, Information Systems, or a related technical field.
Technical & Business Skills
Architectural Mindset: Ability to design complex data flows that connect unstructured documents to structured AI outputs.
Automation Mastery: Proficiency in JavaScript/ Google Apps Script, Python and experience with Data Visualization tools (e.g., Snowflake, Thoughtspot, or Tableau).
Platform Knowledge: Foundational knowledge of ServiceNow (GRC and ITSM) is a significant advantage.
Security Foundation: Notions of Information Security principles and data privacy (understanding the "why" behind risk controls).
Analytical Problem Solving: A knack for debugging complex automation failures and identifying "root causes" in AI hallucinations or data mismatches.
User-Centric Design: A passion for building tools that are intuitive and desirable for employees to use.
Leadership Skills
Communication: Strong ability to build trust with security experts and explain technical AI/automation concepts to non-technical stakeholders.
Innovation & Curiosity: A relentless passion for applying GenAI/LLMs to solve real-world productivity challenges.
Thriving in Ambiguity: Ability to navigate complexity and drive clarity when translating strategic advice into functional tools.
Self-Starter: Proven ability to manage technical workstreams from concept to production with minimal supervision.
Who we are
A healthier future drives us to innovate. Together, more than 100’000 employees across the globe are dedicated to advance science, ensuring everyone has access to healthcare today and for generations to come. Our efforts result in more than 26 million people treated with our medicines and over 30 billion tests conducted using our Diagnostics products. We empower each other to explore new possibilities, foster creativity, and keep our ambitions high, so we can deliver life-changing healthcare solutions that make a global impact.
Let’s build a healthier future, together.
Roche is an Equal Opportunity Employer.
Prepare for this job
A free preview built only from this posting: what it asks for, what you could be asked in an interview, and how to adjust your resume.
Skills and AI tools this role asks for
Questions you could be asked
- How do you structure and test a prompt to get consistent output from a language model?
- How would you design a retrieval step so the model answers from real data instead of guessing?
- How have you integrated a large language model into a production application?
- Describe a typical day in a role like this one: which parts run through AI directly?
- If you removed AI from this role, what would be left, and how do you decide what still needs a human?
Adapt your resume
- List these exact terms on your resume: Prompt Engineering, Rag, and Llm Integration. An applicant tracking system matches the wording, not the idea.
- Attach one line of real, concrete experience to at least one of them — a tool named with nothing behind it rarely survives a human read.
- Show where AI is part of your daily process, not a one-off project — this role expects it to be a running habit.
Want your resume actually rewritten for this job?
The free preview above is everything we have today. A full resume rewrite is not live yet and has no price set. Join the waitlist and we will email you if we open it.
Get new AI jobs at AI Level 3+ by email
One email a week with the new AI jobs at AI Level 3+, each rated AI Level 1 to 4 for how much AI is in the work. No recruiter spam, unsubscribe in one click.
Free. One email a week. Unsubscribe in one click.
Similar roles
Software Engineering roles rated AI Level 3 at other companies.
DatabricksStockholm, Sweden3h ago
DeepJudgeZurich HQ4h ago
Axelera AIRemote · Hybrid/Remote - Europe (incl. UK)5h ago
NotionDublin, Ireland5h ago
LegoraStockholm HQ7h ago
SnowflakeIN-Pune12h ago
NscaleAPAC; Singapore14h ago
What kind of AI work fits you?
Answer 12 practical questions in about three minutes. Get a simple profile, the work it points to, and live roles to explore next.
Find my next step





