Intern Product Cybersecurity Analyst
Stage Rotkreuz, SWITZERLAND IT development
Job description
The Position
Scorecards serve as a visual representation of the security posture of a digital product. They provide a means to compare different products, enabling product managers to assess the product performance in terms of cybersecurity. By highlighting areas that require improvement, scorecards serve as a motivation to enhance product cybersecurity. Additionally, they offer valuable guidance on what aspects need attention and how to implement necessary improvements. The target audience for the scorecards are product managers, supporting them in making informed decisions regarding secure development practices.
As part of the scorecards, the product security department plans to hand out recommendations that align with the results and areas of improvement identified. The recommendations can be exported automatically when printing the scorecard, aiming to enhance the overall score and consequently improve the cybersecurity of the product. Providing those recommendations will be the main task of the internship. Additionally, conducting research and summarising best practices for secure development and secure operations is crucial. This information can be used to write blog articles that provide further readings on the topics evaluated in the scorecard. The recommendations can then link to those articles, covering areas such as best practices and easy improvements. Reading into Roche's secure development standards and guidelines can help find connected contents that can support the recommendations. Lastly, collecting feedback from the product teams regarding the recommendations is essential to ensure continuous improvement in cybersecurity practices.
The contents of the internship can cover 3 to 6 months, depending on the preferences and availability of the intern. Since the scorecard project is still in development, it is beginner friendly when catching up with the progress and can provide valuable insights into building a corporate solution as it is growing fast. Additional responsibilities and tasks can be tailored to the intern’s interests.
Main Tasks
Creating recommendations based on the results and areas of improvement identified in the scorecards in order to help product teams improve their score and with that the cyber security of the product
Researching and summarising best practices for secure development and secure operations
Writing content (e.g. blog articles) with further readings on the topics evaluated with the scorecard to be linked in the recommendations (best practices, easy improvements, technical trends, …)
Researching connected contents in the Roche standards and guidelines
Collecting feedback from the product teams regarding the recommendations
Possible Complementary Tasks (based on interest)
Researching connected contents in public standards and guidelines (FDA, GDPR, in-vitro diagnostics regulations, ...) or state of the art best practices
Taking on development tasks on the scorecard backend (API integrations, score calculation, data model and representation, new features, new evaluation criteria)
User experience tasks on the scorecard’s frontend (design reworks, plotting data more comprehensively, collecting feedback on the comprehensibility, wording, ...)
Defining new features, maintaining a backlog of feature requests and documenting the expected behaviour of new features
Testing the scorecards against the requirements
Estimating the confidence in the score ranking based on the input data quality
Being involved into project planning of the scorecard project’s next steps, dependencies and stakeholders
Who we are
At Roche, more than 100,000 people across 100 countries are pushing back the frontiers of healthcare. Working together, we’ve become one of the world’s leading research-focused healthcare groups. Our success is built on innovation, curiosity and diversity.
Roche Diagnostics International in Rotkreuz is a leading provider of diagnostic systems solutions, and the largest manufacturer of fully automated in vitro diagnostic systems in Switzerland. We are more than 2’700 passionate colleagues from over 65 nationalities. Find out more about our site in Central Switzerland, here.
Besides extensive development and training opportunities, we offer flexible working options, 18 weeks of maternity leave and 10 weeks of gender independent partnership leave. Our employees benefit from multiple services on site such as child-care facilities, medical services, restaurants and cafeterias, as well as various employee events.
We believe in the power of diversity and inclusion, and strive to identify and create opportunities that enable all people to bring their unique selves to Roche.
Roche is an Equal Opportunity Employer.