Staff Product Security Engineer
GE Healthcare Private LimitedJob Description
Staff Product Security Engineer
Job Description Summary
Join a dynamic team that’s transforming how the Patient Care Solutions Products and Solutions at GE HealthCare are architected, secured and delivered to our customers. As a Staff Product Security Engineer you’ll be working on products and solutions that provide clinical excellence at the point of care, with a focus on representing Security/Privacy on the product development team. This position requires understanding of secure product development, system design, post-market security assessments and strong analysis/problem-solving skills.This role will develop deep product domain and customer use environment knowledge of the product’s clinical functionality, expected operating environment and interoperability to accurately determine privacy and security risks. Join the Patient Care Solutions Transformation at GE HealthCare!
Job Description
Responsibilities:
- Represent the Security/Privacy needs of the product design and development teams. Including security/privacy requirements capture, consulting development activities to ensure compliance and secure product testing.
- Work with the Product Security Leader (PSL) to support the product team with process expertise for the GEHC Product Cybersecurity Standard and lifecycle management.
- Lead threat modeling sessions to identify security concerns within the products and solutions. Develop methods to implement security controls based on the system threat model.
- Own the Cybersecurity Management Plan, including the identification, assessment, reporting and mitigation plans for product vulnerabilities. Collaborate with Program Managers, functional leadership and program teams on program scope and priority to address vulnerabilities in a timely manner.
- Generate and maintain the Software Bill of Materials (SBOM). Assess product components and SBOMs integrated into the product.
- Have a complete understanding of the various interdependency and limitations as they refer to security controls within the system.
- Scope and participate in penetration tests, vulnerability scanning and product security risk assessments including remediation planning and closure.
- Create Design Engineering Privacy and Security (DEPS) artifacts for privacy and security activities throughout the product lifecycle, from initial concept through end-of-life.
- Maintain effective quality management system (QMS) compliance with GE HealthCare Quality policies.
Qualifications/Requirements:
- Bachelor's Degree in a relevant field (e.g. Computer Engineering, Computer Science, Information Security) or in a STEM major (Science, Technology, Engineering, or Math)
- 6+ years of product or systems experience with at least 5 years of application security
- Working knowledge of regulatory standards and compliance frameworks (e.g., NIST CSF/800-53, ISO27001, SOC2, HIPAA, HITRUST and GDPR).
- Understanding of secure coding principles, such as the OWASP Top Ten.
- Demonstrated technical leadership capability working on a product development team
- Demonstrated ability to act as a leader-among-peers in a global environment
- Demonstrated ability to work with design scrum teams on the design & implementation of security controls
- Self-starter, energizing, results oriented and able to multi-task
- Effective oral and written communication skills
Desired:
- Master’s degree in STEM with a focus on application security.
- Experience working with application security tools such as Microsoft Threat Modelling Tool, Black Duck, Syft, Burpsuite, Grype, or similar tools.
- Experience with penetration testing and ethical hacking concepts (red team/blue team).
- Experience in Identity management and identity federation tools. (SAML, Oauth, SCIM, XACML).
- Experience working in a medical device regulated environment, including FDA.
- Strong technical understanding of various network protocols and strategies to secure them
- Strong technical understanding of various network services and APIs (eg. network proxies, API gateways)
- Working understanding of enterprise-grade software to embedded software technology
- Security certification(s) not limited to CISSP/CISM, CSSLP, CEH, OCP are a plus.
Additional Information
Relocation Assistance Provided: No
Experience Level
Senior LevelJob role
Job requirements
About company
Similar jobs you can apply for
Manufacturing / ProductionMaintenance Engineer
Persolkelly India Private Limited
Assistant Engineer
Bon Technologies (Mumbai) Private Limited
Electronic
LWI Electronics Inc
Engineering Project Manager
Sriameya Projects India
Hardware & Network Engineer
Chanak Tech ServicesInstallation Engineer
V5 GlobalYou can expect a minimum salary of 0 INR. The salary offered will depend on your skills, experience and performance in the interview.
The candidate should have completed the required education and people who have 6 to 31 years are eligible to apply for this job. You can apply for more jobs in Bengaluru/Bangalore to get hired quickly.
The candidate should have sound communication skills and sound communication skills for this job.
Both Male and Female candidates can apply for this job.
No, it's not a work from home job and can't be done online. You can explore and apply for other work from home jobs in Bengaluru/Bangalore at apna.
No work-related deposit needs to be made during your employment with the company.
Go to the apna app and apply for this job. Click on the apply button and call HR directly to schedule your interview.
The last date to apply for this job is . For more details, download apna app and find Full Time jobs in Bengaluru/Bangalore . Through apna, you can find jobs in 64 cities across India. Join NOW!