Senior Product Security Engineer

4 weeks ago


Hyderabad, Telangana, India Medtronic Full time

Career That Changes Lives

The Principal Cyber Info Assurance Analyst will join the Business Information Security team within the Business Partner Services (BPS) group and partner closely with the Global Security Office (GSO). You will serve as a champion of the GSO, focusing on enhancing user experience with our business partners. You'll serve as a cybersecurity and compliance subject matter expert (SME) to the intelligent Data Solutions business. The cybersecurity SME will focus on identifying, prioritizing and driving remediation of all security risks owned by the business 

The primary focus of the role will be on supporting implementation of achieving and/or maintaining HIPAA, GDPR and other regulatory compliance, and achieving and maintaining the ISO27011 and HITRUST certifications. You will facilitate and assist the business by interpreting the requirements and driving technical remediations. Communicate, escalate, and track progress on assessment remediation activities. Understand information security risks that are inherent to a business and articulate those risks in business terms. Support Commercial activities including contracting and IT/security questionnaires. Maintain current knowledge on data privacy and information security topics and their applicable program requirements. Provide concierge service to our business stakeholders when interacting with the GSO.

We believe that when people from different cultures, genders, and points of view come together, innovation is the result —and everyone wins. Medtronic walks the walk, creating an inclusive culture where you can thrive.

Bring your talents to an industry leader in medical technology and healthcare solutions – we're a market leader and growing every day. You can be proud to be a part of technologies that are rooted in our long history of mission-driven innovation. You will be empowered to shape your own career. We support your growth with the training, mentorship, and guidance you need to own your future success. Together, we can transform healthcare.

Join us for a career in IT that changes lives.

Medtronic is committed to fostering a diverse and inclusive culture. Check out the accomplishments of our Women in IT group ;

A Day in the Life

Maintain relationships within Operating Unit proactively share business' upcoming projects to the GSO Engage with cross functional teams to drive complex data security issues to resolution Contribute continuous improvement to the methodologies and practices of the Business Information Security to attain higher capability maturity levels Track status of open requests/tasks and drive accountability of requestors to ensure timely submitting Partner with the GSO and Privacy to perform deep dives over high risk processes and systems to identify and remediate gaps in data security Support implementing monitoring Security compliance activities related to HITRUST, ISO27001, SOC2, etc. Help facilitate and/or respond to Customer Inquiries Streamline processes and use of tools across Global IT to ensure data flow and security is maintained in the most efficient way possible Provide insight and business background to include data security, encryption, authorization, authentication, and access controls to the GSO process teams, when needed Prepare status reports on data security and privacy matters to educate the Business Relationship Managers (BRM) and business leadership about business owned IT security risks Compile and communicate security/privacy risk to Business IT Leadership, BRMs and business leadership as appropriate Establish a forum for outreach to the broader organization you represent to educate business requestors, business leaders, and IT leadership on the GSO Engagement processes Demonstrate strong knowledge of IT security controls, security risk and threats Regularly meet with the GSO to discuss issues, concerns, complex or high visibility projects, process improvement areas, and review SLA goals and actual results – leverage these relationships and information to ensure business readiness, engagement, and alignment with security programs and initiatives. Act as a resource for security compliance questions, risks, and concerns for the bisomess Perform other security-related duties as and when directed by the Business Information Security management Engage in stakeholder management in their respective business Reach out and meet with stakeholders, educate them about the GSO and Global IT  Serve business stakeholders and requesters as "Customers" with a focus on service and support Advise business / R&D teams on attaining security reviews earlier in their projects Hold yourself and your business accountable for committed deliverables and deadlines Ensure timely response to requests for security support from the business.

Basic Qualifications

Must Have (Minimum Qualifications)


• High school diploma (or equivalent) and 12+ years of experience
OR

• Bachelor's degree and 7+ years of experience or advanced degree and 5+ years of experience

Desired / Preferred Qualifications

Nice To Have (Preferred Qualifications)

Previous Medtronic experience Preference given to current Medtronic employees Strongly preferred: Experience in audit, risk management, vulnerability management, governance, IT security and/or compliance functions Experience with cloud storage systems/PaaS/SaaS Experience with AWS highly regarded Clear understanding of product architecture, data, data flows, and usage Experience working across business units and geographical boundaries to engage IT, business counterparts, and team members Ability to understand, question, and interpret internal and external security environments 3+ years working in IT GRC or controls function Proven experience dealing with ambiguous situations, and producing a consistent result with varied input Working knowledge of IT and security control frameworks (NIST, CobiT, ITIL, CyberEssentials, HDH), as well as regulatory requirements (PCI, HIPAA, GDPR, CCPA) Knowledge of information risk concepts and practices required Knowledge of controls manifestation in large global corporations with regional and local presence is required Experience communicating conceptual and technical information Experience translating technical data into business impact information Experience working with ServiceNow GRC (Governance, Risk, and Compliance) Knowledge of Frameworks, including PCI, SOX and ISO 27001 is a plus Detailed knowledge of ITGRC, Auditing principles / practices is desired Good understanding of Vendor management desired Good understanding of security frameworks desired, included but not limited to NIST, HISTRUST, OWASP, etc. Good project management skills desired Experience in examining reports on security controls (SSAE-16, PCI-ROC, Application Security Assessments)

  • Hyderabad, Telangana, India Bristol Myers Squibb Full time

    The Senior Security Engineer, SAP Security is responsible for designing and implementing the Security for SAP S4 HANA and other SAP systems such as Governance Risk and Compliance (GRC), Project and Portfolio Management (PPM), as well as SAP Fiori and SAP Business Technology Platform.The Digital Capability Security Manager provides direct governance and...


  • Hyderabad, Telangana, India Medtronic Full time

    Careers that Change Lives Summary of the position: The Product Security Engineer position will provide Product Security support and leadership within the Enabling Technologies (ET) solutions. Specifically, the candidate will support and drive the integration of Information Security in the ET programs, to ensure that patient safety and information...


  • Hyderabad, Telangana, India DataVisor Full time

    DataVisor is the world's leading AI-powered Fraud and Risk Platform that delivers the best overall detection coverage in the industry. With an open SaaS platform that supports easy consolidation and enrichment of any data, DataVisor's solution scales infinitely and enables organizations to act on fast-evolving fraud and money laundering activities in real...


  • Hyderabad, Telangana, India Bristol Myers Squibb Full time

    Working with Us Challenging. Meaningful. Life-changing. Those aren't words that are usually associated with a job. But working at Bristol Myers Squibb is anything but usual. Here, uniquely interesting work happens every day, in every department. From optimizing a production line to the latest breakthroughs in cell therapy, this is work that transforms the...


  • Hyderabad, Telangana, India HappyFox Full time

    We're looking for an experienced Security Engineer with at-least 5+ years of experience to join our Product Engineering teams to help keep our products secure.Responsibilities: Perform manual and automated application penetration tests and provide suggestions to harden our productsParticipate regularly in development and release process to identify and...


  • Hyderabad, Telangana, India Experian Full time

    Job Description Job Description  Senior Database Security Engineer  The mission of the EGSO Engineering and Architecture Database Activity Monitoring (DAM) team is to monitor Experian sensitive data, safeguarding against negative impacting cyber events that compromise the Confidentiality, Integrity, and Availability of that data.  The...


  • Hyderabad, Telangana, India Backbase Full time

    The Job in shortJoin the banking revolution As Senior Cloud Security Engineer , you are responsible for defining the processes and implementation of our highly secure and compliant Saa S platform.As a Senior Cloud Security Engineer you'll be expected to implement the foundation of a highly secure, robust platform and related processes to ensure our...


  • Hyderabad, Telangana, India Tide Full time

    Job DescriptionAbout TideAt Tide, we are building a finance platform designed to save small businesses time and money. We provide our members with business accounts and related banking services, but also a comprehensive set of connected administrative solutions from invoicing to accounting.Launched in 2017, Tide is now used by over 1 million small businesses...


  • Hyderabad, Telangana, India Redient Security Full time

    Job DescriptionSenior Java EngineerAbout RoleWe are looking for a highly motivated individual that can help us solve interesting and complex problems for our clients. You will be working closely with product and engineering teams based out of the USA, Europe, and India to build proof-of-concepts, validate strategic architecture decisions, and develop modern...

  • Product Security

    4 weeks ago


    Hyderabad, Telangana, India Progress Full time

    Job Summary We are Progress (Nasdaq: PRGS) - an experienced, trusted provider of products designed with customers in mind so they can develop the applications they need, deploy where and how they want, and manage it all safely and securely. We're proud to have a diverse, global team where we value the individual and enrich our culture by considering...


  • Hyderabad, Telangana, India Backbase Full time

    The Job in shortJoin the banking revolution As Senior Cloud Security Engineer, you are responsible for defining the processes and implementation of our highly secure and compliant SaaS platform.As a Senior Cloud Security Engineer you'll be expected to implement the foundation of a highly secure, robust platform and related processes to ensure our software...

  • Senior Engineer

    22 hours ago


    Hyderabad, Telangana, India Talent500 Full time

    About American Airlines: At American Airlines, we're dedicated to delivering exceptional customer experiences. Our IT infrastructure team plays a critical role in making this happen. As a Senior Engineer, you'll contribute to the development and implementation of cutting-edge technologies that shape the future of travel.Job DescriptionAs a Senior Engineer -...


  • Hyderabad, Telangana, India OSI Systems, Inc Full time

    Job Description Overview At Spacelabs Healthcare, we are on a mission to provide continuous innovation in healthcare technology for better clinical and economic outcomes. Our scalable solutions deliver critical patient data across local and remote systems, enable better-informed decisions, increase efficiencies, and create a safer environment for...


  • Hyderabad, Telangana, India Backbase Full time

    The Job in shortNo day at Backbase is the same, and even more so for our security engineers. We all know that security and banking need to go hand in hand and with hackers and tech evolving by the day, you'll need to stay on your toes and ahead of the game.Your core responsibility is to ensure the delivery of secure software. You are the go-to person for...


  • Hyderabad, Telangana, India Head Digital Works Full time

    About the RoleThe Head Digital Works is looking for a Senior Cloud Engineer - Security with 8-10 years of experience securing cloud infrastructure, particularly in AWS. The ideal candidate will have a deep understanding of AWS services, including VPC, ELB, IAM, KMS, EC2, S3, CloudTrail, and CloudFormation.


  • Hyderabad, Telangana, India Aqua Security Full time

    About Aqua SecurityAqua Security is a leading provider of cloud-native security solutions. Our mission is to empower organizations to confidently adopt the cloud and improve their overall cybersecurity posture.Job DescriptionWe are seeking an experienced DevSecOps Architect to join our Digital Success team. As a key member of this team, you will contribute...


  • Hyderabad, Telangana, India Model N Full time

    Model N Global Information Security team is seeking Senior Information Security Engineer . This role is responsible for the management and development of Model N's Information Security program to support business objectives. This role will act as a critical partner who will work with multiple different teams across organizations. The role will provide...


  • Hyderabad, Telangana, India Bristol-Myers Squibb Full time

    b Working with Us Challenging Meaningful Life-changing Those aren t words that are usually associated with a job But working at Bristol Myers Squibb is anything but usual Here uniquely interesting work happens every day in every department From optimizing a production line to the latest breakthroughs in cell therapy this is work that transforms the...


  • Hyderabad, Telangana, India WELLS FARGO BANK Full time

    About this role:Wells Fargo is seeking a Senior Information Security EngineerIn this role, you will:Lead or participate in computer security incident response activities for moderately complex eventsConduct technical investigation of security related incidents and post incident digital forensics to identify causes and recommend future mitigation...


  • Hyderabad, Telangana, India Oracle Full time

    SaaS Security Product Test Engineer SaaS Security Testing Services team is seeking a test engineer to join Oracle India Development Center under the Oracle SaaS Cloud Security (SCS) organization. You will have the opportunity to contribute and help deliver security services and features for SaaS Enterprise customers and influence the future of testing...