Product Security Engineer

4 weeks ago


india QuEST Global Services Pte. Ltd Full time

Quest Global is an organization at the forefront of innovation and one of the world’s fastest growing engineering services firms with deep domain knowledge and recognized expertise in the top OEMs across seven industries. We are a twenty-five-year-old company on a journey to becoming a centenary one, driven by aspiration, hunger and humility.

We are looking for humble geniuses, who believe that engineering has the potential to make the impossible, possible; innovators, who are not only inspired by technology and innovation, but also perpetually driven to design, develop, and test as a trusted partner for Fortune 500 customers.

As a team of remarkably diverse engineers, we recognize that what we are really engineering is a brighter future for us all. If you want to contribute to meaningful work and be part of an organization that truly believes when you win, we all win, and when you fail, we all learn, then we’re eager to hear from you.

The achievers and courageous challenge-crushers we seek, have the following characteristics and skills:
 

Job Responsibilities
In this role you will be responsible for designing, building, testing and implementing systems with the primary goal of security/patient safety across medical device product portfolio in various operating environments. Some of the focus areas for this position include: Prevention of breach of Intellectual Property (IP), Attack surface minimization, preventive security and privacy controls, incident/vulnerability management.
This role requires experience with security technologies and implementation experience for products with varying levels of capabilities and diverse user environments for both internal and external customers. A hands-on experience and interest in latest security standards, protocols, products and systems is mandatory for the success of this role.
Roles and Responsibilities:

Work directly with embedded software developers in building a security by design mindset by defining implementations and coding inline with the Application Security Program mandates Implement embedded secure code solutions, design patterns, and coding guidelines that meet security and privacy requirements defined in the security plans, risk assessments, policies, and procedures Support security project governance through scheduling activities, planning and prioritization Proactively drive security solutions implementation in-alignment with the development leads, security architects and product owner(s) Drive feature implementations in line with the architecture via designs, coding, reviews and tests. Perform Proof of Concept (POC) activities as necessary Review, Analyze and mitigate SAST, DAST, SCA and penetration test findings in collaboration with the developers for various electromechanical medical devices product lifecycles Review current software security control measures and implement security enhancements across multiple medical devices Participate in post-market product analysis to support vulnerability investigations as required as well as be engaged in continuous security monitoring Required Skills (Technical Competency) : Experienced security developer able to interpret and guide software development teams on secure coding practices and application security test report interpretation for various coding languages and operating environments Strong knowledge of secure software development lifecycle and practices including SAFe/ Agile methodologies for software development Understanding of security by design principles and architecture level security concepts Sound understanding and experience in implementing security technologies/techniques such as, Cryptographic Algorithms/Cipher Suites, Public key Infrastructure (PKI), Hardware/embedded authentication protocols, Secure Boot, and data-at-rest encryption methods Experience implementing OWASP Top10 application security guidelines in embedded systems Knowledge of embedded system architecture and security controls (, firewall and border router configurations, wireless communication architectures, messaging authentication protocols Experienced in generating, defining, and reviewing penetration test results through knowledge standard methodologies and tools including environmental configuration definition, security analysis, threat modeling, and system security audits Knowledge of current and emerging security threats and techniques for exploiting security vulnerabilities Exposure to international privacy requirements & cross-industry trends
Qualifications and Skills Bachelor's degree in Computer Science, Computer Engineering, a related field or equivalent demonstrated experience and knowledge Minimum 8+ years of experience in software development or related fields. Minimum 5 years technical experience working with product security design/development for embedded systems 3 years working with each of the following:Experience with C/C++, Python, Linux and/or security design within real-time operating systemsExperience analyzing, interpreting, and mitigating security findings from multiple sources including SAST, DAST, SCA and penetration testsEmbedded data at rest security implementations including Code Signing, Secure boot, and flash encryption implementationsEmbedded/IoT wired and wireless secure networking implementations within multiple layers of the OSI stackIoT/Embedded PKI solutions and implementation.

  • india TAC Security Full time

    Job Title: Senior Security Engineer - VAPT Location: Pune, India Company Description TAC Security is a global leader in vulnerability management that specializes in protecting Fortune 500 companies, leading enterprises, and governments worldwide. With its AI-based Vulnerability Management Platform ESOF (Enterprise Security in One Framework), TAC Security...


  • india precisely Full time

    Precisely is the leader in data integrity. We empower businesses to make more confident decisions based on trusted data through a unique combination of software, data enrichment products and strategic services. What does this mean to you? For starters, it means joining a company focused on delivering outstanding innovation and support that helps customers...


  • india AlphaSense Full time

    About AlphaSense:  AlphaSense is a market intelligence and search platform used by the world's leading companies and financial institutions. Since 2011, our AI-based technology has helped professionals make smarter business decisions by delivering insights from an extensive universe of public and private content—including equity research, company...


  • india ConnectWise Full time

    Principal Product Security Engineer Pune/Mumbai (Hybrid) 8+ years of experience is must Do you breathe security? We're looking for a leader to champion secure development across our entire product line. You'll design and implement best practices, conduct assessments, and collaborate with teams to build trust in ConnectWise applications. Key...

  • Product Manager

    1 month ago


    india Egnyte Full time

    Description Product Manager – Cloud Security EGNYTE YOUR CAREER. SPARK YOUR PASSION. Egnyte is a place where we spark opportunities for amazing people. We believe that every role has meaning, and every Egnyter should be respected. With 22,000+ customers worldwide and growing, you can make an impact by protecting their valuable data. When...


  • india Synergy America, Inc Full time

    Job Description Our client is looking for a Security Cloud Engineer for a 12+ months contract role in Lawrenceville, GA who will assist the Cybersecurity Team by supporting Security staff in their efforts to protect systems. This position will be responsible for developing and maturing Microsoft Defender products and various other Cloud based products. ...


  • india Karya Consultants Private Limited Full time

    Basic Qualifications: B.Tech. in Computer Science, Electrical, or Computer Engineering, or equivalent work experience as a software engineering or security practitioner. 5+ years of relevant engineering or security assessment experience, experience in application security. Possess a broad knowledge of attack vectors, exploits and mitigations that work at...


  • india Oportun, Inc Full time

    ABOUT OPORTUN Oportun (Nasdaq: OPRT) is a digital banking platform that puts its 1.9 million members' financial goals within reach. With intelligent borrowing, savings, budgeting, and spending capabilities, Oportun empowers members with the confidence to build a better financial future. Since inception, Oportun has provided more than $15.5...


  • india Insight Global Full time

    Position Overview: As an Application Security Engineer, you will drive the security of our entire product suite. You will have the opportunity to partner with multiple product teams to champion secure coding practices and secure-by-design development principles. RESPONSIBILITIES: Support application security reviews and threat modeling Perform application...


  • india Advanced Sterilization Products Full time

    Responsibilities : Working with internal stakeholders across numerous technical functions. Operate as a SME for product teams regarding secure development practices and technical matters. Coordinate shared product security assessment roadmap on an annual basis. Facilitate and manage third party product assurance engagements. Track and...


  • india Oracle Full time

    This is a technical engineering and DevOps role within Oracle SaaS Cloud Security (SCS). This position will be a part of the Life Cycle Management and Service Delivery Team. Focus includes engineering work to automate deployment of services and tools, engineering work to ensure observability and monitoring of these services and and performing information...


  • india Apollo Full time

    Your Role & Mission The  Senior Application Security Engineer will work with product and engineering to create a secure SDLC, design security features and implement tools, education and processes to reduce risk of security issues in the tech stack. Responsibilities Select or build tooling to help developers build secure code Provide...


  • india Deltek Full time

    09-Apr-2024 Security Quality Assurance Analyst India-Remote 9256BR Company Summary As the recognized global standard for project-based businesses, Deltek delivers software and information solutions to help organizations achieve their purpose. Our market leadership stems from the work of our diverse employees who are united by a passion...


  • india Ascendion Full time

    Job Summary: We are seeking a skilled Network Security Engineer to join our dynamic IT team. The ideal candidate will be responsible for designing, implementing, and managing robust security measures to protect our network infrastructure from cyber threats. This role involves monitoring network activity, identifying security risks, and responding to...

  • Infosec Engineer

    2 weeks ago


    india KloudPortal ™ - SaaS | Product Marketing Full time

    Job Description for Infosec Engineer (On-premises and Cloud): KloudPortal Technology Solutions Private limited offers a range of software solutions to clients worldwide. We take pride in creating solutions that are scalable, optimal and effective. Our team of 60+ engineers is diverse and welcoming. About the position: This job posting is for Infosec...

  • Security Engineer

    1 week ago


    india Simbian Full time

    Simbian is a mission driven company solving security with AI. We are seeking a world-class security engineer with intimate knowledge of various security tools (SIEM, SOAR, SOC automation, XDR operation) and looking to build an iconic security company. You are someone who is rejuvenated by working on new and challenging problems and bring your unique...

  • Security Engineer

    5 days ago


    india VE3 Full time

    Job Description Job Title: Security Engineer Location : UKPosition Type : Full-timeExperience Level : Mid-Senior (5+ years)Job Description : We are seeking an experienced Security Engineer with a strong background in penetration testing, vulnerability scanning, security analysis, identification of unencrypted sensitive data, and issue resolution. The ideal...


  • india QuEST Global Services Pte. Ltd Full time

    Quest Global is an organization at the forefront of innovation and one of the world’s fastest growing engineering services firms with deep domain knowledge and recognized expertise in the top OEMs across seven industries. We are a twenty-five-year-old company on a journey to becoming a centenary one, driven by aspiration, hunger and humility. We are...


  • india 3M Consultancy Full time

    Job Description This is a remote position. Job Title: Senior Security Engineer. Location: Washington, DC (Remote) Duration: Full-Time. Role Specific Duties:         Provide network IDS monitoring, cyber threat intelligence, security log analysis and forensics, and web application security scanning and analysis.         Protect users by...


  • india Novalink Solutions LLC Full time

    Job Description The Security Cloud Engineer will assist the Cybersecurity Team by supporting Gwinnett County Security staff in their efforts to protect county systems. This position will be responsible for developing and maturing Microsoft Defender products and various other Cloud based products.  Minimum Qualifications: ·        Previous experience...