
Principal Product Security Engineer
2 weeks ago
A Day in the Life
- Lead and perform product and device-oriented cybersecurity-related activities ranging from incident response to vulnerability assessments and mitigation implementation.
- Develop and perform product-level intrusion detection activities.
- Lead product risk assessments in conjunction with product R&D teams and develop and recommend specific security controls for product/system wide security needs.
- Participate in the creation and testing of product security-related requirements and processes.
- Manage security-related deliverables for regulatory bodies, ensuring compliance with key standards / guidance documents.
- Evaluate and test security risks on programs across the entire development lifecycle, including market-released products.
- Support emerging cybersecurity certification initiatives.
- Maintain and update security documentation.
- Create and maintain threat models using STRIDE.
Must Have: Minimum Requirements
- An undergraduate (bachelors) or graduate degree in computer science, computer engineering, electrical engineering, or similar discipline.
- CISSP or similar certification, or sufficient demonstrated experience
- Experience in embedded devices vulnerability assessment, especially medical devices and Threat Modelling and risk scoring
- Formal education in cybersecurity and information assurance.
- Minimum 12-year experience & 4 years of technical, cybersecurity-related experience,
- Experience in analyzing security posture and vulnerability assessment
- experience in penetration testing, fuzz testing of Web, enterprise cloud and Desktop solutions, (Black box, gray box and Whitebox testing)
- Experience in static code analysis for security vulnerability
- Software Product Development experience, Programming skills in one or more of the following: C, C++, Python, Java, .NET, Go, Ruby and/or Scala
- Understanding of national and international laws, regulations, and policies related to regulated medical device cybersecurity
- Demonstrated understanding of information security practices, risk management processes, cybersecurity principles, and incident response methodologies
Nice to Have:
- Experience as an analyst, engineer, developer, or architect with core cybersecurity responsibility and knowledge in two or more of the following areas:
- Experience in leading application architecture reviews and threat assessments
- Cloud systems architecture and security
- Enterprise and local network infrastructure security
- Experience in code reviews and/or penetration testing
- Large-scale application architecture and security
- Mobile device application architecture and security
- Risk assessments and cybersecurity regulatory requirements
- Experience in static and dynamic code analysis tools and methodologies
- Medical devices and systems security experience
- Security incident management experience
- Log event management and searching experience (Splunk, Sentinel, or similar)
- In-depth OS systems-level experience within one or more of the following: Linux, Windows, Android, iOS
- Demonstrated understanding of networking (ports/protocols), firewalls, load balancers and IPS
- Expertise in Agile and can work with at least one of the common frameworks
- Experience in Healthcare industry or other heavily regulated industry.
- Understanding of national and international laws, regulations, and policies related to regulated medical device cybersecurity
- Experience with container technologies such as Docker, Kubernetes, Mesos, or Open Container Initiative (OCI)
- Demonstrated ability to develop and grow productive, trusting, and open relationships with a wide variety of constituencies.
- Demonstrated leadership and teamwork skills
- Demonstrated ability to communicate complexity in a clear manner
- Demonstrated experience interfacing with customers and other external stakeholders regarding cybersecurity system design and behavior
- Demonstrated strong analytical, problem-solving skills
-
Principal Engineer
2 weeks ago
Hyderabad, India Zyoin Group Full timePosition: Principal EngineerLocation: HyderabadExperience: 10+ YearsAbout the role:The Principal Engineer assumes individual accountability for end-to-end delivery of complex, multi-team / squads’ projects. They serve as the technical stewards of significant components within the systems, infrastructure, and design decisions. Additionally, they take...
-
Principal Product Security Engineer
6 days ago
Hyderabad, Telangana, India Domnic Lewis Full time ₹ 12,00,000 - ₹ 36,00,000 per yearA Day in the LifeLead and perform product and device-oriented cybersecurity-related activities ranging from incident response to vulnerability assessments and mitigation implementation.Develop and perform product-level intrusion detection activities.Lead product risk assessments in conjunction with product R&D teams and develop and recommend specific...
-
Senior Consultant- Software Engineering
3 weeks ago
Hyderabad, Telangana, India Principal Financial Full timeResponsibilities About the Role We are in search of a Senior Consultant - Software Engineering to become part of our top-tier engineering team in Pune Hyderabad This presents a meaningful role to lead solution architecture and innovation for our cloud platform initiatives You will be instrumental in propelling our cloud transformation programs forward ...
-
Software Dev Principal Engineer – Security
3 weeks ago
Hyderabad, Telangana, India Quest Software Full timeJob DescriptionOverviewJob Title: Principal Engineer Security & Cloud Engineering (Product & SC)Location: HybridExperience: 10+ yearsEmployment Type: Full-timeWe are looking for a Principal Engineer to lead Security and Cloud Engineering efforts for our enterprise Java product with both On-Prem and SaaS deployments. This is a hands-on leadership role driving...
-
Software Dev Principal Engineer – Security
2 weeks ago
Hyderabad, India Quest Software Full timeJob Description Overview Job Title: Principal Engineer Security & Cloud Engineering (Product & SC) Location: Hybrid Experience: 10+ years Employment Type: Full-time We are looking for a Principal Engineer to lead Security and Cloud Engineering efforts for our enterprise Java product with both On-Prem and SaaS deployments. This is a hands-on leadership...
-
Principal Engineer
7 days ago
Hyderabad, India Zyoin Group Full timePosition: Principal EngineerLocation: HyderabadExperience: 10+ YearsAbout the role:The Principal Engineer assumes individual accountability for end-to-end delivery of complex, multi-team / squads’ projects. They serve as the technical stewards of significant components within the systems, infrastructure, and design decisions. Additionally, they take...
-
Principal Engineer
3 weeks ago
Hyderabad, Telangana, India Zyoin Group Full timeJob DescriptionPosition: Principal EngineerLocation: HyderabadExperience: 10+ YearsAbout the role:The Principal Engineer assumes individual accountability for end-to-end delivery of complex, multi-team / squads projects. They serve as the technical stewards of significant components within the systems, infrastructure, and design decisions. Additionally, they...
-
Principal Engineer
2 weeks ago
Hyderabad, India Zyoin Group Full timeJob Description Position: Principal Engineer Location: Hyderabad Experience: 10+ Years About the role: The Principal Engineer assumes individual accountability for end-to-end delivery of complex, multi-team / squads projects. They serve as the technical stewards of significant components within the systems, infrastructure, and design decisions....
-
Principal Engineer
3 weeks ago
Hyderabad, Telangana, India Zyoin Group Full timePosition: Principal EngineerLocation: HyderabadExperience: 10+ YearsAbout the role:The Principal Engineer assumes individual accountability for end-to-end delivery of complex, multi-team / squads' projects. They serve as the technical stewards of significant components within the systems, infrastructure, and design decisions. Additionally, they take charge...
-
Principal Product Security Engineer
7 days ago
Hyderabad, Telangana, India Spectral Consultants Full timeKey Responsibilities Lead and execute cybersecurity activities across product and device domains including incident response vulnerability assessment and mitigation Conduct product-level intrusion detection and develop threat models e g STRIDE Collaborate with R D teams on risk assessments and define product system-wide security controls ...