Product & Solution Security Expert (Psse) [osa]

2 weeks ago


Bengaluru, India Siemens Digital Industries Software Full time

Change the future with us

We’re looking for forward-thinking, ambitious game-changers like you to be part of our cybersecurity team. This role is based in Bengaluru, India. Together let’s build groundbreaking security solutions and infrastructures that protect our data and the digital assets of our customers, teams impacting entire industries, cities, and even countries. Help us seek & solve tomorrow’s challenges today

About the job

The Product & Solution Security Expert (PSSE) for Secure Implementation provides technical consultation to OT product development teams to enable implementation of the required product & solution security. The PSSE needs to have experience in the following areas: development/testing on the Linux and Windows environments. The PSSE will function as an expert consultant as part of the PSS CoE, supporting multiple project teams.

**Responsibilities**:
Support project development teams to incorporate appropriate security practices across the development lifecycle (from product / solution concept to release).
- Risk Management & Compliance - Review documents produced during the development and engineering process (e.g., threat and risk analysis results, requirements specs, arch & design specs, test specs, user documentation) regarding PSS.
- Threat & Risk Analysis -Identify security weaknesses and vulnerabilities in the product, solution, or service offering, analyze the threats that might exploit these weaknesses or vulnerabilities, and evaluate the resulting risks. Organize & facilitate threat & risk analysis workshops in accordance with organizational processes (including periodic triggering of workshops based on changes to the product and/or changes to the attack surface).
- Security Requirements - Specify and maintain security requirements for the project. Support for meeting international and regional security standards (e.g., ISA/IEC 62443, GB 40050-2021) and regional regulations (e.g., Chinese Cybersecurity Law).
- Secure Suppliers & Components - Evaluate third-party suppliers & components regarding PSS and providing clearance of implementation and documentation of security critical components (e.g., cryptographic functions, hidden functions, firewall settings).
- Secure Development - Perform code analysis to identify security vulnerabilities and check compliance with secure coding guidelines.
- Security Testing - Perform verification of implementation regarding security requirements (e.g., as part of system test, factory, or site acceptance test). This includes recommendation and creation of security testing tools. Support validation (e.g., friendly hacking, penetration testing) to ensure that implementation fulfills security expectations of customers (e.g., to identify security vulnerabilities, and to evaluate the effectiveness of remediation measures). This includes recommendation and creation of security testing tools.
- Vulnerability Management - Support project teams to analyze vulnerabilities for their risk, prioritize and suitably mitigate risks to the products
- Incident Management - Support Product CERT incident handling teams (no direct responsibility)

Required Skills and Experience
- BE/BTech/MTech/MCA in Electronics/Instrumentation/Computer Science.
- Overall experience of at least 10 years in Information technology/Software development.
- At least 5 years’ experience in defining security controls & measures for IACS/SCADA.
- Active IT security certifications (CISSP, CSSLP or equivalent).
- Up-to-date knowledge on the threat landscape, including capabilities of attackers, available attacker tools, and typical security weaknesses & vulnerabilities.
- Excellent understanding (conceptual and implementation) of Asset Management incl., Passive & Active Asset Detection and Asset Vulnerability Association.
- Excellent understanding (conceptual and implementation) of Anomaly Detection (Host & Network) and configuration/implementation/operation of SIEM solutions.
- Experience in programming (C, C++, Java, JavaScript) in Linux & Windows and scripting (e.g., bash scripts) and ready to learn new technologies (e.g., Go).
- Experience on securing containers (esp. Debian based distributions).
- Knowledge of benchmarks (e.g., CIS-Security benchmarks and Microsoft security baselines).
- Experience in remote access, malware prevention system, Snort IDS/IPS, Nessus.
- Knowledge of PKI and certificate-based authentication
- Knowledge of IIOT and digitalization solutions
- Excellent communication and influencing skills

What else do I need to know?

**Job Family**: Cybersecurity

**Req ID**: 339698



  • Bengaluru, India Siemens Full time

    **Role**:Product & Solution Security Expert (PSSE)**: The world never stands still. And new challenges arise every day. With a passion for questioning things, for supplying ideas, and intelligently driving things forward we are helping society move towards a more intelligent future. Be it with technologies that reduce carbon emissions in cities or...


  • Bengaluru, India Siemens Full time

    **Role**:Product and Solution Security Expert** Siemens founded the new business unit Siemens Advanta (formerly known as Siemens IoT Services) on April 1, 2019 with its headquarter in Munich, Germany. It has been crafted to unlock the digital future of its clients by offering end-to-end support on their outstanding digitalization journey. Siemens Advanta is...


  • Bengaluru, India Siemens Full time

    **Role: Product and Solution Security Expert**: Siemens founded the new business unit Siemens Advanta (formerly known as Siemens IoT Services) on April 1, 2019 with its headquarter in Munich, Germany. It has been crafted to unlock the digital future of its clients by offering end-to-end support on their outstanding digitalization journey. Siemens Advanta is...

  • Solutions Architect

    23 hours ago


    Bengaluru, India Andromeda Security Full time

    Product management | Pre-sales | Azure Security ExpertThis is a full-time role for a product manager / pre-sales solution architect with experience and expertise in Microsoft Entra ID (Azure AD).What you will doEvangelize the product and engage customers, including product demos and installationsEngage in investigation and inbound product management for...


  • Bengaluru, India Ribbon Communications Operating Company Full time

    About UsRibbon Communications (Nasdaq: RBBN) delivers communications software, IP and optical networking solutions to service providers, enterprises and critical infrastructure sectors globally. We engage deeply with our customers, helping them modernize their networks for improved competitive positioning and business outcomes in today's smart, always-on and...


  • Bengaluru, India Ribbon Communications Operating Company Full time

    About UsRibbon Communications (Nasdaq: RBBN) delivers communications software, IP and optical networking solutions to service providers, enterprises and critical infrastructure sectors globally. We engage deeply with our customers, helping them modernize their networks for improved competitive positioning and business outcomes in today's smart, always-on and...

  • Cyber Security

    2 weeks ago


    Bengaluru, India Necurity Solution Full time

    Necurity Solution is a leading company in the Computer & Network Security industry, specializing in providing comprehensive security solutions to businesses worldwide. We are currently seeking a highly skilled and motivated individual to join our team as a Cyber Security professional. As a Cyber Security expert, you will play a crucial role in protecting our...

  • AWS Security Expert

    2 weeks ago


    Bengaluru, India Tavant Full time

    With 24+ years of experience building innovative digital products and solutions, Tavant provides impactful results to its customers. It has been the frontrunner in driving digital innovation and tech-enabled transformation across a wide range of industries such as Fintech, Manufacturing, Agtech, Media & Entertainment, and Retail in North America, Europe, and...

  • Api Security Expert

    4 weeks ago


    Bengaluru, India Bosch Group Full time

    Company Description Bosch Global Software Technologies Private Limited (BGSW), is a 100% owned subsidiary of Robert Bosch GmbH, one of the world’s leading global supplier of technology and services, offering end to end engineering, IT and Business solutions. With over 18000 associates, BGSW is the largest software development center of Bosch outside...

  • Cyber Security

    3 weeks ago


    Bengaluru, India Necurity Solution Full time

    Necurity Solution is a leading company in the Computer & Network Security industry, specializing in providing comprehensive security solutions to businesses worldwide. We are currently seeking a highly skilled and motivated individual to join our team as a Cyber Security professional. As a Cyber Security expert, you will play a crucial role in protecting our...

  • AWS Security Expert

    4 weeks ago


    Bengaluru, India Tavant Full time

    With 24+ years of experience building innovative digital products and solutions, Tavant provides impactful results to its customers. It has been the frontrunner in driving digital innovation and tech-enabled transformation across a wide range of industries such as Fintech, Manufacturing, Agtech, Media & Entertainment, and Retail in North America, Europe, and...

  • AWS Security Expert

    1 month ago


    Bengaluru, India Tavant Full time

    With 24+ years of experience building innovative digital products and solutions, Tavant provides impactful results to its customers. It has been the frontrunner in driving digital innovation and tech-enabled transformation across a wide range of industries such as Fintech, Manufacturing, Agtech, Media & Entertainment, and Retail in North America, Europe, and...

  • AWS Security Expert

    1 month ago


    Bengaluru, India Tavant Full time

    With 24+ years of experience building innovative digital products and solutions, Tavant provides impactful results to its customers. It has been the frontrunner in driving digital innovation and tech-enabled transformation across a wide range of industries such as Fintech, Manufacturing, Agtech, Media & Entertainment, and Retail in North America, Europe, and...


  • Bengaluru, India Black Box Full time

    Cybalt (a Black Box company) provides comprehensive, innovative, and full-lifecycle cybersecurity services such as Consulting, Professional Services, and 24/7 Managed Security Services. We believe ‘one size does NOT fit all’, so we provide tailored solutions to address clients’ specific needs. With multiple Security Operation Centers (SOC) and a global...


  • Bengaluru, India Black Box Full time

    Cybalt (a Black Box company) provides comprehensive, innovative, and full-lifecycle cybersecurity services such as Consulting, Professional Services, and 24/7 Managed Security Services. We believe ‘one size does NOT fit all’, so we provide tailored solutions to address clients’ specific needs. With multiple Security Operation Centers (SOC) and a global...


  • Bengaluru, India Infoblox Full time

    DescriptionIt’s an exciting time to be at Infoblox. Named a Top 25 Cyber Security Company by The Software Report and one of Inc. magazine’s Best Workplaces for 2020, Infoblox is the leader in cloud-first networking and security services. Our solutions empower organizations to take full advantage of the cloud to deliver network experiences that are...


  • Bengaluru, India Freelancer Recruiter Full time

    Primary Skills : agile,c,java,SCA/SAST,OSA,jenkins,mobile application security,SSDLC automationSecondary Skills : Python, waterfall- Understanding of information security key concepts- Ability to analyze security issues (both white-box and black-box), determine their cause and impact on the business and identify the corrective action needed to eliminate...


  • Bengaluru, India Infoblox Full time

    Description It’s an exciting time to be at Infoblox. Named a Top 25 Cyber Security Company by The Software Report and one of Inc. magazine’s Best Workplaces for 2020, Infoblox is the leader in cloud-first networking and security services. Our solutions empower organizations to take full advantage of the cloud to deliver network experiences that are...


  • Bengaluru, India Black Box Full time

    Cybalt (a Black Box company) provides comprehensive, innovative, and full-lifecycle cybersecurity services such as Consulting, Professional Services, and 24/7 Managed Security Services. We believe ‘one size does NOT fit all’, so we provide tailored solutions to address clients’ specific needs. With multiple Security Operation Centers (SOC) and a global...


  • Bengaluru, India Black Box Full time

    Cybalt (a Black Box company) provides comprehensive, innovative, and full-lifecycle cybersecurity services such as Consulting, Professional Services, and 24/7 Managed Security Services. We believe ‘one size does NOT fit all’, so we provide tailored solutions to address clients’ specific needs. With multiple Security Operation Centers (SOC) and a global...