High Salary Product Security Analyst

3 days ago


Bengaluru, Karnataka, India GE HealthCare Full time
Job Description

Job Description Summary

As a Product Security Analyst, you will be collaborating with development teams to complete security testing and tool development for our GEHC products. You will be responsible for Performing VAPT for thick and thin clients, webservices, embedded devices and cloud. Conducting Compliance/Benchmark assessments using DISA Stigs/CIS Benchmarks .Review, Test and Suggest best practices for Cryptography, PKI (web and non-web perspective). Conducting Source code review and discuss with development teams in mitigating the issues and eliminating false positives.

GE Healthcare is a leading global medical technology and digital solutions innovator. Our mission is to improve lives in the moments that matter. Unlock your ambition, turn ideas into world-changing realities, and join an organization where every voice makes a difference, and every difference builds a healthier world.

Job Description

Roles and Responsibilities

You are a skilled Analyst who enjoys security work and is an expert in systems security, product / OT security and application security.

In This Role, You Will

- Work with product managers, independent researchers, and in-house researchers to identify, rate, report and manage product vulnerabilities and incidents.
- Be responsible for providing technical leadership and defining, developing, and evolving security within software in a fast-paced and agile development environment using the latest secure software development technologies and infrastructure.
- Work with Cyber Security Leaders and SMEs to understand product requirements
- Translate security requirements / vision into a prioritized list of user stories, completing work according to required timelines and quality standards
- Assist security champions in completing Threat Modeling and Architecture Risk Analysis on product features
- Perform Security Code Reviews, Vulnerability Analysis and research on application code
- Coach and mentor developers to implement cryptography solutions securely (PKI, Code Signing, Stored Secrets, et cetera)
- Engage subject matter experts in successful transfer of complex domain knowledge
- Apply principles of Secure SDLC and methodologies like Lean/Agile/XP, CI, Software and Product Security
- Provide guidance and advice on writing secure code that meets standards and delivers desired functionality, using the technology selected for the project
- Understand application security methodologies and frameworks
- Leverage GE Digital&aposs tailored Secure SDL practice into specific engineering engagements
- Research new application security technologies and implement them to improve application security.
- Maintaining a backlog of security-related tools that will improve the maintainability and security of our code and the pace of development
- Promote best practices based on OWASP, SANS Top 25, and the GE Digital SDL.
- Write fuzz scenarios to see the break network protocol suites such as TCP/IP, IPv6, UDP, TLS, DTLS
- Ability to automate attack scenarios to avoid repetitive work.
- Good to have experience in Bluetooth/Wifi or any radio based attacks.
- Good to have experience in Rest API security testing and recommending best practices while opting for OAuth or OpenId connect
- Having experience working on IoT platform will be beneficial.

Required Skills

- Professional expertise with Kali Linux, Metasploit, Meterpreter.
- Hands-on experience in Windows/Linux and network security.
- Execute Scans using tools such as Nessus, Burp, Fortify/Coverity, Splunk etc.

Education Qualification

Bachelor&aposs Degree in Computer Science or STEM Majors (Science, Technology, Engineering and Math) with a minimum of 3+ years of experience in systems security, product / OT security and application security.

Desired Characteristics

- Certifications OSCP, CCSP.
- Languages C/C++/Java/Python/Ruby
- Proven experience in breaking the vulnerable boxes.
- Adaptable to learn new skills or technologies as per business needs.
- Detailed working knowledge of two modern programming languages, such as java, python, or ruby
- Good written and oral communication skills and successful security consulting background.
- At least 2 years of security consulting involvement with development team(s) that delivered software-based services
- Experience in developing secure applications
- A high energy and a result-oriented attitude/approach, with an understanding of release timelines and the need to enable development teams, not slow them down
- Experience with Security Development Lifecycle processes such as Threat Modeling desired
- Contribute to and lead discussions and communications within the team and outside, including customers and other business units
- Excellent knowledge of Object Oriented Analysis and Design, Software Design Patterns and coding principles
- Hands-on Experience with developing cloud-deployed applications that utilize oath 2
- Hands-on experience with developing RESTful web services
- Mobile Architecture experience, designing, developing, and integrating solutions.
- Experience with penetration testing tools, ability to replicate security defects uncovered by groups such as GE&aposs red team
- Good understanding of security tools and technologies to facilitate secure development

Inclusion and Diversity

GE Healthcare is an Equal Opportunity Employer where inclusion matters. Employment decisions are made without regard to race, color, religion, national or ethnic origin, sex, sexual orientation, gender identity or expression, age, disability, protected veteran status or other characteristics protected by law.

We expect all employees to live and breathe our behaviors: to act with humility and build trust; lead with transparency; deliver with focus, and drive ownership always with unyielding integrity.

Our total rewards are designed to unlock your ambition by giving you the boost and flexibility you need to turn your ideas into world-changing realities. Our salary and benefits are everything youd expect from an organization with global strength and scale, and youll be surrounded by career opportunities in a culture that fosters care, collaboration and support.

#Hybrid

Additional Information

Relocation Assistance Provided: Yes

  • Bengaluru, Karnataka, India Elytra Security Private limited Full time

    Job Description - Senior Sales ExecutiveLocation: Bangalore, India (Hybrid)Employment Type: Full-timeDepartment: Sales & Business DevelopmentReports To: Director - Sales & PartnershipsAbout Elytra SecurityElytra Security is a Bangalore-based cybersecurity firm building next-generation security and compliance solutions for enterprises, BFSI, healthcare,...


  • Bengaluru, Karnataka, India beBeeSecurity Full time ₹ 1,50,00,000 - ₹ 2,50,00,000

    Product Security SpecialistWe are seeking a skilled Product Security Specialist to join our team.About the RoleThis is a high-level security position that involves collaborating with development teams to ensure the security of our products. You will be responsible for identifying, analyzing, and mitigating security vulnerabilities in our software...


  • Bengaluru, Karnataka, India Infosys Limited Full time

    Job DescriptionKey Responsibilities:- As a Product Analyst your role is pivotal to delivering feature user stories within a scrum team and continuously building a backlog for the scrum team- Work with the Product Manager to map out the user stories for a capability feature become the SME of the capability and develop products to meet the needs of customers...


  • Bengaluru, Karnataka, India Ather Energy Full time

    Job DescriptionWhat youll do at Ather:- Our business journey captures a wealth of information at different touchpoints with the vehicle and customer during production, sales, marketing and vehicle ownership.- On the customer front, not only is there data captured through online touchpoints like the website, email marketing, digital marketing, app...


  • Bengaluru, Karnataka, India Wipro Full time

    Job Title: Business Analyst (IAM)Generic Job Role: Business Analyst role within Identity and Access Management (IAM) departmentQUALIFICATION: Business and Information Technology/Computer Science/Master DegreeExperience: 5 to 8 years of experienceNature of Experience: Customer Support/Technical Support/Access Admin/BAJob Purpose- We are seeking a skilled...


  • Bengaluru, Karnataka, India Cloudflare Full time

    About Us At Cloudflare we are on a mission to help build a better Internet Today the company runs one of the world s largest networks that powers millions of websites and other Internet properties for customers ranging from individual bloggers to SMBs to Fortune 500 companies Cloudflare protects and accelerates any Internet application online without...


  • Bengaluru, Karnataka, India MUFG Full time

    About MUFG Global Service MGS MUFG Bank Ltd is Japan s premier bank with a global network spanning in more than 40 markets Outside of Japan the bank offers an extensive scope of commercial and investment banking products and services to businesses governments and individuals worldwide MUFG Bank s parent Mitsubishi UFJ Financial Group Inc MUFG ...


  • Bengaluru, Karnataka, India CIEL HR Full time

    About Company - It is a global networking company based in the USA that produces networking hardware for consumers businesses and service providers The company operates in three business segments retail commercial and as a service provider Job Role - Principal Product Security Engineer Embedded Mobile App Web ServiceJob Location - Bangalore Vasanth...


  • Bengaluru, Karnataka, India Information & Technology Management Full time

    Job DescriptionReference ID R185716 Updated 08/06/2025Downstream Supply ChainIndiaBengaluruN/ALabelling space in Shell is a dynamic field, where you can support Shell in introducing new products and maintaining existing portfolio. You will protect Shells license to operate by providing compliant labelling for Americas.Job DescriptionAs Label Analyst, you...


  • Bengaluru, Karnataka, India Everbridge Full time US$ 60,000 - US$ 1,20,000 per year

    Everbridge is seeking an energetic, multi-tasking, and process focused Security Analyst to join our team in India and support our global sales team. The Sales Security Analyst provides a wide range of security, privacy, and operational support to the Everbridge sales team. They will work on Third Party Risk Management (TPRM) questionnaires and inquiries from...