Privacy & Security Representative

5 days ago


Bengaluru, India GE Healthcare Full time

**Job Description Summary**: As part of the Imaging System Software platform team at GE Healthcare, PSR-Privacy & Security Representative is the cybersecurity focal point for secure product development and maintenance of released product. The PSR is an experienced member of the product engineering team with influence to drive product privacy and cybersecurity features and enhancements. The PSR must have deep product knowledge to ensure the clinical functionality, expected operating environment, and interoperability to accurately determine a product’s privacy and security risks.

GE Healthcare is a leading global medical technology and digital solutions innovator. Our mission is to improve lives in the moments that matter. Unlock your ambition, turn ideas into world-changing realities, and join an organization where every voice makes a difference, and every difference builds a healthier world.

**Roles and Responsibilities**

In this role, you will:

- Provide privacy and security technical expertise in support of the product team throughout product development, design change, and life-cycle management.
- Work with the Product Security Leader (PSL) to support the product team with process expertise for the GEHC-GE Healthcare Product Cybersecurity Standard and life-cycle management.
- Product cybersecurity development responsibilities:

- Assess the privacy and cybersecurity state of the product and define product roadmap features/enhancements with stakeholder approval.
- Responsible for security architecture and coordination of product development for cybersecurity features and enhancements.
- Assess product components and SBoM integrated into the product.
- Perform defect management for cybersecurity issues.
- Identify operational responsibilities and adherence to cloud standards for cloud
- based products.
- Responsible for Product and Security Manual and MDS2 documentation.
- In coordination with the PSL, own and deliver GEHC Product Cybersecurity Standard artifacts, which includes:

- Design input activities to identify, evaluate, roadmap, and drive cybersecurity and privacy features and enhancements within product development programs.
- Create Design Engineering Privacy and Security (DEPS) artifacts for privacy and security risk assessments to engage in domain-specific product threat modeling, attack surface analysis, risk management and reduction.
- Coordinates with the PSL to support the product team in scheduling and performing vulnerability scans and cybersecurity assessments.
- Lead product Security Technical Design Reviews
- Along with the product LSD-Lead System Designer, responsible for the GEHC Product Cybersecurity Standard compliance and other pertinent standards and process.
- Stay current on healthcare privacy trends and regulatory environment (i.e. FDA, HIPAA, GDPR, etc ) to effectively communicate privacy awareness with the product team.
- Works with the GEHC Product Security team and QARA-Quality Assurance & Regulatory Assurance on released product life-cycle, including:

- Participate in post-market product vulnerability monitoring.
- Participate as an Subject Matter Expert to determine product vulnerability impact, investigation, and risk assessment.
- Responsible for product vulnerability mitigation and design change.
- Responsible for GEHC vulnerability tool update to ensure accurate customer communication.
- Address customer and Sales RFP privacy and security feedback/questions.
- Provide technical expertise on customer concerns, complaints, and CSO escalations.
- Create/Maintain responsible product records within GEHC product cybersecurity tools.

**Education Qualification**:

- Bachelor's Degree in Computer Science or “STEM” Majors (Science, Technology, Engineering and Maths)

**Required Characteristics**:

- A minimum of 7 + years of professional experience in software development.
- Sound understanding of security technologies/techniques like Cryptography, Algorithms, Public key Infrastructure (PKI) Certificate Authority (CA), Hardware/embedded authentication, OAuth, 2-factor authentication, white-box code analysis.
- Experience with Security Development Lifecycle processes such as Threat Modeling.
- Experience with a range of security tools: Nessus, Kali, Microsoft Threat Modeling Tool, etc.
- Experience with OWASP, CVSS, FIPS 140-2 and 140-3, and DoD RMF.

**Good To Have Skills**:

- Certification in cybersecurity.
- Experience in Agile development practices: Test Driven Development (TDD), Behavior Driven Development (BDD) and Scrum.
- Experience in MicroServices using RESTful frameworks.
- Experience in Healthcare domain.

**Inclusion and Diversity**

GE Healthcare is an Equal Opportunity Employer where inclusion matters. Employment decisions are made without regard to race, color, religion, national or ethnic origin, sex, sexual orientation, gender identity or expression, age, disability, protected veteran status or other characteristics protected by law.

We expect a



  • Bengaluru, India Black & White Business Solutions Full time

    **Job Information**: Industry **IT Services** *** Province **Karnataka** *** City **Bangalore North** *** Postal Code **560001** *** Country **India** We have opening for DATA PRIVACY SECURITY with one of our client, pls find the details below. - Must have skills : CISSP Certified, Data Privacy and Security, Experience in privacy by design, Risk...

  • Privacy Counsel

    1 week ago


    Bengaluru, Karnataka, India Switchover Full time ₹ 20,00,000 - ₹ 25,00,000 per year

    Key ResponsibilitiesAs Privacy Advocate, youll have a broad range of responsibilities providing legal research and guidance on initiatives impacting international privacy laws and related data protection and security matters. You will partner cross-functionally with our legal, product, engineering, and other teams to advise on privacy law matters and related...

  • Apac Privacy Counsel

    22 hours ago


    Bengaluru, Karnataka, India Autodesk Full time

    Job Requisition ID # - 24WD75768 Position Overview APAC data protection compliance has become an increasingly important topic for global companies, as new and amended legal requirements continue to evolve in the region. The APAC Privacy Counsel will develop strategies and initiatives to engage with key stakeholders and raise awareness of data privacy...

  • Privacy Research

    21 hours ago


    Bengaluru, Karnataka, India Tsaaro Consulting Full time ₹ 2,00,000 - ₹ 6,00,000 per year

    About Us:Tsaaro Consulting's prime focus is on Data Privacy and SecurityOur team of specialist Data Privacy Consultants, Information Security Consultants, and penetration testers help and advise our Clients to make running a secure business easier with high efficiencyEverything We do is tailored to the individual, and organizational requirements, aligned...


  • Bengaluru, Karnataka, India Infosys Full time ₹ 6,00,000 - ₹ 18,00,000 per year

    Educational RequirementsBachelor of EngineeringService LineData & Analytics UnitResponsibilitiesWork independently with business stakeholders to understand and evaluate data privacy & security requirements of our clients- Work closely with business and data stakeholders to understand and document business requirements, create a plan for delivering the...


  • Bengaluru, India NAZZTEC Full time

    Role OverviewWe are seeking a skilled and detail-oriented Data Privacy Specialist to join our client’s compliance and cybersecurity team in Riyadh, Saudi Arabia. This role is critical to ensuring that all personal data processing activities comply with the applicable data protection laws and standards, particularly those enforced by SAMA , NCA , and the...


  • Bengaluru, India NAZZTEC Full time

    Role OverviewWe are seeking a skilled and detail-oriented Data Privacy Specialist to join our client’s compliance and cybersecurity team in Riyadh, Saudi Arabia. This role is critical to ensuring that all personal data processing activities comply with the applicable data protection laws and standards, particularly those enforced by SAMA , NCA , and the...

  • Privacy Advisor

    7 days ago


    Bengaluru, Karnataka, India DeleteMe Full time

    About DeleteMe, The Online Privacy Company DeleteMe is the online privacy company that makes easy-to-use tools for consumers and businesses to control what personal information companies, third parties, and what other people see about them online. DeleteMe is a rapidly growing SaaS privacy business operating globally and remotely / WFH - we are the emerging...

  • Privacy Advisor

    1 week ago


    Bengaluru, Karnataka, India London Stock Exchange Group Full time

    We are seeking a privacy professional to join the LSEG Global Privacy Office, whose responsibility will be to lead a team of analysts to assist the Privacy Office in providing privacy advice, handle the privacy rights requests, identify and operationalize global regulatory changes and on various global and regional projects related to the implementation and...

  • Privacy Audit Analyst

    2 weeks ago


    Bengaluru, Karnataka, India Teamware Solutions ( A division of Quantum Leap Co Full time ₹ 12,00,000 - ₹ 36,00,000 per year

    Description : Job Summary : The Senior Associate Privacy Audit Analyst leads end-to-end privacy audit engagements, mentors junior staff, and drives complex assessments across global data privacy and U.S. health data regulations. This position emphasizes independent ownership of audit planning, execution, and stakeholder management, with control...