Privacy & Security Representative

1 week ago


Bengaluru, India GE Healthcare Full time

**Job Description Summary**: As part of the Imaging System Software platform team at GE Healthcare, PSR-Privacy & Security Representative is the cybersecurity focal point for secure product development and maintenance of released product. The PSR is an experienced member of the product engineering team with influence to drive product privacy and cybersecurity features and enhancements. The PSR must have deep product knowledge to ensure the clinical functionality, expected operating environment, and interoperability to accurately determine a product’s privacy and security risks.

GE Healthcare is a leading global medical technology and digital solutions innovator. Our mission is to improve lives in the moments that matter. Unlock your ambition, turn ideas into world-changing realities, and join an organization where every voice makes a difference, and every difference builds a healthier world.

**Roles and Responsibilities**

In this role, you will:

- Provide privacy and security technical expertise in support of the product team throughout product development, design change, and life-cycle management.
- Work with the Product Security Leader (PSL) to support the product team with process expertise for the GEHC-GE Healthcare Product Cybersecurity Standard and life-cycle management.
- Product cybersecurity development responsibilities:

- Assess the privacy and cybersecurity state of the product and define product roadmap features/enhancements with stakeholder approval.
- Responsible for security architecture and coordination of product development for cybersecurity features and enhancements.
- Assess product components and SBoM integrated into the product.
- Perform defect management for cybersecurity issues.
- Identify operational responsibilities and adherence to cloud standards for cloud
- based products.
- Responsible for Product and Security Manual and MDS2 documentation.
- In coordination with the PSL, own and deliver GEHC Product Cybersecurity Standard artifacts, which includes:

- Design input activities to identify, evaluate, roadmap, and drive cybersecurity and privacy features and enhancements within product development programs.
- Create Design Engineering Privacy and Security (DEPS) artifacts for privacy and security risk assessments to engage in domain-specific product threat modeling, attack surface analysis, risk management and reduction.
- Coordinates with the PSL to support the product team in scheduling and performing vulnerability scans and cybersecurity assessments.
- Lead product Security Technical Design Reviews
- Along with the product LSD-Lead System Designer, responsible for the GEHC Product Cybersecurity Standard compliance and other pertinent standards and process.
- Stay current on healthcare privacy trends and regulatory environment (i.e. FDA, HIPAA, GDPR, etc ) to effectively communicate privacy awareness with the product team.
- Works with the GEHC Product Security team and QARA-Quality Assurance & Regulatory Assurance on released product life-cycle, including:

- Participate in post-market product vulnerability monitoring.
- Participate as an Subject Matter Expert to determine product vulnerability impact, investigation, and risk assessment.
- Responsible for product vulnerability mitigation and design change.
- Responsible for GEHC vulnerability tool update to ensure accurate customer communication.
- Address customer and Sales RFP privacy and security feedback/questions.
- Provide technical expertise on customer concerns, complaints, and CSO escalations.
- Create/Maintain responsible product records within GEHC product cybersecurity tools.

**Education Qualification**:

- Bachelor's Degree in Computer Science or “STEM” Majors (Science, Technology, Engineering and Maths)

**Required Characteristics**:

- A minimum of 7 + years of professional experience in software development.
- Sound understanding of security technologies/techniques like Cryptography, Algorithms, Public key Infrastructure (PKI) Certificate Authority (CA), Hardware/embedded authentication, OAuth, 2-factor authentication, white-box code analysis.
- Experience with Security Development Lifecycle processes such as Threat Modeling.
- Experience with a range of security tools: Nessus, Kali, Microsoft Threat Modeling Tool, etc.
- Experience with OWASP, CVSS, FIPS 140-2 and 140-3, and DoD RMF.

**Good To Have Skills**:

- Certification in cybersecurity.
- Experience in Agile development practices: Test Driven Development (TDD), Behavior Driven Development (BDD) and Scrum.
- Experience in MicroServices using RESTful frameworks.
- Experience in Healthcare domain.

**Inclusion and Diversity**

GE Healthcare is an Equal Opportunity Employer where inclusion matters. Employment decisions are made without regard to race, color, religion, national or ethnic origin, sex, sexual orientation, gender identity or expression, age, disability, protected veteran status or other characteristics protected by law.

We expect a



  • Bengaluru, India GE Healthcare Full time

    **Job Description Summary**: As part of the Imaging System Software platform team at GE Healthcare, PSR -Privacy & Security Representative is the cybersecurity focal point for secure product development and maintenance of released product. The PSR is an experienced member of the product engineering team with influence to drive product privacy and...

  • Privacy Counsel

    2 weeks ago


    Bengaluru, India Switchover Full time

    Key Responsibilities As Privacy Advocate, youll have a broad range of responsibilities providing legal research and guidance on initiatives impacting international privacy laws and related data protection and security matters. You will partner cross-functionally with our legal, product, engineering, and other teams to advise on privacy law matters and...

  • Privacy Counsel

    7 days ago


    Bengaluru, Karnataka, India Switchover Full time ₹ 20,00,000 - ₹ 25,00,000 per year

    Key ResponsibilitiesAs Privacy Advocate, youll have a broad range of responsibilities providing legal research and guidance on initiatives impacting international privacy laws and related data protection and security matters. You will partner cross-functionally with our legal, product, engineering, and other teams to advise on privacy law matters and related...


  • Bengaluru, Karnataka, India Autodesk Full time

    Job Requisition ID # - 24WD75768 Position Overview APAC data protection compliance has become an increasingly important topic for global companies, as new and amended legal requirements continue to evolve in the region. The APAC Privacy Counsel will develop strategies and initiatives to engage with key stakeholders and raise awareness of data privacy...

  • Privacy Counsel

    2 weeks ago


    Bengaluru, India Privaini Software Full time

    Key Responsibilities As Privacy Advocate, you'll have a broad range of responsibilities providing legal research and guidance on initiatives impacting international privacy laws and related data protection and security matters. You will partner cross-functionally with our legal, product, engineering, and other teams to advise on privacy law matters and...

  • Privacy Counsel

    7 days ago


    Bengaluru, Karnataka, India Privaini Software Full time ₹ 20,00,000 - ₹ 25,00,000 per year

    Key ResponsibilitiesAs Privacy Advocate, you'll have a broad range of responsibilities providing legal research and guidance on initiatives impacting international privacy laws and related data protection and security matters. You will partner cross-functionally with our legal, product, engineering, and other teams to advise on privacy law matters and...

  • Compliance Strategist

    2 weeks ago


    Bengaluru, Karnataka, India DevRev Full time

    **DevRev** DevRev’s AgentOS, purpose-built for SaaS companies, comprises three modern CRM apps for support, product, and growth teams. It connects end users, sellers, support, product people, and developers, reducing 9 business apps and converging 6 teams onto a common platform. Unlike horizontal CRMs, DevRev takes a blank canvas approach to...

  • Data Privacy

    1 day ago


    Bengaluru, Karnataka, India Wipro Limited Full time

    Bengaluru, India - GSH - 3122061 **Job Description**: - The purpose of the role is to assist organisation in any one or more aspects of data privacy and data protection compliance from the below Roles & Responsibilities: - Drives benchmarking activities and ensures all operations, policies, procedures are up to date to comply with accountability,...


  • Bengaluru, India Infosys Full time

    Educational Requirements Bachelor of Engineering Service Line Data & Analytics Unit Responsibilities Work independently with business stakeholders to understand and evaluate data privacy & security requirements of our clients- Work closely with business and data stakeholders to understand and document business requirements, create a plan for delivering the...


  • Bengaluru, Karnataka, India Infosys Full time ₹ 6,00,000 - ₹ 18,00,000 per year

    Educational RequirementsBachelor of EngineeringService LineData & Analytics UnitResponsibilitiesWork independently with business stakeholders to understand and evaluate data privacy & security requirements of our clients- Work closely with business and data stakeholders to understand and document business requirements, create a plan for delivering the...