Product Security Representative

2 weeks ago


Bengaluru, India GE Healthcare Full time

GE Healthcare is a leading global medical technology and digital solutions innovator. Our mission is to improve lives in the moments that matter. Unlock your ambition, turn ideas into world-changing realities, and join an organization where every voice makes a difference, and every difference builds a healthier world.

The PSR is cybersecurity focal point for Edison for Enterprise team to drive secure development and maintenance of Edison Digital Health Platform (EDHP). The PSR is an experienced member of the product engineering team with influence to drive product privacy and cybersecurity features and enhancements. The PSR must have deep product knowledge to ensure the clinical functionality, expected operating environment, and interoperability to accurately determine a product’s privacy and security risks.

**Roles and Responsibilities**

**In this role, you will**
- Provide privacy and security technical expertise in support of the product team throughout product development, design change, and life-cycle management.
- Work with the Product Security Leader (PSL) to support the product team with process expertise for the GEHC Product Cybersecurity Standard and life-cycle management.
- Increase product security awareness within the development team
- Analyzing, tracking and following product related threat, vulnerabilities, security gaps and desired solution
- Maintain cyber security processes, monitoring systems/tools
- Support the development teams by security analyses and threat modelling
- Interact with worldwide engineering and product teams
- Assess the privacy and cybersecurity state of the product and define product roadmap features/enhancements with stakeholder approval
- Responsible for security architecture and coordination of product development for cybersecurity features and enhancements
- Assess product components and SBoM integrated into the product
- Perform defect management for cybersecurity issues
- Identify operational responsibilities and adherence to cloud standards for cloud
- based products
- Responsible for Product and Security Manual and MDS2 documentation
- In coordination with the PSL, own and deliver GEHC Product Cybersecurity Standard artifacts, which includes:

- Lead product Security Technical Design Reviews. Design input activities to identify, evaluate, roadmap, and drive cybersecurity and privacy features and enhancements within product development programs
- Create Design Engineering Privacy and Security (DEPS) artifacts for privacy and security risk assessments to engage in domain-specific product threat modeling, attack surface analysis, risk management and reduction
- Along with the product LSD, responsible for the GEHC Product Cybersecurity Standard compliance and other pertinent standards and process.
- Stay current on healthcare privacy trends and regulatory environment (i.e. FDA, HIPAA, GDPR, etc ) to effectively communicate privacy awareness with the product team.
- Works with the GEHC Product Security team and QARA on released product life-cycle, including:

- Participate in post-market product vulnerability monitoring
- Participate as an SME to determine product vulnerability impact, investigation, and risk assessment
- Responsible for product vulnerability mitigation and design change
- Responsible for GEHC vulnerability tool update to ensure accurate customer communication
- Address customer and Sales RFP privacy and security feedback/questions.
- Provide technical expertise on customer concerns, complaints, and CSO escalations.
- Create/Maintain responsible product records within GEHC product cybersecurity tools.
- Active involvement in DoD RMF submission process and maintenance.

**Quality Specific Goals**:

- Monitor a wide array of diverse information sources - ranging from open-source to classified materials - for potential threats to GE's personnel, infrastructure and operations
- An understanding of APT, Cyber Crime, and other associated actors
- Proven knowledge of typical adversary tactics, techniques, and procedures (TTPs)
- Background in collecting, analyzing, and interpreting data from various sources, detailing the results and preparing substantial analysis products
- Awareness of intelligence enrichment practices and threat hunting experience (PassiveDNS, Domain Registration pivoting, VirusTotal, etc.)
- Active participant in the Intelligence Community.
- Complete all required Quality and GEHC Product Cybersecurity Standard compliance training.
- Identify and report any quality, compliance, security, or privacy concerns and take immediate corrective action as required.
- Coordination with GEHC Product Security Team and product PSL.
- Understand healthcare industry cybersecurity trends and competitive landscape and the implications for your product.

**Qualifications**:

- Bachelor's Degree in a relevant field (e.g. Computer Engineering, Computer Science, Information Security) or in a STEM major (Science, Technology, Engineering, or Math).
- S



  • Bengaluru, Karnataka, India Menlo Security Full time

    Menlo Security's mission is enabling the world to connect, communicate and collaborate securely without compromise. COVID-19 has made our mission all the more real. We support customers across various enterprises including Fortune 500 companies, 9/10 of the largest global banks and the Department of Defense. Menlo is well-funded for growth and our investors...


  • Bengaluru, Karnataka, India GE HEALTHCARE Full time

    **Job Description Summary**: Product Security Architect will be responsible for providing technical security leadership to global development teams for GEHC Life Care Solutions Digital products. In this role, you will be part of LCS Digital group focusing on advanced technology developments for Visualization, Tele health, IOT Connectivity and Edge solutions...


  • Bengaluru, Karnataka, India GE HEALTHCARE Full time

    **Job Description Summary**: GE HealthCare is seeking a seasoned Senior Cyber Security Engineer capable of developing cutting-edge cyber security detection solutions. This role will also be a driving force behind the adoption of new detection technologies based on behavioral analytics and machine learning. This position is responsible for leading the...


  • Bengaluru, Karnataka, India Skyhigh Security Full time US$ 1,25,000 - US$ 1,75,000 per year

    Job Title:Senior Security EngineerAbout Skyhigh Security:Skyhigh Security is a dynamic, fast-paced, cloud company that is a leader in the security industry. Our mission is to protect the world's data, and because of this, we live and breathe security. We value learning at our core, underpinned by openness and transparency.Since 2011, organizations have...


  • Bengaluru, Karnataka, India beBeeSecurity Full time ₹ 25,00,000 - ₹ 31,25,000

    Secure Product SpecialistWe are seeking an experienced and skilled Secure Product Specialist to ensure the robustness and security of our products.


  • Bengaluru, Karnataka, India Oleria Security Full time ₹ 5,00,000 - ₹ 8,00,000 per year

    About Oleria:Oleria provides adaptive and autonomous identity security solutions that help organizations accelerate at the pace of change, trusting that their data is protected. Oleria enables organizations to have comprehensive visibility into their access posture and autonomously identifies and mitigates access risks before they can be exploited. Founded...


  • Bengaluru, Karnataka, India Oleria Security Full time ₹ 1,04,000 - ₹ 1,30,878 per year

    About Oleria:Oleria provides adaptive and autonomous identity security solutions that help organizations accelerate at the pace of change, trusting that their data is protected. Oleria enables organizations to have comprehensive visibility into their access posture and autonomously identifies and mitigates access risks before they can be exploited. Founded...


  • Bengaluru, India Siemens Healthineers Full time

    **Skills**:Graduate / Post Graduate in Computer Science / IT security or related fields. 6-10 years of IT experience and minimum 3 years' experience in IT Security. Demonstrated expertise in the following: - Developing products and services for customers - Security architecture and design - Threat and risk analysis / threat modeling / security risk...


  • Bengaluru, India Siemens Healthineers Full time

    **Skills**:Graduate / Post Graduate in Computer Science / IT security or related fields. 8-15 years of IT experience and minimum 4 years' experience in IT Security. Demonstrated expertise in the following: - Developing products and services for customers - Security architecture and design - Threat and risk analysis / threat modeling / security risk...


  • Bengaluru, Karnataka, India AMD Full time ₹ 15,00,000 - ₹ 20,00,000 per year

    Product Security Lead Engineer (Software)Bangalore, IndiaGeneral Management/ Administration/ Support69211Job DescriptionWHAT YOU DO AT AMD CHANGES EVERYTHINGWe care deeply about transforming lives with AMD technology to enrich our industry, our communities, and the world. Our mission is to build great products that accelerate next-generation computing...