Product Security Engineer
4 days ago
Job Description Summary
We are seeking a talented Product Security and Threat Analyst Engineer to join our Post-Market Vulnerability Team. You will be at the forefront of our product security cybersecurity defense. This role will focus on identifying, analyzing, and mitigating cyber threats and vulnerabilities affecting BD's medical products. The successful candidate will collaborate with cross-functional teams to ensure products meet the highest standards of security and regulatory compliance, while proactively improving threat detection and response capabilities. You will play a crucial role in securing our extensive range of medical devices and systems against cyber threats. You will be responsible for monitoring, analyzing, and responding to incoming security threats, conducting in-depth research on emerging cyber threats, vulnerabilities, and attack vectors. You will evaluate product impact and reassess threats based on product security factors. You will be required to use your deep understanding of threat research to document possible threats and their impact to BD products.
The primary work will involve vulnerability assessments, which includes threat research and analysis, potential impact, exploitability. Assessments will involve product and code analysis to determine the exploitability of vulnerability, as well as assessing safety risk, severity and likelihood.
Job Description
Responsibilities:
- Develop and implement strategies to identify, analyze, and mitigate cyber threats targeting BD products.
- Enhance threat hunting activities to detect and respond proactively to potential security risks.
- Conduct in-depth threat research on vulnerabilities, attack vectors, and possible impacts.
- Develop and maintain artefacts required for ATO submissions, including vulnerability scans, System Security Plans (SSPs), and Risk Assessment Reports
- Determine and document likelihood of exploitability and potential safety risks for potentially impacted products.
- Calculate residual risk for vulnerabilities by considering compensating controls, mitigations, and operational environments.
- Document all threat research and vulnerability assessments in clear, concise, and actionable reports.
- Work with BD public relations teams, providing accurate and timely information on threat status, impact, and analysis for product leadership and customers.
- Partner with product security officers and cross-functional teams to define threat impacts, implement mitigations, and coordinate responses.
- Support the preparation of regular threat intelligence reports and briefings to senior management and stakeholders.
- Continuously enhance threat intelligence processes, tools, and technologies.
- Stay up to date with the latest cybersecurity trends, vulnerabilities, and emerging threats.
- May perform other duties as required.
Qualifications:
- At least 2 years of experience in cybersecurity, with expertise in threat hunting and vulnerability analysis.
- Strong knowledge of cybersecurity threats, vulnerabilities, attack vectors, and controls (e.g., authentication, cryptography, secure coding).
- Familiarity with secure development tools including SCA, SAST, DAST, and vulnerability scanning.
- Familiarity of security frameworks such as NIST 800-53, ISO 27001, GDPR, or IEC
- Knowledge and experience with various programming languages such as C/C++, C#, Python, JavaScript, Ruby, PHP, Go, Swift a plus
- Understanding of MS Windows and Linux operating systems (past and current) and the .NET framework.
- Experience with threat intelligence platforms, threat hunting tools, and cybersecurity frameworks.
- Ability to work in a fast-paced, dynamic environment and manage multiple priorities.
- Strong analytical and problem-solving abilities.
- Strong written and verbal communication skills.
- Relevant certifications such as Security+, CEH, or GIAC are a plus.
Required Skills
Optional Skills
Primary Work Location
IND Bengaluru - Technology Campus
Additional Locations
Work Shift
- 
					Security Engineer II1 week ago 
 Bengaluru, Karnataka, India Safe Security Full time ₹ 12,00,000 - ₹ 36,00,000 per yearAt SAFE Security, our mission is bold and ambitious: We Will Build CyberAGI — a super-specialized system of intelligence that autonomously predicts, detects, and remediates threats. This isn't just a vision—it's the future we're building every day, with the best minds in AI, cybersecurity, and risk. At SAFE, we empower individuals and teams with the... 
- 
					Security Engineer II1 week ago 
 Bengaluru, Karnataka, India Safe Security Full time ₹ 5,00,000 - ₹ 15,00,000 per yearAt SAFE Security, our mission is bold and ambitious: We Will Build CyberAGI — a super-specialized system of intelligence that autonomously predicts, detects, and remediates threats. This isn't just a vision—it's the future we're building every day, with the best minds in AI, cybersecurity, and risk. At SAFE, we empower individuals and teams with the... 
- 
					Security Engineer II1 week ago 
 Bengaluru, Karnataka, India Safe Security Full time ₹ 6,00,000 - ₹ 18,00,000 per yearAt SAFE Security, our mission is bold and ambitious:We Will Build CyberAGI— a super-specialized system of intelligence that autonomously predicts, detects, and remediates threats. This isn't just a vision—it's the future we're building every day, with the best minds in AI, cybersecurity, and risk. At SAFE, we empower individuals and teams with the... 
- 
					  Product Manager2 weeks ago 
 Bengaluru, Karnataka, India Menlo Security Full time ₹ 8,00,000 - ₹ 24,00,000 per yearMenlo Security's mission is enabling the world to connect, communicate and collaborate securely without compromise. COVID-19 has made our mission all the more real. We support customers across various enterprises including Fortune 500 companies, 9/10 of the largest global banks and the Department of Defense.The world has fundamentally changed. We are growing... 
- 
					  Product Manager1 week ago 
 Bengaluru, Karnataka, India Menlo Security Full time ₹ 12,00,000 - ₹ 36,00,000 per yearMenlo Security's mission is enabling the world to connect, communicate and collaborate securely without compromise. COVID-19 has made our mission all the more real. We support customers across various enterprises including Fortune 500 companies, 9/10 of the largest global banks and the Department of Defense. The world has fundamentally changed. We are... 
- 
					Product Security Engineer2 days ago 
 Bengaluru, Karnataka, India Cisco Full time ₹ 20,00,000 - ₹ 25,00,000 per yearWho We AreAs the leader in cloud-managed IT, Cisco connects passionate people to their mission by simplifying the digital workplace. Our impact is driven by the innovative, purposeful, and vibrant people who make up our inclusive community. When technology is intuitive, our customers can focus on what mattersAbout The TeamAs a member of the Device Trust... 
- 
					  Product Security Engineer3 weeks ago 
 Bengaluru, Karnataka, India, Karnataka Traveloka Full timeJob DescriptionProduct Security Engineer at Traveloka will be required to ensure that our products and services are shipped with high security standards through application security testing, hardening, and secure framework. A Product Security Engineer will be smart and self starter. The person needs to find unique ways to understand complex software... 
- 
					  Senior Product Security Engineer4 days ago 
 Bengaluru, Karnataka, India Pocket FM Full time ₹ 12,00,000 - ₹ 36,00,000 per yearAbout Pocket FMPocket FM is the world's largest audio entertainment platform, revolutionizing the way stories are told and consumed. We bring together storytelling, technology, and creativity to deliver an immersive and engaging experience through audio series, audiobooks, and podcasts. With over150 million+ users, andbillions of minutes streamed monthly,... 
- 
					Senior Product Security Engineer2 weeks ago 
 Bengaluru, Karnataka, India Rippling Full time ₹ 12,00,000 - ₹ 36,00,000 per yearAbout RipplingRippling gives businesses one place to run HR, IT, and Finance. It brings together all of the workforce systems that are normally scattered across a company, like payroll, expenses, benefits, and computers. For the first time ever, you can manage and automate every part of the employee lifecycle in a single system.Take onboarding, for example.... 
- 
					  Technical Product Manager3 weeks ago 
 Bengaluru, Karnataka, India, Karnataka Astra Security Full timeAbout Astra: Astra is a cyber security SaaS company that makes otherwise chaotic pentests a breeze with its one of a kind Pentest Platform. Astra's continuous vulnerability scanner emulates hacker behavior to scan applications for 9300+ security tests. CTOs & CISOs love Astra because it helps them fix vulnerabilities in record time and move from DevOps to...