Product Security Analyst
1 week ago
GE Healthcare is a leading global medical technology and digital solutions innovator. Our mission is to improve lives in the moments that matter. Unlock your ambition, turn ideas into world-changing realities, and join an organization where every voice makes a difference, and every difference builds a healthier world.Job Description
Roles and Responsibilities
You are a skilled Analyst who enjoys security work and is an expert in systems security, product / OT security and application security.
In this role, you will:
Work with product managers, independent researchers, and in-house researchers to identify, rate, report and manage product vulnerabilities and incidents.
Be responsible for providing technical leadership and defining, developing, and evolving security within software in a fast-paced and agile development environment using the latest secure software development technologies and infrastructure.
Work with Cyber Security Leaders and SMEs to understand product requirements
Translate security requirements / vision into a prioritized list of user stories, completing work according to required timelines and quality standards
Assist security champions in completing Threat Modeling and Architecture Risk Analysis on product features
Perform Security Code Reviews, Vulnerability Analysis and research on application code
Coach and mentor developers to implement cryptography solutions securely (PKI, Code Signing, Stored Secrets, et cetera)
•Engage subject matter experts in successful transfer of complex domain knowledgeApply principles of Secure SDLC and methodologies like Lean/Agile/XP, CI, Software and Product Security
Provide guidance and advice on writing secure code that meets standards and delivers desired functionality, using the technology selected for the project
Understand application security methodologies and frameworks
Leverage GE Digital's tailored Secure SDL practice into specific engineering engagements
Research new application security technologies and implement them to improve application security.
Maintaining a backlog of security-related tools that will improve the maintainability and security of our code and the pace of development
Promote best practices based on OWASP, SANS Top 25, and the GE Digital SDL.
Write fuzz scenarios to see the break network protocol suites such as TCP/IP, IPv6, UDP, TLS, DTLS
Ability to automate attack scenarios to avoid repetitive work.
Good to have experience in Bluetooth/Wifi or any radio based attacks.
Good to have experience in Rest API security testing and recommending best practices while opting for OAuth or OpenId connect
Having experience working on IoT platform will be beneficial.
Required Skills
Professional expertise with Kali Linux, Metasploit, Meterpreter.
Hands-on experience in Windows/Linux and network security.
Execute Scans using tools such as Nessus, Burp, Fortify/Coverity, Splunk etc.
Education Qualification
Bachelor's Degree in Computer Science or "STEM" Majors (Science, Technology, Engineering and Math) with a minimum of 2+ years of experience in systems security, product / OT security and application security.
Desired Characteristics
Certifications – OSCP, CCSP.
Languages – C/C++/Java/Python/Ruby
Proven experience in breaking the vulnerable boxes.
Adaptable to learn new skills or technologies as per business needs.
Detailed working knowledge of two modern programming languages, such as java, python, or ruby
Good written and oral communication skills and successful security consulting background.
Experience in developing secure applications
A high energy and a result-oriented attitude/approach, with an understanding of release timelines and the need to enable development teams, not slow them down
Experience with Security Development Lifecycle processes such as Threat Modeling desired
Contribute to and lead discussions and communications within the team and outside, including customers and other business units
Excellent knowledge of Object Oriented Analysis and Design, Software Design Patterns and coding principles
Hands-on Experience with developing cloud-deployed applications that utilize oath 2
Hands-on experience with developing RESTful web services
Mobile Architecture experience, designing, developing, and integrating solutions.
Good understanding of security tools and technologies to facilitate secure development
Inclusion and Diversity
GE Healthcare is an Equal Opportunity Employer where inclusion matters. Employment decisions are made without regard to race, color, religion, national or ethnic origin, sex, sexual orientation, gender identity or expression, age, disability, protected veteran status or other characteristics protected by law.
We expect all employees to live and breathe our behaviors: to act with humility and build trust; lead with transparency; deliver with focus, and drive ownership – always with unyielding integrity.
Our total rewards are designed to unlock your ambition by giving you the boost and flexibility you need to turn your ideas into world-changing realities. Our salary and benefits are everything you'd expect from an organization with global strength and scale, and you'll be surrounded by career opportunities in a culture that fosters care, collaboration and support.
#LI-AM11
#LI-Hyrbid
Additional InformationRelocation Assistance Provided: Yes
-
Product Security Analyst
1 week ago
IND--Bengaluru-EPIP (Phase II), India GE HealthCare Full time ₹ 12,00,000 - ₹ 36,00,000 per yearJob Description SummaryWe are seeking enthusiastic and innovative developers to join our Cybersecurity R&D team. You'll be part of a dynamic group that builds cutting-edge security and privacy analysis tools powered by generative AI. This role blends prompt engineering, scripting, and app development to create intelligent solutions that support penetration...
-
Staff Product Security Engineer
1 day ago
IND--Bengaluru-EPIP (Phase II), India GE HealthCare Full time ₹ 8,00,000 - ₹ 24,00,000 per yearJob Description SummaryAs a Staff Product Security Engineer, you will be part of the Ultrasound Digital team with the vision of building and sustaining product competencies and customer orientation to provide timely patient care. We are looking for a person with strong technical acumen in Cyber security in the cloud and preferably a person who has knowledge...
-
Senior Technical Product Manager
1 day ago
IND--Bengaluru-EPIP (Phase II), India GE HealthCare Full time ₹ 8,00,000 - ₹ 12,00,000 per yearJob Description SummaryWe are seeking a Senior Technical Product Manager to lead the development and deployment of Over-the-Air (OTA) product capabilities across our software subscription portfolio. This role will be instrumental in shaping the future of our digital product delivery, enabling seamless updates, feature rollouts, and data-driven enhancements...
-
Senior Staff Cyber Security Program Manager
1 week ago
IND--Bengaluru-EPIP (Phase II), India GE HealthCare Full time ₹ 12,00,000 - ₹ 36,00,000 per yearJob Description SummaryAs a Senior Program Manager, you will lead cross-functional initiatives to deliver high-impact cybersecurity and privacy solutions. You will orchestrate program strategy, execution, and continuous improvement for our team's core activities. This role demands a strategic thinker with deep expertise in program management, cybersecurity...
-
Security Analyst
2 days ago
gujarat, ind, India the athlos Full timeHiring a Security Analyst to join our Global SOC team. Analysts work in a team environment to monitor the health and wellness of security devices on our partner's client networks. You will work with a fast-paced global leader in IT Security Services providing support to our vast partner base amid an ever-changing technology landscape. The Security Analyst is...
-
Staff Technical Product Manager
1 day ago
IND--Bengaluru-EPIP (Phase II), India GE HealthCare Full time ₹ 12,00,000 - ₹ 36,00,000 per yearJob Description SummaryAs the Technical Product Manager - Workday, you will drive the strategic direction, planning, and execution of technical projects and initiatives related to the Workday platform. You will collaborate with cross-functional teams including the HR function, up and downstream systems, and our AMS provider to define the strategic roadmap,...
-
Senior Technical Product Manager
3 days ago
IND--Bengaluru-EPIP (Phase II), India GE HealthCare Full time US$ 1,20,000 - US$ 1,80,000 per yearJob Description SummaryWe are seeking a Senior Technical Product Manager to lead the design, configuration, and management of Oracle Fusion Financials capabilities across our enterprise financial systems. This role will be instrumental in shaping the future of our financial operations, enabling seamless revenue recognition, progress billing, and accounts...
-
Product Security Analyst
2 weeks ago
Bengaluru, Karnataka, India GE Healthcare Ltd Full time ₹ 12,00,000 - ₹ 36,00,000 per yearJob Description Summary As a Product Security Analyst, you will be collaborating with development teams to complete security testing and tool development for our GEHC products. You will be responsible for Performing VAPT for thick and thin clients, web services, embedded devices, and cloud. Conducting Compliance/Benchmark assessments using DISA Stigs/CIS...
-
Principal Engineer
1 week ago
IND--Bengaluru-EPIP (Phase II), India GE HealthCare Full time ₹ 12,00,000 - ₹ 36,00,000 per yearJob Description SummaryWe are seeking a Principal Engineer to lead our Cyber Security Engineering and AI Automation initiatives for our Healthcare Device and Solutions organization.This role is for a hands-on technical leader passionate about penetration testing, cloud security, and AI-driven automation in a regulated healthcare environment.You will...
-
Principal Product Marketing Manager
1 week ago
Bengaluru, India Skyhigh Security Full timeAbout Skyhigh Security: Skyhigh Security is a dynamic, fast-paced, cloud company that is a leader in the security industry. Our mission is to protect the world’s data, and because of this, we live and breathe security. We value learning at our core, underpinned by openness and transparency. Since 2011, organizations have trusted us to provide them with a...