Staff Product Security Engineer
1 day ago
GE HealthCare is a leading global medical technology and digital solutions innovator. Our mission is to improve lives in the moments that matter. Unlock your ambition, turn ideas into world-changing realities, and join an organization where every voice makes a difference, and every difference builds a healthier world.Job Description
Key Responsibilities:
Assess the security for software/Product architecture – guide the product architects to ensure security is built into at the design level itself.
Own development of cyber security artifacts including threat model and lead discussion on identifying mitigations.
Assist the Engineering teams in triaging and identification of fix for detected product vulnerabilities.
Interact with internal / external team to co-ordinate security and privacy assessments which includes VAPT to determine compliance and security posture.
Assist business units in the development and implementation of product security and Privacy practices including policies, standards, guidelines, and procedures.
Verify that security and privacy requirements defined in the security plans, policies, and procedures are followed and protection measures are functioning as intended.
Guide the business unit in their management of the resolution of security audit or review findings.
Provide security risk management and security advice as well as advice on strategic direction relating to product and information security.
Assist with security incidents and review risk and impact of breaches to protected systems.
Review proposed services, engineering changes, and feature requests for security implications and needed security controls.
Qualifications/Requirements:
Bachelor's degree in engineering
Should have 7+ years of development and security experience which includes application security, mobile security, network security, OS security and Cloud Security.
Experience in Rest Api, Kubernetes and container security assessments.
Product/Information security experience in all phases of service/product development and deployment including architecture, design, development, testing and deployment.
Good understanding of AWS services, specifically related to security.
Experience in designing security solutions.
Hands-on experience in execution and review of Static & Dynamic Code Analysis reports and ability to discuss with development teams for true positives.
Experience and knowledge of penetration testing methodologies and tools.
Conducting information security analyses, audits, and reviews
Experience in Automation of pen test scenarios using Python or any other languages is mandatory
Willingness to learn new technologies and work on security for varied products.
Strong interpersonal skills with the ability to facilitate diverse groups, help negotiate priorities, and resolve conflicts among project stakeholders
Sound security engineering knowledge (technical) so as to work collaboratively with the Tech Leads and software/products architects to ensure secure products.
Knowledge of information system architecture and security controls (e.g., firewall, specialized appliances)
Sound understanding of Cryptography, various Encryption Algorithms, Public key Infrastructure (PKI) and Certificate Authority (CA), OAUTH authentication, 2FA
Desired Characteristics:
AWS Solution Architect – Associate along with AWS Security Specialty certification.
Experience of Information security assessment in healthcare sector.
Experience with NIST 800-53, CIS/STIG benchmark audit.
Ideal candidate would have worked on the software development initially and then graduated in to either -S/W Lead/security assessments ensuring security in the product design.
Exposure to privacy requirements
Understanding of HI-TRUST and SOC2.
Excellent Cyber Security capabilities
Strong knowledge of secure software development lifecycle and practices such as threat modelling, security reviews, penetration tests, and security incident response
Understanding of security by design principles and architecture level security concepts
Up to date knowledge of current and emerging security threats and techniques for exploiting security vulnerabilities
Ability to relate cyber security incidents from cross-industries.
Good to have security certifications like OSCP/CCSP/CISSP
Inclusion and Diversity
GE HealthCare is an Equal Opportunity Employer where inclusion matters. Employment decisions are made without regard to race, color, religion, national or ethnic origin, sex, sexual orientation, gender identity or expression, age, disability, protected veteran status or other characteristics protected by law.
We expect all employees to live and breathe our behaviors: to act with humility and build trust; lead with transparency; deliver with focus, and drive ownership – always with unyielding integrity.
Our total rewards are designed to unlock your ambition by giving you the boost and flexibility you need to turn your ideas into world-changing realities. Our salary and benefits are everything you'd expect from an organization with global strength and scale, and you'll be surrounded by career opportunities in a culture that fosters care, collaboration and support.
Disclaimer: GE HealthCare will never ask for payment to process documents, refer you to a third party to process applications or visas, or ask you to pay costs. Never send money to anyone suggesting they can provide employment with GE HealthCare.
#LI-SM1
Additional InformationRelocation Assistance Provided: Yes
-
Product Security Analyst
1 week ago
IND--Bengaluru-EPIP (Phase II), India GE HealthCare Full time ₹ 12,00,000 - ₹ 36,00,000 per yearJob Description SummaryAs a Product Security Analyst, you will be collaborating with development teams to complete security testing and tool development for our GEHC products. You will be responsible for Performing VAPT for thick and thin clients, webservices, embedded devices and cloud. Conducting Compliance/Benchmark assessments using DISA Stigs/CIS...
-
Product Security Analyst
1 week ago
IND--Bengaluru-EPIP (Phase II), India GE HealthCare Full time ₹ 12,00,000 - ₹ 36,00,000 per yearJob Description SummaryWe are seeking enthusiastic and innovative developers to join our Cybersecurity R&D team. You'll be part of a dynamic group that builds cutting-edge security and privacy analysis tools powered by generative AI. This role blends prompt engineering, scripting, and app development to create intelligent solutions that support penetration...
-
Staff Software Engineer
1 day ago
IND--Bengaluru-EPIP (Phase II), India GE HealthCare Full time ₹ 12,00,000 - ₹ 24,00,000 per yearJob Description SummaryThis position is for a Staff Software Engineer in the Healthcare Digital Team in GE Healthcare, Bangalore. The staff software engineer will be responsible for design and implementation of one or more application modules, subsystems or services. In addition, this person will drive activities to improve software quality and development...
-
Staff Software Engineer
1 day ago
IND--Bengaluru-EPIP (Phase II), India GE HealthCare Full time ₹ 8,00,000 - ₹ 24,00,000 per yearJob Description SummaryThe PCS Enterprise Platform team is working on building next gen visualization platform. The Staff Software Engineer is a critical and highly visible role within Patient Care Solutions (PCS) platform team. This role is responsible for owning the design & implementation of features / functionality, working closely with scrum team for...
-
Senior Staff Cyber Security Program Manager
1 week ago
IND--Bengaluru-EPIP (Phase II), India GE HealthCare Full time ₹ 12,00,000 - ₹ 36,00,000 per yearJob Description SummaryAs a Senior Program Manager, you will lead cross-functional initiatives to deliver high-impact cybersecurity and privacy solutions. You will orchestrate program strategy, execution, and continuous improvement for our team's core activities. This role demands a strategic thinker with deep expertise in program management, cybersecurity...
-
Staff Technical Product Manager
1 day ago
IND--Bengaluru-EPIP (Phase II), India GE HealthCare Full time ₹ 12,00,000 - ₹ 36,00,000 per yearJob Description SummaryAs the Technical Product Manager - Workday, you will drive the strategic direction, planning, and execution of technical projects and initiatives related to the Workday platform. You will collaborate with cross-functional teams including the HR function, up and downstream systems, and our AMS provider to define the strategic roadmap,...
-
Senior Staff Cloud
6 days ago
IND--Bengaluru-EPIP (Phase II), India GE HealthCare Full time ₹ 12,00,000 - ₹ 36,00,000 per yearJob Description SummaryAs a Senior Staff Cloud & AI Cybersecurity Architect, You'll be involved designs, implementation, and managing security strategies for systems incorporating artificial intelligence and machine learning (AI/ML). Unlike a traditional security architect, this role specifically addresses the unique threats and vulnerabilities introduced...
-
Staff Software Engineer
21 hours ago
IND--Bengaluru-EPIP (Phase II), India GE HealthCare Full time ₹ 1,20,000 - ₹ 1,80,000 per yearJob Description SummaryGE Healthcare's Monitoring Solutions (MS) team is seeking a Staff Software Engineer – Automation with deep expertise in test automation, system reliability, and technical leadership. You will play a pivotal role in developing a next-generation Digital Health Software platform that delivers clinical intelligence at the point of care....
-
Senior Staff Software Engineer
1 day ago
IND--Bengaluru-EPIP (Phase II), India GE HealthCare Full time ₹ 2,00,000 - ₹ 4,00,000 per yearJob Description SummaryAs Senior Staff Software Engineer, you will be responsible for designing highly complex modules, critical components or a whole application/product in its entirety. Has the vision to integrate it across multiple systems. This position works independently and is seen as a technical leader. The position is responsible for driving the...
-
Staff Technical Product Manager
2 weeks ago
IND--Bengaluru-EPIP (Phase II), India GE HealthCare Full time ₹ 1,00,00,000 - ₹ 2,00,00,000 per yearJob Description SummaryResponsible for operating in lock-step with product management to create a clear strategic direction for build needs for customer success in Software Subscription. You will work with the team and deliver a clear and descriptive set of requirements to enable the delivery of a products features and functionality. Your priority is...