Product Security Analyst

2 days ago


INDBengaluruEPIP Phase II India GE Healthcare Private Limited Full time ₹ 12,00,000 - ₹ 36,00,000 per year

Sr Product Security Analyst

Job Description SummaryWe are looking for an Sr Product Security Analyst, with a focus on Penetration testing and Python coding. In this role you will work in a team to identify, risk rate, communicate and track product vulnerabilities and be a part of the Cyber Security Lab team.

GE Healthcare is a leading global medical technology and digital solutions innovator. Our mission is to improve lives in the moments that matter. Unlock your ambition, turn ideas into world-changing realities, and join an organization where every voice makes a difference, and every difference builds a healthier world. Job Description

Roles and Responsibilities

In this role, you will:

  • Be able to scope and participate in hardware and software penetration tests, vulnerability identification and vulnerability risk assessment.

  • Engage in application and domain-specific threat modeling and attack surface analysis/reduction

  • Engage in incident response methods lead incident response processes related to product cybersecurity

  • Create and track meaningful metrics around product cyber risk and compensating controls

  • Perform Security Code Reviews, Vulnerability Analysis and research on application code

  • Create vulnerability and incident trend analysis to improve product design

  • Maintain cyber Bills of Material and conduct proactive vulnerability monitoring and assessment on cyber components

  • Engage and administer End Of Life processes for digital products

  • Promote best practices based on OWASP, SANS Top 25.

  • Write fuzz scenarios to see the break network protocol suites such as TCP/IP, IPv6, UDP, TLS, DTLS

  • Ability to automate attack scenarios to avoid repetitive work.

  • Consult, architect on security requirements and utilize best practices to meet them.

  • Help prepare reports at appropriate levels of confidentiality for stakeholders to view

  • Respond promptly and in detail to customer-sponsored penetration tests

  • Provide guidance on automated testing tools and techniques

Required Skills

  • Professional expertise with Kali Linux, Metasploit, Meterpreter.

  • Hands-on experience in Windows/Linux and network security.

  • Execute Scans using tools such as Nessus, Burp, Fortify/Coverity, Splunk etc.

Education Qualification

  • Bachelor's Degree in Computer Science or "STEM" Majors (Science, Technology, Engineering and Math) with a minimum of 5+ years of experience in systems security, product / OT security and application security

Technical Expertise

  • Experience with cyber security framework (NIST 800-53, ISO 27001, IEC 62443, etc.) implementation and governance

  • Experience with secure coding principles; code signing; secure boot

  • Experience with penetration testing and ethical hacking

  • Knowledge of CI/CD and automation tools (Chef, Git, Jenkins)

  • Knowledge of Identity management and identity federation (SAML, Oauth, SCIM, XACML)

  • Experienced in developing web services (SOAP/REST)

  • Must be available for on call for potential security response

  • Knowledge of application risk identification and evaluation techniques

  • Knowledge of Cyber Security and full knowledge of multiple related engineering functions

  • Experience securing applications within cloud platforms such as AWS, Azure and alike.

  • Experience with broad set of information security technologies and processes within a SaaS, IaaS, PaaS, or cloud environment

Inclusion and Diversity

GE Healthcare is an Equal Opportunity Employer where inclusion matters. Employment decisions are made without regard to race, color, religion, national or ethnic origin, sex, sexual orientation, gender identity or expression, age, disability, protected veteran status or other characteristics protected by law.

We expect all employees to live and breathe our behaviors: to act with humility and build trust; lead with transparency; deliver with focus, and drive ownership – always with unyielding integrity.

Our total rewards are designed to unlock your ambition by giving you the boost and flexibility you need to turn your ideas into world-changing realities. Our salary and benefits are everything you'd expect from an organization with global strength and scale, and you'll be surrounded by career opportunities in a culture that fosters care, collaboration and support.

#LI-AM11

#LI-Hybrid

Additional Information

Relocation Assistance Provided: Yes

Experience LevelSenior Level

  • IND--Bengaluru-EPIP (Phase II), India GE HealthCare Full time ₹ 8,00,000 - ₹ 24,00,000 per year

    Job Description SummaryAs a Staff Product Security Engineer, you will be part of the Ultrasound Digital team with the vision of building and sustaining product competencies and customer orientation to provide timely patient care. We are looking for a person with strong technical acumen in Cyber security in the cloud and preferably a person who has knowledge...


  • IND--Bengaluru-EPIP (Phase II), India GE HealthCare Full time ₹ 8,00,000 - ₹ 12,00,000 per year

    Job Description SummaryWe are seeking a Senior Technical Product Manager to lead the development and deployment of Over-the-Air (OTA) product capabilities across our software subscription portfolio. This role will be instrumental in shaping the future of our digital product delivery, enabling seamless updates, feature rollouts, and data-driven enhancements...


  • IND--Bengaluru-EPIP (Phase II), India GE Healthcare Private Limited Full time US$ 1,20,000 - US$ 1,80,000 per year

    Senior Staff Cyber Security Program Manager Job Description SummaryAs a Senior Program Manager, you will lead cross-functional initiatives to deliver high-impact cybersecurity and privacy solutions. You will orchestrate program strategy, execution, and continuous improvement for our team's core activities. This role demands a strategic thinker with...


  • IND--Bengaluru-EPIP (Phase II), India GE HealthCare Full time ₹ 8,00,000 - ₹ 16,00,000 per year

    Job Description SummaryAs the Technical Product Manager - Workday, you will drive the strategic direction, planning, and execution of technical projects and initiatives related to the Workday platform. You will collaborate with cross-functional teams including the HR function, up and downstream systems, and our AMS provider to define the strategic roadmap,...


  • Bengaluru, Karnataka, India GE Healthcare Private Limited Full time ₹ 20,00,000 - ₹ 25,00,000 per year

    Product Security Analyst Job Description SummaryAs a Product Security Analyst, you will be collaborating with development teams to complete security testing and tool development for our GEHC products. You will be responsible for Performing VAPT for thick and thin clients, webservices, embedded devices and cloud. Conducting Compliance/Benchmark assessments...


  • Bengaluru, Karnataka, India GE Healthcare Private Limited Full time ₹ 20,00,000 - ₹ 25,00,000 per year

    Sr Product Security Analyst Job Description SummaryWe are looking for an Sr Product Security Analyst, with a focus on Penetration testing and Python coding. In this role you will work in a team to identify, risk rate, communicate and track product vulnerabilities and be a part of the Cyber Security Lab team. GE Healthcare is a leading global...


  • IND--Bengaluru-EPIP (Phase II), India GE HealthCare Full time ₹ 12,00,000 - ₹ 24,00,000 per year

    Job Description SummaryAs a Principal Software Engineer, in the identity domain, you will lead the design and development of identity and access management solutions. This role requires deep expertise in authentication and authorization protocols, standards, and technologies. You will play a key role in shaping the architecture and strategy for secure...


  • India MAX Security Full time

    Max is Global Risk Management organization based out in Tel Aviv, Israel and its APAC HQ is based out of Mumbai. Led by veterans from Israeli Military Special Forces, Intelligence, Cyber and Secret Services we operate in 160 countries across the globe. We have capabilities in every continent across the world and carry the experience of 25 + successful years...


  • Bengaluru, India Cloudsek Information Security Full time

    Job Description - We are looking for a Cyber Security Analyst to be a part of the CloudSEK Cyber-Security team - An ideal candidate will demonstrate an aptitude for learning new technologies, evidenced by the ability to expand upon core knowledge - She/he should be highly analytical with the ability to derive facts quickly, methodically, and accurately -...

  • Principal Network

    1 week ago


    IND--Bengaluru-EPIP (Phase II), India GE HealthCare Full time ₹ 8,00,000 - ₹ 16,00,000 per year

    Job Description SummaryFocuses on ongoing management/maintenance of all Digital infrastructure, products, services & ops ensuring business continuity, capacity management, incident response & help desk mgmt. Impacts the team's ability to achieve service, quality and timeliness of objectives. The role is subject to operating policy objectives. There is...