Principal - Product Security Leader

GE Healthcare GE Healthcare · Healthcare · Bengaluru, Karnātaka, India · Digital Technology / IT

This role focuses on enhancing cybersecurity for GE Healthcare's products and cloud-based digital solutions. It involves overseeing the delivery and implementation of cybersecurity processes and controls, coordinating across departments, managing cyber risk, and ensuring alignment with the cybersecurity organization's goals. The role also involves collaborating with stakeholders, product teams, and external partners to align strategies and operations. A key aspect is influencing secure product development, architecting cloud security solutions, leading threat modeling, and ensuring compliance with various security standards and regulations like HIPAA and FDA requirements. The role also mentions leveraging AI tools to mitigate threats in LLM and AI agent-based solutions.

What you'd actually do

  1. Drive secure product development processes standards that can help in early detection and assessment of design flaws, vulnerabilities, weaknesses, missing security controls in products/Applications.
  2. Help team to architect cloud security solutions for securing GEHC SaaS products and should have good understanding of AWS and other security solutions, architecture blueprint and software supply chain security.
  3. Lead Threat modelling in various products and able to identify appropriate solutions to mitigate design threats
  4. Well versed with NIST 800-53 controls, CSA Cloud controls, Owasp Top 10 controls and able to articulate same to product development team to implement them within the assigned products and able to clarify cyber queries from development team
  5. Influence the development of GEHC products and ensure they are secure by design and by default.

Skills

Required

  • Bachelor’s degree in computer science or “STEM” Majors
  • minimum 10 years of experience
  • Cybersecurity
  • Cloud security solutions
  • AWS
  • NIST 800-53 controls
  • CSA Cloud controls
  • Owasp Top 10 controls
  • Secure Development Lifecycle (SDL)
  • SAST
  • DAST
  • Pen test reports
  • Dev-SecOps
  • product management
  • Legal
  • compliances
  • engineering
  • AI tools in cyber processes
  • LLM
  • AI agents-based solutions

Nice to have

  • Healthcare Industry experience
  • CISSP/CISA
  • CompTIA Security+
  • GSEC
  • AWS certification
  • AI certification

What the JD emphasized

  • HIPAA
  • FDA premarket cybersecurity requirements
  • medical device Quality and traceability requirements