Senior Software Engineer - Cybersecurity

GE Healthcare GE Healthcare · Healthcare · Waukesha, WI +1 · Digital Technology / IT

Senior Software Engineer focused on cybersecurity for enterprise-grade platforms in regulated healthcare environments. Responsibilities include designing and building secure software systems, embedding security throughout the SDLC, mitigating risks, and ensuring compliance. Requires experience with secure backend systems, application security concepts, and awareness of cybersecurity threats. Experience in regulated environments is desired.

What you'd actually do

  1. Define, develop, and evolve secure software solutions in a fast-paced, Agile development environment using modern technologies and infrastructure
  2. Partner with product management, security architects, and stakeholders to understand product vision, security requirements, and risk posture
  3. Translate business and security requirements into prioritized user stories, ensuring delivery meets timelines, quality, and security standards
  4. Drive increased engineering efficiency by eliminating duplication, promoting secure design patterns, and leveraging shared frameworks and reusable components
  5. Work cross-functionally with cyber-security, quality, and regulatory to align objectives and deliver secure outcomes

Skills

Required

  • Bachelor’s Degree in Computer Science or STEM-related field
  • Minimum of 4 years of professional software engineering experience with design patterns, secure state management, or defensive coding techniques
  • Minimum of 3 years of experience building secure backend systems, such as: RESTful APIs, relational databases, Windows and Unix/Linux-based systems, and C# (or similar object-oriented languages)
  • Demonstrated awareness of cybersecurity threats, emerging attack vectors, and industry trends
  • Ability to analyze the impact of technology and architectural choices on security, performance, and maintainability
  • Hands-on experience with application security concepts such as authentication, authorization, encryption, secrets management, and secure data handling
  • Willingness to work a hybrid schedule with three days per week on-site at the GE HealthCare office located in Waukesha, Wisconsin
  • Demonstrated flexibility in approach to work hours, and willingness to partner with and accommodate global teams and schedules
  • Legal authorization to work in the U.S. is required. We will not sponsor individuals for employment visas, now or in the future, for this job opening

Nice to have

  • Master’s Degree in Computer Science or STEM-related field
  • 5+ years of professional software experience working in a product development team
  • 2+ years of experience in cybersecurity-focused domains such as IAM, data protection, secure platforms, or compliance-driven systems
  • Knowledge of secure system design in regulated environments (e.g., healthcare, finance, government, or enterprise SaaS)
  • Exposure to cloud platforms (AWS, Azure, or GCP) with a focus on cloud security and shared responsibility models
  • Proven ability to break down problems, document requirements and risks, and estimate engineering effort
  • Experience designing and securing scalable microservices architectures
  • Familiarity with DevSecOps tooling (SAST, DAST, dependency scanning, secrets detection, etc.)
  • Demonstrated knowledge of medical device cybersecurity practices, including vulnerability management, and post‑market surveillance in regulated environments.
  • Initiative to explore alternative technologies, security tools, and approaches to solving complex problems
  • Strong problem-solving, communication, and collaboration skills
  • Experience identifying misalignments with goals and proactively recommending corrective actions
  • Track record of balancing competing priorities while meeting delivery commitments
  • Ability to clearly articulate technical and security tradeoffs and influence outcomes through collaboration

What the JD emphasized

  • strong cybersecurity focus
  • embed security into every phase of the software lifecycle
  • protecting sensitive data
  • mitigating risks
  • ensuring compliance
  • regulated environments
  • secure software solutions
  • security requirements
  • security standards
  • secure design patterns
  • cyber-security
  • secure outcomes
  • application security
  • threat mitigation
  • secure coding practices
  • vulnerability prevention
  • technical and security issues
  • security maturity
  • secure state management
  • defensive coding techniques
  • building secure backend systems
  • cybersecurity threats
  • emerging attack vectors
  • application security concepts
  • secure data handling
  • cybersecurity-focused domains
  • secure platforms
  • compliance-driven systems
  • secure system design
  • cloud security
  • securing scalable microservices architectures
  • DevSecOps tooling
  • medical device cybersecurity practices
  • vulnerability management
  • regulated environments