Staff Product Security Engineer - Pcs

GE Healthcare GE Healthcare · Healthcare · Bengaluru, Karnātaka, India · Digital Technology / IT

Staff Product Security Engineer responsible for cybersecurity and privacy in the development and maintenance of medical technology products. This includes security architecture, threat modeling, risk assessments, vulnerability management, and ensuring compliance with healthcare regulations like HIPAA.

What you'd actually do

  1. Provide privacy and security technical expertise in support of the product team throughout product development, design change, and life- cycle management.
  2. Work with the Product Security Leader (PSL) to support the product team with process expertise for the GEHC Product Cybersecurity Standard and life- cycle management.
  3. Assess the privacy and cybersecurity state of the product and define product roadmap features/enhancements with stakeholder approval
  4. Responsible for security architecture and coordination of product development for cybersecurity features and enhancements
  5. Own/create Threat models, Security Risk Assessment, Privacy Impact Assessment and other required Product Security / DEPS deliverables for PCS Service Technology products/platforms

Skills

Required

  • 8+ years of development and security experience
  • application security
  • mobile security
  • network security
  • OS security
  • Cloud Security
  • Product/Information security experience in all phases of service/product development and deployment
  • security architecture
  • secure software development lifecycle
  • threat modelling
  • security reviews
  • penetration tests
  • security incident response
  • penetration testing methodologies and tools
  • information security analyses, audits, and reviews
  • secure products
  • information system architecture
  • security controls
  • Cryptography
  • Encryption Algorithms
  • Code Signing
  • Public key Infrastructure (PKI)
  • Certificate Authority (CA)
  • OAUTH authentication
  • 2FA

Nice to have

  • AWS services
  • AWS Solution Architect – Associate certification
  • Rest API
  • Kubernetes
  • container security assessments
  • Information security assessment in healthcare sector
  • privacy requirements
  • security by design principles
  • architecture level security concepts
  • current and emerging security threats and techniques

What the JD emphasized

  • Product Cybersecurity Standard
  • Product Security
  • cybersecurity
  • privacy
  • threat modeling
  • Security Risk Assessment
  • HIPAA