Graduate / Post Graduate in Computer Science / Information systems with specialization on Cybersecurity.
5-7 years of IT experience and minimum 3 years' experience in Cybersecurity.
Demonstrated expertise in the following:
- Active contribution in cybersecurity for healthcare product development or services.
- Proficiency in Secure Architecture and Design
- Threat and risk analysis / threat modeling / security risk analysis
- Security vulnerability monitoring / 3rd party software security evaluation
- Security incident handling / security forensic analysis
- Fuzz testing / penetration testing
- Secure coding and design guidelines / secure software development and deployment / Secure supply chain Management for Product lifecycle
- Knowledge on HIPAA / HITECH regulations / FDA cybersecurity regulations for medical devices
- Standards: IEC 62443, NIST SP 800-x, IEC 80001, CLSI AUTO11-Ax, ISO 27001 etc.
- Certified Information Systems Security Professional (CISSP) or Certified Secure Software Lifecycle Qualified (CSSLP) or equivalent demonstrated expertise is beneficial.
Areas of Responsibility:
- Support project teams in conducting the corresponding security activities during the development process,
project management process and services and in product and solution release.
- Participate in threat and risk analysis workshops
- Provide expertise and support in security tools to product teams
- Conduct product and solution security training and development of training material.
- Develop and maintain security guidelines and guidance for product development teams.
- Collect product & solution security related lessons learned and feed into continuous improvement activities (e.g. update of guidelines, reporting to PSSOs, integration in
- Participate in incident response teams, incident escalation awareness material).
- Stay up-to-date on the latest security threats/technologies.
- Support the development of the PSS community within the organization, with experience exchange internally and externally.
- Support multiple projects at the same time and should occupy the function for the main part of defined working time.
- Self motivated to keep up-to-date knowledge on tools and technologies eg: Cloud, Identity and Access Management (IAM), Encryption, Mobile, Network, Endpoint security
- Occasional travel outside India for collaboration activities if required.