At STERIS, we help our Customers create a healthier and safer world by providing creative healthcare and life science product and service solutions around the globe.
Position Summary
The Senior Cybersecurity Engineer is a cybersecurity specialist working within the STERIS R&D; controls department. The responsibilities include analyzing software and hardware for potential vulnerabilities, creating work instructions for secure software maintenance, collaborating with product development teams for secure designs, conducting vulnerability assessments, and participating in incident response efforts. You will focus on creating and maintaining the security standards that contribute to the safety and integrity of critical healthcare technology.
Duties
- Receive and analyze CVEs from open‑source sources, determine applicability to STERIS products, and collaborate with product teams to gather information needed for CVE impact and applicability assessments
- Develop and track software bill of materials (SBOM), track vulnerabilities in SBOM,
and work with product teams to remediate the vulnerabilities
- Identify potential software security vulnerabilities and collaborate with product teams for remediation and planning
- Lead cybersecurity incident response activities, supporting investigation and remediation efforts.
- Lead product security risk assessments, requirements analysis, and test methods in alignment with internal procedures and regulatory requirements.
- Evaluate and execute product security testing including test planning, cases, and procedure development
- Perform vulnerability assessment and network scanning activities
- Perform internal security testing activities including fuzz testing to identify potential product vulnerabilities
- Reproduce penetration testing findings to help product teams understand security issues and develop effective remediations
- Implement proposed security controls/methods to software embedded in STERIS products and other software