28 Sep
|
BAXTER
|
Bengaluru
Job Summary
As a Principal Product Cybersecurity Engineer, you will own and direct the cybersecurity design, architecture, and analysis of medical devices, digital platforms, and connected healthcare solutions. You will serve as a cybersecurity subject matter expert, leading security initiatives from concept through deployment while providing technical leadership and mentorship across cross-functional teams. You will drive cybersecurity strategy, influence technical decision making, and ensure products are designed and maintained in alignment with industry best practices, regulatory expectations, and organizational objectives.
You will contribute to the organizations cybersecurity vision and strategic roadmap, utilizing deep knowledge of medical device security, connectivity, cloud technologies, software development, and risk management to deliver innovative and secure solutions.
What You'll Be Doing
- Lead the implementation of cybersecurity principles as part of the overall architecture for medical devices, connected systems, digital platforms, and hosted solutions.
- Create, own, and maintain security-related documentation including: Threat Models and Interface Architecture; Security Requirements and Architectures; Security Risk Assessments and Security Risk Analyses; Data Protection Impact Assessments (DPIAs); Product Security Whitepapers; Manufacturer Disclosure Statements for Medical Devices (MDS2); Software Bills of Materials (SBOMs); Static Code Analysis Reports and Security Evidence Packages.
- Partner with product development teams to establish and maintain cybersecurity requirements, plans, policies, and best practices throughout the product lifecycle.
- Lead threat modeling activities and security architecture reviews for medical devices, software applications, cloud-hosted services, and interconnected systems.
- Perform and guide vulnerability assessments, penetration testing, fuzz testing, secure code analysis, and vulnerability scanning activities.
- Establish governance processes around product vulnerability management and cybersecurity risk management.
- Monitor threat intelligence, analyze emerging threats, CWEs, CVEs, and zero-day vulnerabilities, and assess potential impacts on products and platforms.
- Assess third-party software, open-source components, and off-the-shelf technologies for secure use within Baxter products and solutions.
- Drive cybersecurity improvements across cross-functional teams including Engineering, Quality, Regulatory, Risk Management, Marketing, Clinical, Human Factors, Service, and Compliance.
- Ensure compliance with product development processes, quality systems, design controls, and applicable cybersecurity standards and regulations.
- Support annual security audits and assessments, including SOC 2, HITRUST, and other cybersecurity compliance initiatives.
- Participate in security incident investigations, response activities, and post-incident recovery efforts.
- Interface with regulatory agencies and external stakeholders as needed to represent cybersecurity aspects of Baxter products.
- Contribute to external cybersecurity communications including security bulletins, whitepapers, FAQs, and customer-facing documentation.
- Lead project planning, estimation, and execution of cybersecurity deliverables while mentoring and guiding junior engineers and technical teams.
What You'll Bring
Required Qualifications
- Bachelors degree in Computer Science, Engineering, Information Security, Mathematics, Information Management, or a related technical discipline; advanced degree preferred.
- 5+ years of experience in software development, cybersecurity engineering, product security, or secure software development lifecycle (SSDLC) activities.
- Solid understanding of application security and secure development practices throughout the software lifecycle.
- Experience addressing OWASP Top 10 vulnerabilities and implementing secure coding practices.
- Experience performing threat modeling, security risk assessments, secure design reviews, and vulnerability analysis.
- Experience with threat modeling methodologies such as STRIDE, DREAD, LINDDUN, PASTA, or similar frameworks.
- Experience with vulnerability scanning, penetration testing, fuzz testing, and secure code analysis tools.
Disclaimer: This job posting has been aggregated from external source. Role details, content, and availability are subject to change. Applicants are advised to confirm the latest information directly on the company website before applying.
📌 Principle Engineer, Cybersecurity (Bengaluru)
🏢 BAXTER
📍 Bengaluru