At Solventum, we improve lives by helping healthcare professionals do their best work. Join a team using innovation and insight to make a real impact on the future of healthcare.
Responsibilities
- The Impact You ll Make in this Role: Joining a team of cybersecurity professionals motivated to secure Solventums healthcare information systems and the personal health information of our clients and their patients.
- Operating and enhancing application security tool environments.
- Authoring automation scripts for reoccurring tasks (Python preferred)
- Setup and execute authenticated and unauthenticated dynamic application security testing DAST scans against web applications and APIs using approved tools.
- Manage scan scheduling, configuration, and coverage across application security tool environments.
- Tune scanning profiles to reduce false positives and improve detection accuracy.
- Ensure DAST scanning aligns with release cycles and risk-based scanning requirements
- Validate DAST findings to confirm exploitability and business impact.
- Categorize vulnerabilities using industry standards (eg, OWASP Top 10).
- Prioritize findings based on risk, application criticality, and exposure.
- Eliminate false positives and duplicate findings prior to developer handoff.
- Partner with development and platform teams to explain DAST findings and remediation expectations.
- Track remediation progress and verify fixes through re-scanning or targeted validation.
- Maintain accurate vulnerability records in enterprise tracking systems.
- Escalate overdue or high-risk vulnerabilities in accordance with policy.
- Working with application teams to validate that software applications meet security guidelines and compliance standards such as HIPPA, SOC II, GDPR, NIST 800-53, etc.
- Building solutions that collect and present vulnerability and compliance data to Solventums leadership.
Minimum qualifications
- Bachelor s Degree & 3-6 years of experience
- Experience administering Qualys VM or App sec
- Experience in working across multiple teams and disciplines
- Robust attention to detail and analytical skills.
- Risk-based prioritization and sound judgment.
- Knowledgeable with AWS or Azure cloud environments
- Familiarity with best practice software security requirements in industry standard compliance programs (NIST, HITRUST, FedRAMP, etc.)
- Experience developing or testing RESTful APIs with an understanding of Postman and/or Swagger files
- Strong communication skills, ability to work independently or collaborate with application teams
Additional qualifications (Nice to have)
- Experience administering Qualys or WebInspect vulnerability management and application security modules
Work location
- Hybrid - India Only
Travel
- May include up to 10%
Relocation Assistance
- Is not authorized.
Disclaimer: This job posting has been aggregated from external source. Role details, content, and availability are subject to change. Applicants are advised to confirm the latest information directly on the company website before applying.