Cyber Security Consultant (Maharashtra)

Cyber Security Consultant (Maharashtra)

07 Oct
|
Syrma Johari Medtech
|
Maharashtra

07 Oct

Syrma Johari Medtech

Maharashtra

Title - Information & Data Security (Medical Device Mandate)

Exp- 9 to 12yrs

Location - Pune (Onsite - WFO)

We are looking for an experienced Information & Data Security Lead to establish and strengthen enterprise information security, data protection, cybersecurity risk management and security governance across the organization. The role will be responsible for protecting sensitive business, customer, product and intellectual-property data across applications, infrastructure, cloud environments and engineering operations.

The candidate will work closely with Engineering, IT, Product, Quality, Regulatory, Legal, Compliance and Business teams to embed security into enterprise processes as well as the medical-device product lifecycle. The role will support cybersecurity for connected and software-enabled medical devices, including security risk assessment, secure development, vulnerability management, SBOM, SOUP, VAPT and post-market cybersecurity activities.

This position is ideal for a senior security professional who can translate security, privacy, and regulatory requirements into practical policies, controls, risk-management processes and product-security practices.

Roles & Responsibility

- Lead the organization's information and data security strategy, policies, standards, controls and governance, aligned with applicable security, privacy and regulatory requirements.
- Establish and maintain data classification, protection, retention, access control, encryption, DLP and IAM practices for sensitive and regulated information.
- Lead security risk assessments, vulnerability management, penetration testing, security audits and remediation programs, including tracking and reporting of security risks and findings.
- Lead security architecture and risk assessments across cloud, applications, APIs, engineering platforms and connected/IoT environments, and embed security into the SDLC through threat modelling, secure design, SPDF and security reviews.
- Support cybersecurity across the medical-device product lifecycle,



working with Engineering, Quality and Regulatory teams on product cybersecurity, EU MDR/IVDR, MDCG 2019-16 rev.1, vulnerability management, security updates and post-market activities.
- Lead security incident response, including investigation, containment, root-cause analysis, corrective actions and lessons learned.
- Manage third-party and supplier security assessments and ensure appropriate security requirements are incorporated into supplier and customer engagements.
- Develop security KPIs/KRIs, risk dashboards and executive reporting, and support customer and regulatory audits through evidence collection, gap assessment and remediation closure.
- Develop security awareness and training programs covering data protection, phishing, access management, confidential information and cybersecurity practices

Specific Skill

- 8–12 years of experience in information security, cybersecurity, data security or a related discipline, preferably within medical devices, healthcare, digital health or another highly regulated industry.
- Strong understanding of information-security governance, data protection, cybersecurity risk management, IAM, vulnerability management, incident response and security controls, with practical experience implementing security policies and processes.
- Strong working knowledge of ISO/IEC 27001, NIST, SOC 2 and GDPR, as applicable, with familiarity with ISO 13485, ISO 14971, IEC 62304, IEC 82304, IEC 81001-5-1, EU MDR/IVDR and MDCG 2019-16 rev.1 and medical-device cybersecurity requirements/guidance preferred.
- Experience in cloud, application, API, connected device/IoT and engineering security, including SPDF,



SBOM, SOUP, threat modelling, secure SDLC, security architecture and vulnerability remediation.
- Experience supporting medical-device or software-enabled product cybersecurity, including product security risk assessment and lifecycle cybersecurity activities.
- Experience with security audits, penetration testing, compliance assessments, third-party security assessments and remediation programs.
- Bachelor's degree in Cybersecurity, Information Security, Computer Science, Engineering or a related field, or equivalent experience. Relevant certifications such as CISSP, CISM, CISA, CRISC or ISO/IEC 27001 Lead Implementer/Auditor are preferred.

General Skill

- Strong communication and presentation skills, with the ability to explain complex cybersecurity, data-protection and technology risks clearly to senior leadership, engineering teams, quality/regulatory teams and business stakeholders.
- Strong structured thinking and problem-solving skills, with the ability to identify security risks, assess their business and product impact, and translate them into practical controls and remediation actions.
- Strong cross-functional collaboration skills with the ability to work effectively across Engineering, IT, Product, Quality, Regulatory, Legal, Compliance and Business teams.
- Solid leadership and stakeholder-management skills, with the ability to establish security practices, drive adoption and influence teams without relying solely on formal authority.
- Strong understanding of the need to balance security, privacy, product functionality, business objectives, regulatory requirements and customer needs.
- High level of integrity, confidentiality and accountability when handling sensitive business, customer, product and intellectual-property information.
- Ability to work effectively in a rapidly evolving cybersecurity and technology environment, while maintaining focus on risk, compliance and operational priorities.

📌 Cyber Security Consultant (Maharashtra)
🏢 Syrma Johari Medtech
📍 Maharashtra

Reply to this offer

Impress this employer describing Your skills and abilities, fill out the form below and leave Your personal touch in the presentation letter.

Subscribe to this job alert:

Get the latest job offers by email for: cyber security consultant (maharashtra) / maharashtra

Subscribe to this job alert:

Get the latest job offers by email for: cyber security consultant (maharashtra) / maharashtra