Privacy & Security Representative

Reposted 4 Days Ago
Be an Early Applicant
Bengaluru, Bengaluru Urban, Karnataka
In-Office
Senior level
Artificial Intelligence • Healthtech • Analytics • Biotech
The Role
Responsible for data movement reviews, cybersecurity risk assessments, compliance with regulatory standards, and technical expertise for product security features. Collaborate with teams on vulnerability management and customer concerns.
Summary Generated by Built In
Job Description SummaryResponsible for data movement reviews, data collection and analysis, and identification of anomalous patterns of data. Support in the detection, design, and testing analytic frameworks, processes, procedures and controls. Assisting in the planning, preparing, and hunting for cyber incidents stemming from internal and external threat actors.
GE Healthcare is a leading global medical technology and digital solutions innovator. Our mission is to improve lives in the moments that matter. Unlock your ambition, turn ideas into world-changing realities, and join an organization where every voice makes a difference, and every difference builds a healthier world.

Job Description

Job Summary

As part of the Imaging System Software Platform team at GE Healthcare, PSR is the cybersecurity focal point for secure product development and maintenance of released product.  The PSR is an experienced member of the product engineering team with influence to drive product privacy and cybersecurity features and enhancements.  The PSR must have deep product knowledge to ensure the clinical functionality, expected operating environment, and interoperability to accurately determine a product’s privacy and security risks.

Job Description

Roles and Responsibilities

In this role, you will:

  • Provide privacy and security technical expertise in support of the product team throughout product development, design change, and life-cycle management.

  • Work with the Product Security Leader (PSL) to support the product team with process expertise for the GEHC-GE Healthcare Product Cybersecurity Standard and life-cycle management.

  • Product cybersecurity development responsibilities:

    • Assess the privacy and cybersecurity state of the product and define product roadmap features/enhancements with stakeholder approval.

    • Responsible for security architecture and coordination of product development for cybersecurity features and enhancements.

    • Assess product components and SBoM integrated into the product.

    • Perform defect management for cybersecurity issues.

    • Identify operational responsibilities and adherence to cloud standards for cloud- based products.

    • Responsible for Product and Security Manual and MDS2 documentation.

  • In coordination with the PSL, own and deliver GEHC Product Cybersecurity Standard artifacts, which includes:

    • Design input activities to identify, evaluate, roadmap, and drive cybersecurity and privacy features and enhancements within product development programs.

    • Create Design Engineering Privacy and Security (DEPS) artifacts for privacy and security risk assessments to engage in domain-specific product threat modelling, attack surface analysis, risk management and reduction.

    • Coordinates with the PSL to support the product team in scheduling and performing vulnerability scans and cybersecurity assessments.

    • Lead product Security Technical Design Reviews

    • Along with the product LSD-Lead System Designer, responsible for the GEHC Product Cybersecurity Standard compliance and other pertinent standards and process.

  • The released products shall be in compliance to required regulatory standards & compliance (like FDA, HIPPA, GDPR etc)

  • Works with the GEHC Product Security team and QARA-Quality Assurance & Regulatory Assurance on released product life cycle, including:

    • Participate in post-market product vulnerability monitoring.

    • Participate as an Subject Matter Expert to determine product vulnerability impact, investigation, and risk assessment.

    • Responsible for product vulnerability mitigation and design change.

    • Responsible for GEHC vulnerability tool update to ensure accurate customer communication.

  • Address customer and Sales RFP privacy and security feedback/questions.

  • Provide technical expertise on customer concerns, complaints, and CSO escalations.

  • Create/Maintain responsible product records within GEHC product cybersecurity tools.

Education Qualification:

  • Bachelor's Degree in Computer Science or “STEM” Majors (Science, Technology, Engineering and Maths)

Required Characteristics:

  • 7+ years full-time information security experience with emphasis on technical assessment (system/web application vulnerability assessment, penetration testing, white-box secure code analysis, etc.) and security architecture (design of security controls, secure system design, understanding of identity and authentication management, etc.)

  • Experience in working with Product sector environment.

  • Globally recognized Cyber Security Certifications (Advanced/Expert Level).

  • Sound understanding of security technologies/techniques like Cryptography, Algorithms, Public key Infrastructure (PKI) Certificate Authority (CA), Hardware/embedded authentication, OAuth, 2-factor authentication, white-box code analysis.

  • Information security experience with emphasis on technical assessment (system/web application vulnerability assessment, penetration testing, white-box code analysis, etc.) and security architecture (design of security controls, secure system design, understanding of identity and authentication management, etc.)

  • Experience with a range of security tools related to SAST (Static Application Security Assessment), DAST (Dynamic Application Security Assessment), Vulnerability Management, SCA (Software Composition Analysis), Penetration Testing, Threat Modelling Tool etc.

  • The PSR Shall be capable of not only finding risks/issues, but shall also suggest the best route to remediation, knowing the compensatory controls & guide product team for its closure.

  • Firm with knowledge of OWASP, CVSS, FIPS 140-2/140-3 and DoD RMF.

Good To Have Skills:

  • Experience in Micro Services using RESTful frameworks.

  • Experience in Healthcare domain.

  • Penetration Testing in Web Application, Thick Client, Mobile Application, REST/SOAP

  • Infrastructure Penetration Testing

  • Experience in Red Teaming Activities (add on)

  • Recognition for CVE or Wall-of-Fame though Bug-Bounty (add on)

Inclusion and Diversity:

GE Healthcare is an Equal Opportunity Employer where inclusion matters. Employment decisions are made without regard to race, colour, religion, national or ethnic origin, sex, sexual orientation, gender identity or expression, age, disability, protected veteran status or other characteristics protected by law.

We expect all employees to live and breathe our behaviours: to act with humility and build trust; lead with transparency; deliver with focus, and drive ownership – always with unyielding integrity.

Our total rewards are designed to unlock your ambition by giving you the boost and flexibility you need to turn your ideas into world-changing realities. Our salary and benefits are everything you’d expect from an organization with global strength and scale, and you’ll be surrounded by career opportunities in a culture that fosters care, collaboration and support.

#LMP2

Additional Information

Relocation Assistance Provided: Yes

Top Skills

Algorithms
Cryptography
Dast
Oauth
Penetration Testing
Public Key Infrastructure (Pki)
Sast
Software Composition Analysis
Vulnerability Management
Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
Chicago, IL
50,282 Employees
Year Founded: 1892

What We Do

Every day millions of people feel the impact of our intelligent devices, advanced analytics and artificial intelligence.

As a leading global medical technology and digital solutions innovator, GE Healthcare enables clinicians to make faster, more informed decisions through intelligent devices, data analytics, applications and services, supported by its Edison intelligence platform.

With over 100 years of healthcare industry experience and around 50,000 employees globally, the company operates at the center of an ecosystem working toward precision health, digitizing healthcare, helping drive productivity and improve outcomes for patients, providers, health systems and researchers around the world.

We embrace a culture of respect, transparency, integrity and diversity.

Similar Jobs

CrowdStrike Logo CrowdStrike

Senior Software Engineer

Cloud • Computer Vision • Information Technology • Sales • Security • Cybersecurity
Remote or Hybrid
16 Locations
10000 Employees

CrowdStrike Logo CrowdStrike

Senior Software Engineer

Cloud • Computer Vision • Information Technology • Sales • Security • Cybersecurity
Remote or Hybrid
KA, IND
10000 Employees

CrowdStrike Logo CrowdStrike

Engineering Manager

Cloud • Computer Vision • Information Technology • Sales • Security • Cybersecurity
Remote or Hybrid
18 Locations
10000 Employees

PayPal Logo PayPal

Manager, Data Science

Fintech • Payments
In-Office or Remote
2 Locations
34450 Employees

Similar Companies Hiring

LayerOne Thumbnail
Software • Information Technology • Artificial Intelligence
New York, NY
15 Employees
Scotch Thumbnail
Software • Retail • Payments • Fintech • eCommerce • Artificial Intelligence • Analytics
US
25 Employees
Idler Thumbnail
Artificial Intelligence
San Francisco, California
6 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account