Staff Product Security Engineer

Posted 6 Days Ago
Be an Early Applicant
Bengaluru, Bengaluru Urban, Karnataka, IND
In-Office
Senior level
Artificial Intelligence • Healthtech • Analytics • Biotech
The Role
Lead product security for Patient Care Solutions by representing security/privacy throughout the product lifecycle: threat modeling, SBOM generation, vulnerability management, penetration testing, design of security controls, regulatory compliance, and collaboration with product, program, and quality teams to mitigate risks and ensure QMS alignment.
Summary Generated by Built In
Job Description SummaryJoin a dynamic team that’s transforming how the Patient Care Solutions Products and Solutions at GE HealthCare are architected, secured and delivered to our customers. As a Staff Product Security Engineer you’ll be working on products and solutions that provide clinical excellence at the point of care, with a focus on representing Security/Privacy on the product development team. This position requires understanding of secure product development, system design, post-market security assessments and strong analysis/problem-solving skills.
This role will develop deep product domain and customer use environment knowledge of the product’s clinical functionality, expected operating environment and interoperability to accurately determine privacy and security risks. Join the Patient Care Solutions Transformation at GE HealthCare!

Job Description

Responsibilities:

  • Represent the Security/Privacy needs of the product design and development teams.  Including security/privacy requirements capture, consulting development activities to ensure compliance and secure product testing.
  • Work with the Product Security Leader (PSL) to support the product team with process expertise for the GEHC Product Cybersecurity Standard and lifecycle management.
  • Lead threat modeling sessions to identify security concerns within the products and solutions.  Develop methods to implement security controls based on the system threat model.
  • Own the Cybersecurity Management Plan, including the identification, assessment, reporting and mitigation plans for product vulnerabilities.  Collaborate with Program Managers, functional leadership and program teams on program scope and priority to address vulnerabilities in a timely manner.
  • Generate and maintain the Software Bill of Materials (SBOM).  Assess product components and SBOMs integrated into the product.
  • Have a complete understanding of the various interdependency and limitations as they refer to security controls within the system.
  • Scope and participate in penetration tests, vulnerability scanning and product security risk assessments including remediation planning and closure.
  • Create Design Engineering Privacy and Security (DEPS) artifacts for privacy and security activities throughout the product lifecycle, from initial concept through end-of-life.
  • Maintain effective quality management system (QMS) compliance with GE HealthCare Quality policies.

Qualifications/Requirements:

  • Bachelor's Degree in a relevant field (e.g. Computer Engineering, Computer Science, Information Security) or in a STEM major (Science, Technology, Engineering, or Math)
  • 6+ years of product or systems experience with at least 5 years of application security
  • Working knowledge of regulatory standards and compliance frameworks (e.g., NIST CSF/800-53, ISO27001, SOC2, HIPAA, HITRUST and GDPR).
  • Understanding of secure coding principles, such as the OWASP Top Ten.
  • Demonstrated technical leadership capability working on a product development team
  • Demonstrated ability to act as a leader-among-peers in a global environment
  • Demonstrated ability to work with design scrum teams on the design & implementation of security controls
  • Self-starter, energizing, results oriented and able to multi-task
  • Effective oral and written communication skills

Desired:

  • Master’s degree in STEM with a focus on application security.
  • Experience working with application security tools such as Microsoft Threat Modelling Tool, Black Duck, Syft, Burpsuite, Grype, or similar tools.
  • Experience with penetration testing and ethical hacking concepts (red team/blue team).
  • Experience in Identity management and identity federation tools. (SAML, Oauth, SCIM, XACML).
  • Experience working in a medical device regulated environment, including FDA.
  • Strong technical understanding of various network protocols and strategies to secure them
  • Strong technical understanding of various network services and APIs (eg. network proxies, API gateways)
  • Working understanding of enterprise-grade software to embedded software technology
  • Security certification(s) not limited to CISSP/CISM, CSSLP, CEH, OCP are a plus.

Additional Information

Relocation Assistance Provided: No

Skills Required

  • Bachelor's degree in Computer Engineering, Computer Science, Information Security, or STEM
  • 6+ years product or systems experience with at least 5 years of application security
  • Working knowledge of regulatory standards and compliance frameworks (NIST CSF/800-53, ISO27001, SOC2, HIPAA, HITRUST, GDPR)
  • Understanding of secure coding principles (e.g., OWASP Top Ten)
  • Demonstrated technical leadership capability on a product development team
  • Ability to act as a leader among peers in a global environment
  • Ability to work with design scrum teams on design and implementation of security controls
  • Self-starter, results oriented, able to multi-task
  • Effective oral and written communication skills
  • Master's degree in STEM with focus on application security
  • Experience with application security tools (Microsoft Threat Modeling Tool, Black Duck, Syft, BurpSuite, Grype)
  • Experience with penetration testing and ethical hacking concepts (red team/blue team)
  • Experience in identity management and federation (SAML, OAuth, SCIM, XACML)
  • Experience working in a medical device regulated environment, including FDA
  • Strong understanding of network protocols, network services, proxies, and API gateways
  • Working understanding of enterprise-grade to embedded software technology
  • Security certifications (CISSP, CISM, CSSLP, CEH, OCP)

GE Healthcare Compensation & Benefits Highlights

The following summarizes recurring compensation and benefits themes identified from responses generated by popular LLMs to common candidate questions about GE Healthcare and has not been reviewed or approved by GE Healthcare.

  • Healthcare Strength Healthcare coverage is portrayed as comprehensive, including medical, dental, and vision options with HSA-eligible choices and preventive care coverage. Mental health and well-being support programs are also emphasized as part of the overall package.
  • Retirement Support Retirement support is described as meaningful, with a 401(k) match and additional programs such as student-loan matching in some descriptions. Legacy pension and retiree medical obligations for certain closed groups also signal continued support for long-tenured populations.
  • Strong & Reliable Incentives Variable and role-linked earning opportunities appear attractive in some job families, including high on-target earnings potential in certain sales roles. Additional role-based perks like company cars and travel-related reimbursements further increase the perceived value of total rewards in those positions.

GE Healthcare Insights

Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
HQ: Chicago, IL
50,282 Employees
Year Founded: 1892

What We Do

Every day millions of people feel the impact of our intelligent devices, advanced analytics and artificial intelligence. As a leading global medical technology and digital solutions innovator, GE Healthcare enables clinicians to make faster, more informed decisions through intelligent devices, data analytics, applications and services, supported by its Edison intelligence platform. With over 100 years of healthcare industry experience and around 50,000 employees globally, the company operates at the center of an ecosystem working toward precision health, digitizing healthcare, helping drive productivity and improve outcomes for patients, providers, health systems and researchers around the world. We embrace a culture of respect, transparency, integrity and diversity.

Similar Jobs

In-Office
Bangalore, Bengaluru Urban, Karnataka, IND
57802 Employees

Wells Fargo Logo Wells Fargo

Consultant

Fintech • Financial Services
Hybrid
Bengaluru, Bengaluru Urban, Karnataka, IND
205000 Employees

Wells Fargo Logo Wells Fargo

Consultant

Fintech • Financial Services
Hybrid
Bengaluru, Bengaluru Urban, Karnataka, IND
205000 Employees

Wells Fargo Logo Wells Fargo

Engineering Manager

Fintech • Financial Services
Hybrid
Bengaluru, Bengaluru Urban, Karnataka, IND
205000 Employees

Similar Companies Hiring

Legora Thumbnail
Artificial Intelligence • Legal Tech • Software
New York, New York
700 Employees
Hanover Park Thumbnail
Artificial Intelligence • Fintech • Software • Financial Services
New York, New York
42 Employees
Onshore Thumbnail
Artificial Intelligence • Fintech • Software • Financial Services
New York, New York
60 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account