Staff Product Security Engineer
Stryker Careers · Gurugram, India
Job description
Work Flexibility: Hybrid or Onsite Who we want: We seek Product Security engineers who can help us design cyber secure medical devices and applications. What you will do: As a Product Cybersecurity Engineer, you will participate in project planning, product cybersecurity risk analysis, and risk mitigation strategies. You will lead various product cybersecurity tasks and activities established by product design controls and SDLC procedures. You will be involved in all facets of the robotics and enabling technology product development life cycle. Technical Responsibilities: You will perform cybersecurity risk analysis and threat modeling and develop mitigation strategies. You will work closely with cross-functional teams, including Quality, Regulatory, and Marketing, in driving alignment around product Cybersecurity and HIPAA compliance. You will provide input to project management on scheduling, milestone achievement, and project challenges. You will participate in all product hardware and software security facets, including systems hardening, automated and manual penetration testing, automated vulnerability scanning for compliance, and issue remediation. To identify security flaws, you will perform manual and automated code reviews for complex embedded and clinical application software. You will develop and implement security policies and procedures to ensure compliance with industry standards. You will integrate automated security testing into all phases of SDLC. You will automate routine tasks and extract valuable data using various scripting languages like PowerShell, Ruby, or Python. You will research and implement best practices in the product cybersecurity architecture around security systems, including improper access control, code injection, information exposure, firewalls, and multi-factor authentication. You will support cybersecurity documentation requests from legal and sales teams as needed. You will participate in incident response, V&E assessments and manage the resolution of security incidents. Minimum Qualifications (Required): Bachelor's degree in Software Engineering/ Computer Science or related discipline & 6+ years of work experience Preferred Qualifications (Strongly desired): Experience with security requirements, data security, malware analysis, vulnerability assessment, and penetration testing using off-the-shelf tools and techniques is preferred. Understanding one or more security standards/frameworks like NIST 800-53, IEC80001-2-8, IEC 27002, ISO 27799, IEC 15408-2, and IEC 62443-3-3. Solid understanding of Linux operating systems. Experience in securing medical devices or embedded devices. Understanding of networking concepts. Understanding quality standards like IEC 62304, IEC 60601, and 21CRF 820. Experience with threat modeling and risk assessment. Security certifications such as CISSP, CSSLP, or CISM are a plus. Travel Percentage: 10%
Verified and listed by ActiveJobs. Applications are made directly on Stryker Careers's own career page — we never sit in the middle.