Siemens Healthineers

Lead Cyber Security Engineer

Siemens Healthineers Bengaluru, Karnataka, India

Hospitals and Health Care · 10,001+ employees

Yesterday
security Principal (10+ yrs) Full-time India
Create a free account to apply — email only, no card. You can also save this posting or score it against your profile with AI.

About the role

The Lead Cyber Security Engineer conducts risk assessments, threat modeling, and vulnerability analyses across product development programs. They also provide security expertise, support incident response, and develop security guidelines to ensure compliance with regulatory standards.

What they look for

Cybersecurity Threat modeling Risk assessment Vulnerability analysis Security architecture TCP/IP TLS PKI Python PowerShell Bash Secure Development Lifecycle IEC 62443 GDPR ISO 27001 Kubernetes

Requirements

Candidates must have over 8 years of product security experience and strong knowledge of security architecture, networking, and secure development practices. Proficiency in scripting languages and familiarity with cybersecurity regulations like GDPR and ISO 27001 are required.

Full description

Job Requirements Cybersecurity Engineer

 

Summary:

The Cybersecurity Systems Engineer (CYSE) is responsible for conducting cybersecurity risk assessments, performing threat modeling, managing security requirements, executing vulnerability analyses, and supporting cybersecurity compliance activities across product development programs. The role contributes significantly to TrueBeam platform initiatives while providing cybersecurity engineering support to other product platforms, ensuring consistent implementation of cybersecurity practices and requirements across the organization.

 

Experience:

  • 8+ years of product security experience

Mandatory Expertise

  • Security architecture and design
  • Strong knowledge of key security concepts – TCP/IP fundamentals, TLS, SSH, HTTPS, PKI, Certificate lifecycle
  • Windows operating systems and networking
  • Expertise in any languages such as Python, PowerShell, or Bash or .net
  • Drive vulnerability assessment, CVE impact analysis and remediation activities across the product lifecycle.
  • Experience working with Secure Development Lifecycle (SDL) practices including threat modelling, secure code review, static analysis, dependency management and vulnerability remediation
  • Strong understanding of cybersecurity regulations, standards (IEC 62443, IEC 62351) and its impact of products and regulatory frameworks such as GDPR, ISO 27001, NIS2 and CRA.
  • Good documentation and writing skills

 Preferred knowledge

  • Linux operating systems.
  • Docker/container fundamentals
  • Container image vulnerabilities and Hardening, Kubernetes security fundamentals
  • Container networking and secrets management, Basic cloud security concepts
  • Understanding of Linux/container-based product architectures
  • Capability to develop security tools like custom scanner or log analyzer

Areas of Responsibility:

  • Support project teams in executing security activities throughout the development lifecycle, project management processes, service delivery, and product/solution releases
  • Participate in incident response activities and escalation processes
  • Conduct threat and risk analysis workshops
  • Provide expertise and support for security tools used by product teams
  • Deliver product and solution security training and develop training materials
  • Develop and maintain security guidelines for product development teams
  • Capture product and solution security lessons learned and contribute to continuous improvement initiatives, including guideline updates.
  • Stay current with emerging security threats and technologies
  • Support multiple projects simultaneously and dedicate the majority of working time to this function

Similar roles