Stryker

Senior Security Engineer (Security by Design)

Stryker Gurugram, Haryana, India

Medical Equipment Manufacturing · 10,001+ employees

20 h ago
security Mid (2-5 yrs) Full-time India
Create a free account to apply — email only, no card. You can also save this posting or score it against your profile with AI.

About the role

You will lead cybersecurity risk analysis, threat modeling, and the development of mitigation strategies for medical products. Additionally, you will manage incident response, perform penetration testing, and ensure compliance with industry standards like HIPAA and GDPR.

What they look for

Cybersecurity Threat Modeling Risk Analysis Penetration Testing Vulnerability Assessment Systems Hardening Incident Response Python PowerShell Ruby Compliance Medical Device Security Embedded Systems SDLC Data Security Malware Analysis

Requirements

Candidates must have a bachelor's degree in Software Engineering or Computer Science and at least 4 years of relevant work experience. Proficiency in security frameworks, threat modeling, and experience securing medical or embedded devices is required.

Full description

Work Flexibility: Hybrid

What you will do ​

  • You will lead and manage cybersecurity risk analysis and threat modeling and develop mitigation strategies to develop secure medical products.
  • You will work closely with cross-functional teams, including Quality, Regulatory, and Marketing, in driving alignment around product Cybersecurity, HIPAA, and GDPR compliance.
  • You will lead in all product hardware and software security facets, including systems hardening, automated and manual penetration testing, automated vulnerability scanning for compliance, and issue remediation.
  • You will develop and implement security policies and procedures to ensure compliance with industry standards.
  • You will integrate automated security testing into all phases of SDLC.
  • You will automate routine tasks and extract valuable data using various scripting languages like PowerShell, Ruby, or Python.
  • You will take a lead in incident response, V&E assessments and manage the resolution of security incidents.
  • You will evaluate emerging security technologies and recommend their adoption to improve the organization’s security posture.

What you need:

Required Qualifications:

  • Bachelor's degree in Software Engineering/ Computer Science or related discipline & 4+ years of work experience
  • Experience with security requirements, data security, malware analysis, vulnerability assessment, and penetration testing using off-the-shelf tools and techniques is preferred.
  • Understanding one or more security standards/frameworks like NIST 800-53, IEC80001-2-8, IEC 27002, ISO 27799, IEC 15408-2, and IEC 62443-3-3.
  • Experience in securing medical devices or embedded devices.
  • Understanding quality standards like IEC 62304, IEC 60601, and 21CRF 820.
  • Experience with threat modeling and risk assessment.
  • Security certifications such as CISSP-ISSAP, CCSP, OSCP or CEH are a plus.

Preferred Qualifications:

  • Security certifications such as CISSP-ISSAP, CCSP, OSCP or CEH are a plusInsert detailed job description here.

Travel Percentage: 10%

Similar roles