Senior Security Engineer (Security by Design)
Stryker Gurugram, Haryana, India
Medical Equipment Manufacturing · 10,001+ employees
About the role
You will lead cybersecurity risk analysis, threat modeling, and the development of mitigation strategies for medical products. Additionally, you will manage incident response, perform penetration testing, and ensure compliance with industry standards like HIPAA and GDPR.
What they look for
Requirements
Candidates must have a bachelor's degree in Software Engineering or Computer Science and at least 4 years of relevant work experience. Proficiency in security frameworks, threat modeling, and experience securing medical or embedded devices is required.
Full description
Work Flexibility: Hybrid
What you will do
- You will lead and manage cybersecurity risk analysis and threat modeling and develop mitigation strategies to develop secure medical products.
- You will work closely with cross-functional teams, including Quality, Regulatory, and Marketing, in driving alignment around product Cybersecurity, HIPAA, and GDPR compliance.
- You will lead in all product hardware and software security facets, including systems hardening, automated and manual penetration testing, automated vulnerability scanning for compliance, and issue remediation.
- You will develop and implement security policies and procedures to ensure compliance with industry standards.
- You will integrate automated security testing into all phases of SDLC.
- You will automate routine tasks and extract valuable data using various scripting languages like PowerShell, Ruby, or Python.
- You will take a lead in incident response, V&E assessments and manage the resolution of security incidents.
- You will evaluate emerging security technologies and recommend their adoption to improve the organization’s security posture.
What you need:
Required Qualifications:
- Bachelor's degree in Software Engineering/ Computer Science or related discipline & 4+ years of work experience
- Experience with security requirements, data security, malware analysis, vulnerability assessment, and penetration testing using off-the-shelf tools and techniques is preferred.
- Understanding one or more security standards/frameworks like NIST 800-53, IEC80001-2-8, IEC 27002, ISO 27799, IEC 15408-2, and IEC 62443-3-3.
- Experience in securing medical devices or embedded devices.
- Understanding quality standards like IEC 62304, IEC 60601, and 21CRF 820.
- Experience with threat modeling and risk assessment.
- Security certifications such as CISSP-ISSAP, CCSP, OSCP or CEH are a plus.
Preferred Qualifications:
- Security certifications such as CISSP-ISSAP, CCSP, OSCP or CEH are a plusInsert detailed job description here.
Travel Percentage: 10%
Similar roles
-
Interim Cybersecurity & IT Risk Lead Consultant
Fermi Inc Dallas, Georgia, United States
-
Cybersecurity Architect
North Suburban Family Physicians Bloomington, Minnesota, United States · $141K–$211K/yr
-
IT & Security Engineer
Albedo Broomfield, Colorado, United States · $107K–$115K/yr
-
Cybersecurity Engineer
TRIDENT SYSTEMS LLC Fairfax County, Virginia, United States · $70K–$101K/yr
-
Cybersecurity Administrator
Aleut Federal San Antonio, Texas, United States · $91K–$97K/yr
-
Co-op - Cybersecurity, Engineering & Operations
Chemtrade North Vancouver, British Columbia, Canada · CA$40K–CA$46K/yr