Thermo Fisher Scientific

Senior Business Analyst – Cybersecurity & DevSecOps

Thermo Fisher Scientific Bengaluru, Karnataka, India

Biotechnology Research · 10,001+ employees

Yesterday
security Senior (5-10 yrs) Full-time India
Log in to apply, save this posting, or score it against your profile with AI.

About the role

The Senior Business Analyst will prioritize the cybersecurity operations backlog and translate security risks into actionable requirements for the DevSecOps team. They will also drive vulnerability remediation initiatives and ensure compliance through effective stakeholder coordination and metrics reporting.

What they look for

Cybersecurity DevSecOps Agile Backlog Management Vulnerability Management Risk Assessment Stakeholder Management Requirements Definition Security Operations Application Security Compliance SAFe CI/CD Pipelines Security Automation Data Analysis Problem-solving

Requirements

Candidates must have 6–10 years of experience in product ownership or business analysis within an Agile technology environment. A strong background in cybersecurity, DevSecOps, and vulnerability management is required, along with excellent communication and analytical skills.

Full description

Work Schedule

Standard (Mon-Fri)

Environmental Conditions

Office

Job Description

Job Description

We are looking for a Senior Business Analyst (6–10 years of experience) to join our DevSecOps Agile Release Train (ART).

In this role, you will connect cybersecurity priorities, operational needs, compliance requirements, and software delivery. You will work closely with the Product Security Architect, Security Tech Lead, Product Management, and other stakeholders to translate security needs into clear priorities and actionable work for the Cyber Operations team.

As a senior business analyst, you will own and prioritize the team's backlog and ensure the team focuses on work that delivers the highest value and strengthens our security posture.

What You Will Do

  • Own, maintain, and prioritize the cybersecurity operations team backlog based on security risk, business value, compliance needs, and dependencies.
  • Translate cybersecurity and operational needs into clear features, user stories, enablers, and acceptance criteria.
  • Drive initiatives related to vulnerability assessment and remediation
  • Define processes and remediation playbooks for cybersecurity issues, including third-party dependencies
  • Help development teams understand and remediate security findings
  • Define requirements for cybersecurity metrics, trend reporting, hygiene reports, and release readiness capabilities
  • Support the collection and delivery of security evidence required for audits and compliance
  • Participate in PI Planning, backlog refinement, Sprint Planning, reviews, retrospectives, PO Syncs, and Inspect & Adapt activities
  • Coordinate priorities and dependencies with Product Management, other Product Owners, Cybersecurity, and Engineering teams
  • Review and accept delivered work based on agreed acceptance criteria and Definition of Done.

Required Skills

  • 6–10 years of experience as a Product Owner, Business Analyst or in a comparable role in an Agile technology environment
  • Experience in Cybersecurity, DevSecOps, Security Operations, Application Security, or a related security domain
  • Understanding of vulnerability management, security risk, and remediation processes
  • Strong experience with backlog management, prioritization, requirements definition, user stories, and acceptance criteria
  • Experience working with software development or engineering teams
  • Ability to translate complex technical and business needs into clear, actionable requirements
  • Strong stakeholder management, communication, and influencing skills
  • Strong analytical and problem-solving skills
  • Ability to manage competing priorities and make decisions based on value, risk, urgency, and dependencies
  • Excellent written and verbal communication skills in English.

Desirable Skills

  • Experience working in a SAFe environment or Agile Release Train.
  • Familiarity with CI/CD pipelines, third-party dependency management, or security automation.
  • Experience with security metrics, compliance, or audit processes.
  • Experience working with globally distributed teams.

Similar roles