Cybersecurity Engineer

Clario

India

On-site

INR 1,800,000 - 4,000,000

Full time

12 days ago

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Competitive pay
Provident fund
Medical insurance
Remote work flexibility

Job summary

Clario, part of Thermo Fisher Scientific, seeks a hands-on Cybersecurity Engineer to strengthen product security and DevSecOps through penetration testing, threat modeling, and secure-by-design practices. You will work with Product, Engineering, Architecture, and DevOps to embed security across the SDLC and drive measurable security improvements.

The role emphasizes security automation, CI/CD integration, and collaboration with cross-functional teams in a dynamic environment.

Qualifications

  • Bachelor's degree in CS, Cybersecurity, or related field or equivalent experience.
  • 5+ years in Cybersecurity, Application/Product Security or related area.
  • Experience with manual and automated security testing of web apps, APIs, cloud environments.
  • Strong threat modeling and security architecture review skills (STRIDE/PASTA).
  • Proficiency in Python/Java/JavaScript/C#, PowerShell, Go or similar.

Responsibilities

  • Perform comprehensive penetration testing of web apps, APIs, cloud, and infra.
  • Lead threat modeling for new and existing products early in SDLC.
  • Conduct secure design and architecture reviews against industry standards.
  • Evaluate security controls and provide actionable remediation guidance.
  • Integrate security testing into CI/CD pipelines and automate checks.
  • Develop security tooling and automation to improve coverage and efficiency.
  • Collaborate with Product, Engineering, DevOps, and Architecture teams on security requirements.
  • Support vulnerability management, risk assessment, and verification of fixes.

Skills

Penetration testing
Threat modeling
Application security
Secure SDLC
DevSecOps
Security architecture

Education

Bachelor's degree in Computer Science or related

Tools

SAST
DAST
SCA
OWASP
Kubernetes
CI/CD tooling

Job description

The Cybersecurity Engineer is a hands-on technical role responsible for strengthening Clario’s product and enterprise security posture through proactive security assessments, threat modeling, and secure design practices. This individual will partner closely with engineering, architecture, DevOps, and product teams to identify, assess, and mitigate security risks throughout the Software Development Lifecycle (SDLC). The ideal candidate possesses deep expertise in penetration testing, threat modeling, application security, and secure development practices, with the ability to translate complex security findings into actionable remediation guidance. This role requires a security professional who can think like an attacker, validate security controls through manual and automated testing, and influence product teams to build resilient, secure solutions by design. In addition to conducting security assessments, the Cybersecurity Engineer will help mature Clario’s DevSecOps capabilities by integrating security validation, testing, and governance into development pipelines and engineering workflows. Success in this role requires strong technical skills, effective communication, and the ability to work collaboratively across the organization to drive measurable security improvements. Clario, part of Thermo Fisher Scientific, is seeking a highly skilled Cybersecurity Engineer to strengthen our Product Security and DevSecOps capabilities through a combination of penetration testing, threat modeling, secure design reviews, and security automation. In this role, you will conduct comprehensive security assessments across web applications, APIs, cloud environments, and supporting infrastructure to identify vulnerabilities and validate security controls. You will partner closely with Product, Engineering, Architecture, and DevOps teams to perform threat modeling exercises, review security architectures, and embed security‑by‑design principles throughout the Software Development Lifecycle (SDLC). The ideal candidate will have strong expertise in application security, threat modeling frameworks such as STRIDE or PASTA, secure development practices, and DevSecOps methodologies, with hands‑on experience integrating security testing into CI/CD pipelines.

What We Offer
  • Competitive compensation
  • Provident fund and medical insurance
  • Engaging employee programs and local events
  • Modern office spaces and remote work flexibility
What You’ll Be Doing
  • Conduct comprehensive penetration testing of web applications, APIs, cloud environments, and supporting infrastructure to identify security vulnerabilities and validate security controls.
  • Lead threat modeling exercises for new and existing products, partnering with engineering and architecture teams to identify risks, attack paths, and appropriate mitigations early in the SDLC.
  • Perform secure design and architecture reviews to ensure products are built with security‑by‑design principles and aligned with industry standards and best practices.
  • Evaluate application, cloud, and infrastructure security controls and provide actionable recommendations to reduce risk and improve overall security posture.
  • Willingness to work in European Shift (1pm to 10pm)
  • Work closely with development teams to prioritize, track, and remediate security findings while promoting secure coding practices.
  • Integrate security testing and validation into CI/CD pipelines, enabling automated security checks and continuous risk identification throughout the development lifecycle.
  • Develop and maintain security tooling, scripts, and automation capabilities that improve the efficiency and effectiveness of security assessments.
  • Collaborate with Product, Engineering, DevOps, and Architecture teams to embed security requirements into product planning, design, development, and deployment processes.
  • Support vulnerability management activities, including validation, risk assessment, remediation guidance, and verification of fixes.
  • Contribute to the development and maintenance of security standards, secure development guidelines, and product security processes.
  • Stay current on emerging threats, attack techniques, vulnerabilities, and security technologies, applying that knowledge to improve Clario's security capabilities.
  • Provide technical guidance and mentorship to engineering teams on secure design, threat mitigation, and security best practices.
  • Assist with security audits, compliance initiatives, and evidence collection activities related to product and application security controls.
  • Drive continuous improvement of Clario's Product Security and DevSecOps programs through innovation, automation, and the adoption of industry-leading practices.Time Allocation (Typical) 30–55% Product Security Engineering (Threat Modeling, Secure Design Reviews, Security Architecture Assessments, Developer Enablement) 30–55% Penetration Testing and Security Validation Activities 10–15% Security Automation, DevSecOps Integration, Governance, and Process Improvement
What We Look For

Bachelor's degree in Computer Science, Cybersecurity, Information Security, Software Engineering, or a related technical discipline, or equivalent practical experience. 5+ years of experience in Cybersecurity, Application Security, Product Security, Security Engineering, or a related field. Demonstrated experience performing manual and automated penetration testing of web applications, APIs, cloud environments, and supporting infrastructure. Strong experience conducting threat modeling and security architecture reviews using established methodologies such as STRIDE, PASTA, ATT&CK, or equivalent frameworks. Solid understanding of secure software development practices, common attack techniques, and security vulnerabilities, including the OWASP Top 10 and API Security Top 10. Experience identifying, validating, and communicating security risks to technical and non-technical stakeholders. Proficiency in one or more programming or scripting languages such as Python, Java, JavaScript, C#, PowerShell, Go, or similar languages. Experience working within Agile development environments and integrating security practices into the SDLC. Strong understanding of DevSecOps principles and experience integrating security tools into CI/CD pipelines. Excellent analytical, problem-solving, communication, and collaboration skills. Ability to independently drive security initiatives while partnering effectively with Engineering, Product, Architecture, and Operations teams. Experience with cloud security assessments and securing environments in AWS, Azure, or Google Cloud Platform. Experience with modern application architectures including microservices, APIs, containers, Kubernetes, and serverless technologies. Familiarity with Static Application Security Testing (SAST), Dynamic Application Security Testing (DAST), Software Composition Analysis (SCA), Container Security, and Infrastructure-as-Code security tools. Experience developing security automation, custom security tooling, or pipeline integrations to improve security coverage and efficiency. Knowledge of secure architecture patterns, identity and access management, cryptography, and zero‑trust security concepts. Experience supporting regulatory, compliance, or audit requirements in highly regulated industries such as healthcare, life sciences, or financial services. Security certifications such as: OSCP (Offensive Security Certified Professional) OSWE (Offensive Security Web Expert) GWAPT (GIAC Web Application Penetration Tester) GWEB (GIAC Web Application Defender) CISSP (Certified Information Systems Security Professional) CCSP (Certified Cloud Security Professional) Azure, AWS, or GCP Security Certifications

At Clario

Clario, a part of Thermo Fisher Scientific, our purpose is to transform lives by unlocking better evidence. Whether you're advancing clinical science, building innovative technology, or supporting our global teams, your work helps bring life‑changing therapies to patients faster. The Department Head has the discretion to hire personnel with a combination of experience and education, which may vary from the above listed qualifications. EEO Statement Clario is an equal opportunity employer. Clario evaluates qualified applicants without regard to race, color, religion, gender, national origin, age, sexual orientation, gender identity or expression, protected veteran status, disability/handicap status, or any other legally protected characteristic. Clario Privacy Policy Clario is a leading provider of endpoint data solutions to the clinical trials industry, generating high-quality clinical evidence for life sciences companies. We offer comprehensive evidence generation solutions that combine medical imaging, eCOA, precision motion, cardiac solutions and respiratory endpoints. For more than 50 years, Clario has delivered deep scientific expertise and broad endpoint technologies to the clinical trials industry. Our endpoint data solutions have supported over 30,000 clinical trials in more than 100 countries. Our global team of science, technology, and operational experts have supported over 70% of all FDA drug approvals since 2015.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Software Quality Engineer
Software Quality Engineer

Clario • India

On-site
INR 600,000 - 900,000
Competitive pay
Medical insurance
Remote work flexibility
+1
Software Quality Engineer
Software Quality Engineer

US Biomedical Systems India Pvt Ltd. • India

Hybrid
INR 900,000 - 1,300,000
Competitive pay and incentives
Provident fund and medical insurance
Engaging employee programs and local‑s
+2
Software Quality Engineer II
Software Quality Engineer II

Clario • India

Hybrid
INR 1,200,000 - 2,500,000
Competitive pay
Provident fund
Medical insurance
+2
Talent Development Specialist
Talent Development Specialist

Clario • Bengaluru

Hybrid
INR 600,000 - 1,100,000
Competitive pay
Provident fund
Medical insurance
+2
Talent Development Specialist
Talent Development Specialist

US Biomedical Systems India Pvt Ltd. • Bengaluru

Hybrid
INR 800,000 - 1,500,000
Provident fund
Medical insurance
Remote work flexibility
+1
Quality Control Analyst I
Quality Control Analyst I

Clario • Bengaluru

On-site
INR 600,000 - 800,000
Quality Control Analyst I
Quality Control Analyst I

US Biomedical Systems India Pvt Ltd. • Bengaluru

On-site
INR 450,000 - 700,000
Project Manager, Respiratory
Project Manager, Respiratory

Clario • Bengaluru

Hybrid
INR 1,000,000 - 1,600,000
Competitive pay
Provident fund
Employee programs
+2
Software Quality Engineer
Software Quality Engineer

clarioclinical • India

Hybrid
INR 700,000 - 1,000,000
Provident fund
Medical insurance
Remote work flexibility
+2
Associate Software Quality Engineer
Associate Software Quality Engineer

Clario • India

Hybrid
INR 350,000 - 520,000
Competitive pay
Provident fund
Remote work flexibility
+1