An application made for this job — a tailored resume and cover letter that speak straight to the posting.
Smith+ Nephew is seeking a Product Cybersecurity Engineer to design and implement security tooling across the product lifecycle. You will perform threat modeling, SAST/DAST and SBOM activities, and drive vulnerability response in a dynamic medical technology environment.
The role requires 4+ years of hands-on cybersecurity experience, with a view to strengthening product security controls and collaborating with cross-functional teams. Hybrid work from Pune, India, with UK shift timings.
Life Unlimited. At Smith+ Nephew, we design and manufacture technology that takes the limits off living. We're on the lookout for an individual who is ready to make an impact in medical equipment industry. If you're eager to be part of a dynamic environment that fosters growth and collaboration, look no further. Explore our latest job opening for Product Security Engineer role and you will as Product Cybersecurity Engineer focus on product security tooling, will provide hands on cybersecurity tool engineering in support of the Product Security team with the goal of ensuring Smith + Nephew products and their data is secure and resilient to cybersecurity threats.
Your will collaborate with a diverse cohort of internal stakeholders to design, engineer, and ensure implementation of security tools that are utilized through the entire product lifecycle (e.g. threat model, Static Application Security Testing, Dynamic Application Security Testing, Software Composition Analysis). You will be responsible for running security scans (e.g. Static Application Security Testing, Dynamic Application Security Testing, Software Composition Analysis) and support the creation of Software Bill of Materials (SBOMs) based on an understanding of the products and the tools.
Education: Bachelor's or equivalent experience or Master’s degree in Computer Science or Information Technology. Licenses/Certifications: Current CISM, CISSP, CRISC, or similar certification preferred. Experience: Minimum 4+ years of experience in hands-on cybersecurity experience. Strong understanding of mitigating security controls. Vulnerability Management, Penetration Testing, Code Security. Good to have - FDA and other medical device regulators experience. Knowledge of cyber security standard frameworks such as HIPAA, FDA, ISO 27001/2, NIST CSF, and OWASP. Understanding of network infrastructure, including firewalls, web proxy and/or email architecture- particularly as they apply in a mitigating control functionality. Experience with different cloud computing platforms and the cloud security framework. Ability to design, recommend, plan, guide, and support implementation of innovative security solutions. Understand the current Medical Device market, including what customers want to see with regards to product security. Understanding of back-channels typically used by threat actors for malicious activity. Understanding of different connectivity protocols and any risks involved with them. Superb communication, collaboration, and relationship building and collaborator engagement skills. Experience in being able to manage and prioritize multiple tasks in an effective manner. Ability to work independently and proactively without daily direction.
Working from Office for 2 days - Hybrid - Kharadi, Pune. Shift Timings - UK shift (12:30 PM to 9:30 PM IST).
You. Unlimited.
We believe in crafting the greatest good for society. Our strongest investments are in our people and the patients we serve. Inclusion + Belonging - Committed to Welcoming, Celebrating and Thriving. Learn more about our Employee Inclusion Groups on our website https://www.smith-nephew.com/
Follow us on LinkedIn to see how we support and empower our employees and patients every day. Check us out on Glassdoor for a glimpse behind the scenes and a sneak peek into You. Unlimited., life, culture, and benefits at S+N. Explore our website and learn more about our mission, our team, and the opportunities we offer.
Smith+ Nephew is a global medical technology company. We design and manufacture technology that takes the limits off living. We support healthcare professionals to return their patients to health and mobility, helping them to perform at their fullest potential. From our first employee and founder, T.J. Smith, to our team today, it’s our people who make Smith+ Nephew a unique place. Yes, we love to innovate and develop exciting technologies, and we offer competitive salaries and progressive benefits. But it’s our culture - of Care, Collaboration and Courage - that really sets us apart. Through a spirit of ownership and can-do attitude we work together to win. We’re a company of people who care about each other, about our customers and their patients, and about our communities. Together, we fulfill our shared purpose of Life Unlimited.