Product Security Engineer (SBOM)

Zinnov Management Consulting

Bengaluru

On-site

INR 1,800,000 - 2,800,000

Full time

13 days ago
Application generator

Stand out for this role — generate a tailored resume and cover letter in about a minute.

Get past ATS filters

Job summary

Zinnov invites a seasoned Professional, Product Security Engineer to join their Bengaluru GCC for a MedTech client. You will lead SBOM programs, security questionnaires, and regulatory evidence while collaborating with cross-functional teams to strengthen product security across the portfolio.

You will design reusable processes, automate data collection via APIs, and maintain FDA/IEC/NIST-aligned documentation, shaping secure-by-design practices for global healthcare products.

Qualifications

  • 5+ years in cybersecurity or product security with SBOM exposure.
  • Hands-on SBOM/SCA concepts and tools (SPDX/CycloneDX).
  • Understanding CVE/CVSS, NVD, and risk-informed decisions.
  • Ability to design repeatable processes and integrate enterprise platforms, APIs, SaaS tools, and document repositories.
  • Bachelor's degree in CS/Info Security/Engineering.

Responsibilities

  • Lead customer, hospital, and third-party security questionnaire responses with evidence and SLAs.
  • Own creation, maintenance, and review of MDS2 documentation with cross-functional teams.
  • Govern SBOM lifecycle including generation, validation, storage, and vulnerability correlation.
  • Work with SBOM/SCA platforms (Black Duck, Snyk, Mend, Sonatype, Anchore, etc.).
  • Correlate SBOM components with NVD, CISA KEV, vendor advisories, and product risk assessments.
  • Design or improve questionnaire/evidence workflows using ITG/GRC tooling (ServiceNow IRM, OneTrust, Whistic, ProcessUnity).
  • Automate data collection and evidence exchange via APIs and scripting.
  • Maintain FDA IEC/NIST-aligned documentation for product security.
  • Provide program metrics on SBOM coverage, remediation status, and risk.
  • Support threat modeling, architecture reviews, and secure-by-design practices.

Skills

SBOM & SCA concepts
Vulnerability management
Security documentation
Threat modeling
API integration
Program governance
Stakeholder management
Communication skills
SDLC & DevSecOps

Education

Bachelor's degree in Computer Science/Information Security/Engineering

Tools

SPDX / CycloneDX
ServiceNow IRM
OneTrust
Whistic
ProcessUnity

Job description

Zinnov is hiring for the role of Professional, Product Security Engineer on behalf of our Global MNC MedTech client company a company where technology sits at the centre of everything: powering how the core business operates day to day and shaping the products and digital solutions that will define the future of patient care. This role is part of the companys establishment of their new India Global Capability Centre (GCC) in Bengaluru which will drive enterprise technology, digital transformation and innovation for its global operations and contributing to technology that ultimately helps millions of people around the world.

How you'll make an impact
  • Lead customer, hospital, and third-party security questionnaire responses, establishing reusable evidence, ownership, review, approval, and response-SLA processes.
  • Own creation, maintenance, version control, and quality review of MDS2 documentation in partnership with Product Security, Regulatory, Quality, and engineering teams.
  • Govern the SBOM lifecycle including generation, ingestion, validation, storage, versioning, component provenance, vulnerability correlation, and release alignment.
  • Work with SBOM/SCA platforms such as Black Duck, Snyk, Mend, Sonatype Lifecycle, Anchore, Dependency-Track, Syft/Grype, Wiz, or equivalent and support SPDX / CycloneDX formats.
  • Correlate SBOM components with NVD, CISA KEV, vendor advisories, CVSS/EPSS, and product risk assessments to support remediation and disclosure decisions.
  • Design or improve questionnaire and evidence workflows using platforms such as ServiceNow IRM, OneTrust, Whistic, ProcessUnity, or equivalent customer-assurance/GRC tooling.
  • Automate data collection and evidence exchange using APIs, workflow tools, scripting, and integrations with engineering, vulnerability-management, and document repositories.
  • Maintain traceable technical documentation aligned with FDA cybersecurity expectations, IEC 81001-5-1, AAMI TIR57, NIST SSDF, and other applicable product-security standards.
  • Provide program metrics on questionnaire turnaround, MDS2 coverage, SBOM completeness, vulnerability exposure, and remediation status to leadership and cross-functional stakeholders.
  • Support threat modelling, security requirements definition, architecture reviews, and penetration testing to embed secure-by-design practices across the product portfolio.
  • Analyze CVE/KEV exploitability, component exposure, and compensating controls, driving vulnerability remediation through to closure.
  • Develop customer-facing security white papers and regulatory evidence packages alongside MDS2 responses and technical security documentation.
  • Maintain traceability between SBOM/vulnerability data and risk files, safety assessments, design controls, and quality management system (QMS) records.
What you'll bring
Skills Required:
  • 5+ years of experience in cybersecurity, product security, security architecture, or a related discipline, including hands-on exposure to SBOM, vulnerability management, and security documentation.
  • Hands-on experience with SBOM/SCA concepts and tools, including SPDX or CycloneDX, component inventory, vulnerability correlation, and supplier software transparency.
  • Understanding of CVE/CVSS, NVD, CISA KEV, vulnerability prioritization, and how software-component risk informs product-security decisions.
  • Ability to design repeatable processes and integrate enterprise platforms, APIs, SaaS tools, and document/evidence repositories.
  • Strong written communication, stakeholder management, evidence quality, and program governance skills across technical and regulatory teams.
  • Experience supporting product security engineering activities such as threat modeling, security architecture reviews, and secure-by-design practices.
  • Experience maintaining traceability between product security findings and risk management, safety, and quality documentation (risk files, design controls, QMS).
  • Bachelor's degree in Computer Science, Information Security, Engineering, or a related technical field.
Preferred:
  • Experience in MedTech or healthcare with FDA premarket/postmarket cybersecurity expectations, Section 524B, IEC 81001-5-1, IEC 62443, AAMI TIR57, and NIST SSDF.
  • Working knowledge of MDS2 and experience coordinating customer or hospital security questionnaires for technology or medical-device products is a plus.
  • Experience with ServiceNow IRM, OneTrust, Whistic, ProcessUnity, or equivalent questionnaire/evidence-management platforms.
  • Experience supporting PSIRT operations, coordinated vulnerability disclosure (CVD), and post-market surveillance activities.
  • Software engineering, scripting, or data automation skills (Python, APIs, workflow automation) to streamline SBOM and evidence workflows.
  • Software development or engineering background with practical knowledge of the software development lifecycle (SDLC), DevSecOps practices, source-code repositories, and CI/CD-integrated security scanning.
  • CISSP, CSSLP, GICSP, Security+, or equivalent product-security certification; medical device cybersecurity training is a plus.
Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Professional, Security Tool, SBOM Engineer
Professional, Security Tool, SBOM Engineer

Zinnov Management Consulting • Bengaluru

Hybrid
INR 1,800,000 - 2,400,000
Product Security Engineer
Product Security Engineer

HBK - Hottinger Brüel & Kjær • Chennai District

On-site
INR 1,200,000 - 1,800,000
Sr Cybersecurity Specialist
Sr Cybersecurity Specialist

Healthminds Consulting • Hyderabad

On-site
INR 3,000,000 - 6,000,000
Senior Cyber Security Engineer
Senior Cyber Security Engineer

Bayer CropScience Limited • Bengaluru

On-site
INR 3,000,000 - 4,600,000
Cyber Security Specialist (Product Security)
Cyber Security Specialist (Product Security)

Masimo Corporation • Bengaluru

On-site
INR 800,000 - 1,200,000
Professional, Attack Surface & Exposure Analyst
Professional, Attack Surface & Exposure Analyst

Zinnov Management Consulting • Bengaluru

Hybrid
INR 1,800,000 - 2,800,000
Product Security Engineer
Product Security Engineer

Emerson • Maharashtra

On-site
INR 1,200,000 - 1,800,000
Product Security Engineer
Product Security Engineer

Atlas Consolidated • Hyderabad

On-site
INR 1,800,000 - 2,400,000
Security Engineering Manager
Security Engineering Manager

Smartstream Limited • Bengaluru

On-site
INR 4,000,000 - 7,000,000
Security Engineering Manager
Security Engineering Manager

SmartStream • India

On-site
INR 4,000,000 - 6,000,000