Senior Cyber Security Engineer

Bayer CropScience Limited

Bengaluru

On-site

INR 3,000,000 - 4,600,000

Full time

9 days ago
Application generator

Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Job summary

Bayer CropScience Limited is seeking an experienced product-security professional to lead cloud and DevSecOps security across connectivity platforms. You will own security engineering work, guide remediation plans and collaborate with development teams to fix findings before PR merge or release.

The role emphasizes security pipelines, SBOM generation, and evidence-driven audits, with a focus on ISO/GDPR-aligned controls.

Qualifications

  • Bachelor's degree in Computer Science, Information Security, Cybersecurity, Software Engineering or related field.
  • 7+ years of hands-on cybersecurity, product security, cloud security or DevSecOps experience.
  • Strong experience with GCP and at least one other cloud platform (AWS/Azure).
  • Hands-on with CI/CD security, GitHub workflows, vulnerability scanning, container/image scanning, secret scanning and release gates.

Responsibilities

  • Own and execute product-security engineering work for connectivity solutions and remediation of security gaps.
  • Design, maintain and improve GitHub security pipelines and standard caller workflows across repositories.
  • Onboard projects to security workflows and validate secrets versus variables in release stages.
  • Review cloud, Kubernetes, IAM configurations and identify misconfigurations or over-permissive access.
  • Drive closure of findings from security tools and ensure fixes are re-scanned.
  • Prepare release security reports and evidence packs for quality and audit sign-off.

Skills

Communication
Stakeholder mgmt
Analytical thinking
Documentation

Education

Bachelor's degree

Tools

GitHub
Dependabot
SonarQube
JFrog Xray
Orca
Tanium
CrowdStrike
Burp Suite
SIEM
Kubernetes

Job description

Own and execute product-security engineering work for Cortenic connectivity solutions, including security debt reduction, remediation SLAs, operating dashboards and continuous improvement of inherited security gaps. Design, maintain and improve central GitHub security pipelines and standard caller workflows across connectivity repositories, including dependency, secret, code-quality, artifact, container and cloud-security scans. Onboard repositories and projects to standard security workflows, map branches and environments, validate secrets versus variables, and ensure the correct image and configuration are used across release stages. Review cloud, Kubernetes, Artifact Registry and IAM configurations; identify misconfigurations, over-permissive access, registry exposure, data-classification gaps and monitoring/logging coverage issues. Identify, triage, prioritize and drive closure of findings from Dependabot, Xray, SonarQube, Orca, Tanium, CrowdStrike, Burp Suite and Secret Scanning, including re-scans and evidence-based verification. Partner with development teams during sprints to interpret scan reports, fix findings before PR merge or release, remediate High/Critical dependency and container vulnerabilities, and validate fixes through pipeline re-runs. Configure and maintain security quality gates, generate SBOMs for production releases, prepare release security reports, assess gate exceptions and provide evidence for Quality, audit and release sign-off.

Create and maintain security runbooks, repository onboarding checklists, branch/environment/secrets guides, audit-ready evidence packs and technical reference material for reviews, approvals and stakeholder briefings. Support penetration testing by defining scope, preparing architecture/access/environment details, reviewing reports, creating remediation plans with development teams and providing closure evidence. Respond to cybersecurity incidents, customer/security-contract questions, Cyber Central requests and newly disclosed vulnerabilities with impact assessments, approved evidence, clear documentation and timely follow-through. Support compliance and certification readiness by providing scan artifacts, risk and vulnerability evidence, control implementation inputs and audit support in partnership with Global Cybersecurity and Quality.

Required Bachelor's degree in Computer Science, Information Security, Cybersecurity, Software Engineering, or a related field. 7+ years of hands-on cybersecurity, product security, cloud security or DevSecOps experience in software/product engineering environments. Strong experience with GCP preferred and at least one additional cloud platform such as AWS or Azure. Practical experience with CI/CD security, GitHub workflows, vulnerability scanning, dependency scanning, container/image scanning, secret scanning and release security gates. Experience with tools such as Dependabot, SonarQube, JFrog Xray, Orca, Tanium, CrowdStrike, Burp Suite, SAST/DAST tools, SIEM/logging platforms or equivalent technologies. Ability to translate scan findings into prioritized remediation plans, work with engineering teams to close findings, and produce audit-ready evidence. Working knowledge of ISO 27001, SOC 2, NIST, GDPR, HIPAA, GxP, SaMD, medical device cybersecurity or other regulated product-security expectations is preferred. Strong analytical, documentation, stakeholder-management and communication skills, with the ability to support developers, Quality, Global Cybersecurity and leadership stakeholders.

Cloud Security

Google Cloud Platform preferred, plus AWS or Azure; cloud, Kubernetes, Artifact Registry, IAM, workload identity, secrets, variables and registry exposure reviews

DevSecOps & Security Tooling

GitHub security pipelines, Dependabot, Secret Scanning, SonarQube, JFrog Xray, Orca, Tanium, CrowdStrike, Burp Suite, SAST/DAST and CI/CD security gates

Vulnerability & Remediation Management

Severity and exploitability-based prioritization, High/Critical dependency and container fixes, patch verification, re-scans and closure evidence

Release Assurance

Security quality gates, SBOM generation, release security reports, exception assessments, control checklists and evidence for Quality/release sign-off

Monitoring & Incident Response

Cybersecurity signal triage, SIEM/log-source coverage, incident support, newly disclosed CVE impact assessment and escalation handling

Security Documentation & Evidence

Runbooks, onboarding checklists, branch/environment/secrets guides, audit-ready evidence packs and technical reference material

Penetration Testing Support

Scope definition, architecture/access/environment readiness, report review, remediation planning and closure evidence

Regulated Product Security

Healthcare or SaMD product security, ISO 27001, SOC 2, NIST, HIPAA, GDPR, GxP/release audit support and security-risk evidence

Agile & Collaboration

Jira, Confluence, Scrum practices, developer enablement, stakeholder Q&A, sprint backlog integration and clear communication with cross-functional teams

Experience working in enterprise/global cybersecurity teams on cybersecurity management plans, cyber test reports, security requirements, release security reviews, risk assessments and risk-management reporting.

Familiarity with global cybersecurity governance activities such as policy and procedure creation, security-gate design, centralized control checklists, threat modeling and cybersecurity control ownership mapping.

Understanding of regulated product-security deliverables, including Cybersecurity Management Plans, Cyber Test Reports, Security Risk Management Plans/Reports, Threat Modeling Reports, residual-risk decisions and release-security evidence packs.

Ability to support global teams with incident response, customer escalations, external disclosures, newly disclosed vulnerability assessments and documented impact/risk decisions.

Exposure to certification and compliance readiness work with Quality, including ISO certification scope, certification strategy, control evidence, submission support and audit-ready security-risk documentation.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

DevSecOps Engineer
DevSecOps Engineer

Sutherland Global • Hyderabad

On-site
INR 1,800,000 - 2,600,000
Cybersecurity Subject Matter Expert
Cybersecurity Subject Matter Expert

Sunovaa Tech • Pune District, Bengaluru

Hybrid
INR 2,500,000 - 4,000,000
Product Security Engineer
Product Security Engineer

HBK - Hottinger Brüel & Kjær • Chennai District

On-site
INR 1,200,000 - 1,800,000
Senior Product Security Engineer
Senior Product Security Engineer

Dun & Bradstreet • Hyderabad

On-site
INR 4,000,000 - 7,000,000
Cybersecurity & Compliance Advisor
Cybersecurity & Compliance Advisor

Siemens • Gurugram District

On-site
INR 2,800,000 - 4,200,000
Sr. IT Engineer (Security)
Sr. IT Engineer (Security)

DataCore Software GmbH • Bengaluru

On-site
INR 2,500,000 - 4,500,000
Offensive Security Engineer
Offensive Security Engineer

UST • Ernakulam

On-site
INR 2,400,000 - 3,600,000
Cloud Security Operations Specialist - DevSecOps
Cloud Security Operations Specialist - DevSecOps

BOT Consulting • Jaipur

On-site
INR 1,200,000 - 1,800,000
Lead Security Engineer
Lead Security Engineer

mpc • Bengaluru

On-site
INR 1,800,000 - 2,400,000
Senior Cyber Security Operations Analyst
Senior Cyber Security Operations Analyst

Version 1 • Bengaluru

On-site
INR 1,800,000 - 3,600,000