Senior Cybersecurity Engineer

STERIS

Maharashtra

On-site

INR 1,500,000 - 3,200,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

STERIS is seeking a Senior Cybersecurity Engineer in its R&D controls department in India to advance secure software practices for healthcare technologies. The role centers on vulnerability analysis, SBOM development, and collaboration with product teams on secure designs.

You will drive risk assessments, regulatory-compliant security documentation, and robust testing strategies. The candidate will lead incident response activities, perform security testing across embedded products, and

Qualifications

  • Bachelor's degree in computer engineering, Software Engineering, or Cybersecurity.
  • 5+ years of embedded product cybersecurity experience.
  • 3+ years in device security vulnerability assessment and SDLC.
  • 2+ years in Linux or Windows system-level security analysis.
  • Experience with vulnerability scanning tools and threat intelligence services.

Responsibilities

  • Receive and analyze CVEs from open-source sources, determine applicability to STERIS products, and collaborate with product teams to gather information needed for CVE impact and applicability assessments.
  • Develop and track software bill of materials (SBOM), track vulnerabilities in SBOM, and work with product teams to remediate the vulnerabilities.
  • Identify potential software security vulnerabilities and collaborate with product teams for remediation and planning.
  • Lead cybersecurity incident response activities, supporting investigation and remediation efforts.
  • Lead product security risk assessments, requirements analysis, and test methods in alignment with internal procedures and regulatory requirements.
  • Evaluate and execute product security testing including test planning, cases, and procedure development.
  • Perform vulnerability assessment and network scanning activities.
  • Perform internal security testing activities including fuzz testing to identify potential product vulnerabilities.
  • Reproduce penetration testing findings to help product teams understand security issues and develop effective remediations.
  • Implement proposed security controls/methods to software embedded in STERIS products and other software applications for the assigned product(s) or project(s).
  • Research new techniques and methods to enhance internal security testing practices and improve overall device security.
  • Initiate improvement projects related to Cybersecurity technology, tools, and practices.
  • Work on cybersecurity assessments and documentation required for regulatory compliance such as FDA 510(k) submissions, including but not limited to security risk management, threat modeling, security architecture views, vulnerability management, and regulatory compliance deliverables.
  • Respond to Cybersecurity Questionnaires from STERIS Customers.
  • Create and update FAQs, White Paper/Knowledge Articles based on commonly asked questions by Customers.
  • Perform other related and evolving job-related duties as assigned

Skills

Embedded security
C/C++/C#
SBOM management
Vulnerability assessment
Penetration testing
Linux security
Windows security
Threat modeling
Software security requirements

Education

Bachelor's degree in computer engineering, Software Engineering, or Cybersecurity

Tools

Threat modeling tools
Network testing tools
Vulnerability scanning tools

Job description

Position Summary

The Senior Cybersecurity Engineer is a cybersecurity specialist working within the STERIS R&D controls department. The responsibilities include analyzing software and hardware for potential vulnerabilities, creating work instructions for secure software maintenance, collaborating with product development teams for secure designs, conducting vulnerability assessments, and participating in incident response efforts. You will focus on creating and maintaining the security standards that contribute to the safety and integrity of critical healthcare technology.

Duties
  • Receive and analyze CVEs from open‑source sources, determine applicability to STERIS products, and collaborate with product teams to gather information needed for CVE impact and applicability assessments
  • Develop and track software bill of materials (SBOM), track vulnerabilities in SBOM, and work with product teams to remediate the vulnerabilities
  • Identify potential software security vulnerabilities and collaborate with product teams for remediation and planning
  • Lead cybersecurity incident response activities, supporting investigation and remediation efforts.
  • Lead product security risk assessments, requirements analysis, and test methods in alignment with internal procedures and regulatory requirements.
  • Evaluate and execute product security testing including test planning, cases, and procedure development
  • Perform vulnerability assessment and network scanning activities
  • Perform internal security testing activities including fuzz testing to identify potential product vulnerabilities
  • Reproduce penetration testing findings to help product teams understand security issues and develop effective remediations
  • Implement proposed security controls/methods to software embedded in STERIS products and other software applications for the assigned product(s) or project(s)
  • Research new techniques and methods to enhance internal security testing practices and improve overall device security
  • Initiate improvement projects related to Cybersecurity technology, tools, and practices
  • Work on cybersecurity assessments and documentation required for regulatory compliance such as FDA 510(k) submissions, including but not limited to security risk management, threat modeling, security architecture views, vulnerability management, and regulatory compliance deliverables
  • Respond to Cybersecurity Questionnaires from STERIS Customers
  • Create and update FAQs, White Paper/Knowledge Articles based on commonly asked questions by Customers
  • Perform other related and evolving job-related duties as assigned
Education

Bachelor’s degree in computer engineering, Software Engineering, or Cybersecurity required.

Required Experience
  • Bachelor’s degree in computer engineering, Software Engineering, or Cybersecurity required. (A degree in another engineering discipline may be acceptable with proven cybersecurity education and/or training and demonstrated experience in software security.)
  • At least 5 years of direct experience in the field of embedded product cybersecurity, conducting device security risk assessments and security testing
  • At least 3 years’ experience in device security vulnerability assessment and software development lifecycle
  • At least 2 years’ experience in linux or windows system level security analysis
  • Knowledge in programming languages like C++/C/C# etc.
  • Experience in analyzing penetration test results and recommending corrective actions
  • At least 1 year Experience with security testing for embedded products and utilizing various tools for network testing
  • Experience in writing software security requirements
  • Experience with vulnerability scanning tools and threat intelligence services.
Preferred Experience
  • Experience using Threat Modeling tools and conducting penetration testing is desirable
  • Software security certification such as SSCP or CISSP is desirable
  • Knowledge of Windows and Linux operating systems and OS configurations
  • Experience with IEC62304, UL 29000 and FDA cybersecurity regulation is desirable
Skills
  • Team player with the ability to interact with multiple product development teams across multiple locations
  • Keen interest in acquiring technical knowledge of leading techniques, standards and practices related to software system security
  • Develop knowledge about various types of cyberattacks and appropriate defenses
  • Strong communication and problem-solving skills
  • Experience in developing applications/scripts for multiple operating systems
  • Knowledge of Internet and Things (IoT) and related solutions

STERIS strives to be an Equal Opportunity Employer.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Staff Product Security Engineer
Staff Product Security Engineer

Stryker Group • India

On-site
INR 1,800,000 - 3,200,000
Staff Product Security Engineer
Staff Product Security Engineer

Stryker • Gurugram District

On-site
INR 1,400,000 - 2,000,000
Staff Product Security Engineer
Staff Product Security Engineer

PowerToFly • Gurugram District

On-site
INR 1,500,000 - 2,600,000
Senior Software Engineer
Senior Software Engineer

STERIS • Maharashtra

On-site
INR 800,000 - 1,200,000
Sr Cybersecurity Specialist
Sr Cybersecurity Specialist

HealthMinds Consulting Pvt. Ltd • Bengaluru

On-site
INR 2,500,000 - 4,500,000
Health insurance
Cyber Security Specialist (Product Security)
Cyber Security Specialist (Product Security)

Masimo • Bengaluru

On-site
INR 600,000 - 800,000
Sr. Staff Engineer
Sr. Staff Engineer

Stryker • Bengaluru

On-site
INR 3,500,000 - 5,200,000
Product Security Engineer
Product Security Engineer

Emerson • Maharashtra

On-site
INR 1,200,000 - 1,800,000
Sr. Cyber Security Engineer
Sr. Cyber Security Engineer

Cloud Counselage Pvt Ltd • Mumbai

Hybrid
INR 1,200,000 - 1,500,000
Competitive salary
Professional development opportunities
Exposure to cutting-edge cloud technologies
+1
Senior Cybersecurity Engineer | 4-6 years Experience
Senior Cybersecurity Engineer | 4-6 years Experience

Utthunga Technologies • Bengaluru

On-site
INR 1,800,000 - 3,000,000