Senior Product Security Engineer

Stryker India Private Limited

Karnataka

On-site

INR 3,500,000 - 6,500,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Stryker India Private Limited is seeking a Senior Staff Engineer to lead vulnerability management across the lifecycle of medical devices and related software. You will own SBOM generation and configuration, collaborate with product teams, and drive security risk management practices.

The role requires deep expertise in vulnerability assessments, patching, and regulatory alignment within a hybrid work model. Travel and leadership responsibilities are expected at senior levels.

Qualifications

  • Demonstrated knowledge of vulnerability management aspects including SBOM generation, vulnerability assessments, threat modeling, security risk assessment processes, and security patching best practices.
  • Proficient in identifying security vulnerabilities across cloud, distributed apps, embedded systems, or IOT.
  • Thorough understanding of NIST, ISO, and related security frameworks applicable to vulnerability management.
  • Experience building cross-department relationships and working with internal/external teams.
  • Expertise applying security control frameworks, risk assessments, and vulnerability severity scoring.
  • Proficient in using one or more vulnerability scanning tools.

Responsibilities

  • Create and own strategies prioritizing objectives for vulnerability management across the lifecycle of medical devices and solutions.
  • Develop solutions for disposition of vulnerabilities from internal assessments.
  • Guide product teams in vulnerability management within a defined risk management process.
  • Collaborate with product teams to develop SBOM generation, repositories, and version management.
  • Design and implement SBOM configuration management for continuous vulnerability processes.
  • Develop policies for coordinated vulnerability disclosure.
  • Roadmap improvements for vulnerability assessment capabilities.
  • Engage with tool vendors to deploy vulnerability management for medical devices and health software.
  • Establish standards for timely security patches for medical products and related systems.
  • Apply regulatory guidance and industry practices to product security procedures and work instructions.
  • Provide product security guidance to internal taskforces.
  • Collaborate with product teams to assess security risks and drive design decisions for new products.
  • Deliver presentations to senior leadership on security topics.

Skills

Vulnerability management
SBOM
Threat modeling
Security risk assessment
Security patching
Vulnerability scanning tools

Education

Bachelor's degree in a related field

Tools

N/A

Job description

Sr. Staff Engineer Work Flexibility: Hybrid

What You Will Do:
  • Create and own strategies that prioritize objectives for creating effective vulnerability management processes across the entire lifecycle of medical device and associated solutions.
  • Develop efficient solutions for determining the disposition of vulnerabilities produced through internal assessments and analysis efforts throughout the product lifecycle.
  • Guide product development teams in completing overall vulnerability management procedures within a defined security risk management process.
  • Work with product teams and product security services teams to develop and optimize the generation, repositories, and version management of software bills of material (SBOM) for a variety of medical device technologies.
  • Design and implement SBOM configuration management solutions to enable continuous vulnerability management processes.
  • Develop and own the policy and process of coordinated vulnerability disclosure.
  • Review current state and desired state of vulnerability assessment capabilities to define a roadmap needed improvements.
  • Work with tool vendors to develop and implement vulnerability management solutions associated with in-market medical devices and health software products.
  • Develop standards and internal guidance for the timeliness of security patches for medical products and related systems.
  • Apply regulatory guidance and industry best practices to drive strategies for product security procedures and work instructions.
  • Provide product security guidance and leadership to internal taskforce teams.
  • Collaborate with product teams to assess security risks and drive design decisions for new products and related systems based on vulnerability assessment results.
  • Develop and deliver presentations and communications to clearly convey security topics up to the senior leadership level.
  • Collaborate with Stryker enterprise functions to leverage domain expertise and capabilities and identify areas of opportunity.
  • Recommend efficiency and process improvements to product security capabilities and functions.
  • Manage all facets of Vulnerability Assessment and Penetration testing involving embedded devices, Web and Mobile based Applications.
  • Perform attacks and identify vulnerabilities on interfaces like USB, WiFi.
  • Ethernet etc.
  • Perform manual and automated security code review for complex Desktop, Web and Mobile applications to identify security flaws.
  • Leverage DevSecOps to embed security testing into all phases of SDLC.
  • Provide support/inputs in issue remediation.
  • Prepare Test Plans and Test Reports to support test activities.
Knowledge and Capabilities:
  • Demonstrated knowledge of various vulnerability management aspects including SBOM generation, vulnerability assessments, threat modeling, security risk assessment processes, and security patching best practices.
  • Proficient in identifying security vulnerabilities across several areas of computing such as cloud, distributed applications, embedded systems, or IOT.
  • Thorough understanding of the current revisions of NIST, ISO, and other related security frameworks especially those that apply to vulnerability management.
  • Proven experience building successful working relationships with internal and external personnel in various departments.
  • Expertise in applying security control frameworks, security risk assessments, and scoring the severity of security threats and vulnerabilities.
  • Proficient in using one or more vulnerability scanning tools.
  • Proven expertise working with product development teams in a broad number of computing environments.
  • Excellent written and verbal communication skills.
  • Proven ability to facilitate meetings to accomplish goals and objectives in a collaborative environment.
  • Proven ability to develop and analyze procedural documents and associated artifacts.
  • Demonstrated ability to understand and communicate how objectives fit into broader organizational goals, prioritize tasks, and develop timelines and work estimates.
What You Will Need:
  • Bachelor's Degree in product security, computer science, mathematics, statistics, or related field 10+ years of applicable (product) security work experience required.
Preferred Qualifications:
  • Master's Degree in security related discipline preferred.
  • Understands security risk management processes preferably in the healthcare or medical device industry.
  • Direct experience working in a product focused vulnerability management process.
  • One or more active, industry recognized, and relevant cybersecurity certifications.

Travel Percentage: 10%

Experience Level Senior Level

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Sr. Staff Engineer
Sr. Staff Engineer

Stryker • Bengaluru

On-site
INR 3,500,000 - 5,200,000
Staff Product Security Engineer
Staff Product Security Engineer

PowerToFly • Gurugram District

On-site
INR 1,500,000 - 2,600,000
Staff Product Security Engineer
Staff Product Security Engineer

Stryker Corporation • India

Hybrid
Confidential
Staff Product Security Engineer
Staff Product Security Engineer

Stryker • Gurugram District

On-site
INR 1,400,000 - 2,000,000
Sr Cybersecurity Specialist
Sr Cybersecurity Specialist

HealthMinds Consulting Pvt. Ltd • Bengaluru

On-site
INR 2,500,000 - 4,500,000
Health insurance
Staff Product Security Engineer
Staff Product Security Engineer

Stryker Group • India

On-site
INR 1,800,000 - 3,200,000
Product Security Engineer
Product Security Engineer

spectris • Chennai District

On-site
INR 1,500,000 - 2,100,000
Sr Cybersecurity Specialist
Sr Cybersecurity Specialist

HealthMinds • Bengaluru

On-site
INR 3,500,000 - 6,000,000
Product Security Engineer
Product Security Engineer

Zela Luxury Health Clubs • Chennai District

On-site
INR 1,800,000 - 3,200,000
Product Security Engineer II
Product Security Engineer II

Medtronic • Hyderabad

On-site
INR 1,500,000 - 2,300,000