Get more replies from employers
Send a job-specific resume in minutes.
GE HealthCare's Imaging360 seeks a Staff Cyber Security Engineer to embed cybersecurity, privacy, and regulatory expectations into product design, development, and lifecycle management. You will partner with engineering, product, cloud operations, and governance teams to ensure secure-by-design delivery and DEPS compliance across cloud and on-premises components.
You will lead threat modeling, security reviews, vulnerability management, SBOM curation, and secure deployment practices.
Job Description Summary The Staff Cyber Security Engineer will serve as the Product Security Representative (PSR) for AIS Digital Ecosystems – Imaging360, a cloud-enabled enterprise healthcare platform that connects with on-premises imaging scanners and integrates with third-party products and services. This role is responsible for embedding cybersecurity, privacy, and regulatory expectations into product design, software development, cloud operations, integrations, and lifecycle management. The successful candidate will partner with Product Security Leaders, engineering, architecture, product management, cloud operations, quality, compliance, and external vendor teams to ensure Imaging360 follows the GE HealthCare Design Engineering Privacy and Security (DEPS) process. The role requires strong experience securing enterprise-scale cloud products, distributed healthcare workflows, hybrid cloud/on-premises connectivity, APIs, identity and access management, third-party integrations, vulnerability management, and secure product lifecycle practices. The Senior Cyber Security Engineer will be expected to leverage open-source technology and industry standard programming languages to enhance cyber security operations. Success in this role will require delivery of engineering, software development, and build-automation projects in an agile environment.
Serve as the Product Security Representative for multiple Imaging360 products and releases, representing cybersecurity and privacy requirements throughout the product lifecycle. Drive execution of the GEHC DEPS process, including security and privacy planning, threat modeling, cybersecurity risk assessment, secure design reviews, vulnerability management, lifecycle security artifacts, and phase-appropriate security deliverables from concept through development and evaluation. Own Security Design Reviews across the product lifecycle, including concept definition, architecture and design, development execution, verification / evaluation, and release readiness for Imaging360 capabilities and integrations. Partner with Product Security Leaders and product teams to interpret and apply GEHC cybersecurity standards, regulatory expectations, and quality management system requirements. Lead threat modeling and security architecture reviews for cloud-hosted enterprise applications, APIs, data flows, scanner connectivity, on-premises integrations, identity services, and third-party product integrations. Assess cybersecurity risks associated with hybrid deployments involving cloud services, customer networks, on-premises scanners, edge components, and external vendor systems. Define and influence implementation of security controls for authentication, authorization, encryption, audit logging, secrets management, network segmentation, secure communication, data protection, and system hardening. Own or support cybersecurity management plans, vulnerability triage, remediation planning, risk acceptance discussions, and closure tracking across multiple product teams. Coordinate SAST, SCA, DAST, penetration testing, infrastructure scanning, container security, cloud security reviews, and remediation activities in partnership with engineering and operations teams. Generate, maintain, and assess Software Bill of Materials (SBOM) content, including open-source, commercial, and third-party components integrated into the product. Evaluate third-party product integrations for cybersecurity, privacy, data protection, interface security, supportability, and operational risk. Collaborate with architecture, platform, DevOps, cloud operations, quality, regulatory, privacy, and program teams to ensure secure-by-design and compliant delivery. Provide cybersecurity guidance to scrum teams, review design and implementation decisions, and help teams adopt secure SDLC and DevSecOps practices. Support fielded product security activities, including vulnerability impact assessments, customer notifications, remediation planning, patch strategy, and lifecycle risk management. Champion Imaging360-level security KPI reporting, governance dashboards, and ongoing monitoring of security health indicators, including vulnerability posture, remediation progress, open risks, security test coverage, SBOM readiness, and DEPS compliance status. Prepare clear technical and leadership-level communication on security posture, risks, remediation status, and product security readiness.
Relocation Assistance Provided: Yes At GE HealthCare, we see possibilities through innovation. We’re partnering with our customers to fulfill healthcare’s greatest potential through groundbreaking medical technology, intelligent devices, and care solutions. Better tools enabling better patient care. Together, we are not only building a healthier future but living our purpose to create a world where healthcare has no limits.