Staff Product Security Engineer

Stryker Corporation

India

Hybrid

Confidential

Full time

10 days ago

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Stryker Corporation is seeking a Product Cybersecurity Engineer in India to contribute to project planning, risk analysis, and mitigation for medical device software and robotics products.

You will lead cybersecurity tasks across product design controls and SDLC, collaborating with Quality, Regulatory, and Marketing to ensure compliance and robust security across hardware and software domains. Travel is expected up to 10%.

Qualifications

  • Bachelor's degree in Software Engineering/ Computer Science or related discipline and 6+ years of work experience.

Responsibilities

  • Perform cybersecurity risk analysis and threat modeling and develop mitigation strategies.
  • Work with Quality, Regulatory, and Marketing to align product cybersecurity and HIPAA compliance.
  • Provide input to project management on scheduling, milestones and challenges.
  • Participate in all product hardware and software security facets, including hardening, testing, scanning and remediation.
  • Identify security flaws via manual and automated reviews of embedded/clinical software.
  • Develop and implement security policies and procedures ensuring industry standard compliance.
  • Integrate automated security testing into all SDLC phases.
  • Automate routine tasks and extract data using scripting languages like PowerShell, Ruby or Python.
  • Research best practices in product cybersecurity architecture, including access control, injections, exposure, firewalls, MFA.
  • Support cybersecurity documentation requests from legal and sales teams as needed.
  • Participate in incident response, V&E assessments and resolution of security incidents.

Skills

Cybersecurity risk analysis
Threat modeling
Cross-functional teamwork
Penetration testing

Education

Bachelors in CS/SE

Tools

PowerShell
Python
Ruby

Job description

Work Flexibility

Hybrid or Onsite

Remote – Role allows you to work the majority to 100% of time from an alternate workplace.

Field-based – You can expect to regularly work a majority to 100% of time at customer facilities and has a set territory or expectation to travel within a set boundary. Almost all sales roles would likely be qualified as field-based.

Onsite – Role is 100% located at a Stryker facility. Some ad hoc flexibility may be available depending on role, level, and job requirements. Manufacturing roles and any role that requires physical presence at the office would qualify under this category.

Hybrid – You can expect to regularly work in both an alternate workplace and a Stryker facility. Roles that are partially remote or co-located would qualify as hybrid, and the expectation to be onsite would be defined and agreed upon by your manager/supervisor.

Who we want

We seek Product Security engineers who can help us design cyber secure medical devices and applications.

What you will do

As a Product Cybersecurity Engineer, you will participate in project planning, product cybersecurity risk analysis, and risk mitigation strategies.

You will lead various product cybersecurity tasks and activities established by product design controls and SDLC procedures.

You will be involved in all facets of the robotics and enabling technology product development life cycle.

Technical Responsibilities
  • You will perform cybersecurity risk analysis and threat modeling and develop mitigation strategies.
  • You will work closely with cross-functional teams, including Quality, Regulatory, and Marketing, in driving alignment around product Cybersecurity and HIPAA compliance.
  • You will provide input to project management on scheduling, milestone achievement, and project challenges.
  • You will participate in all product hardware and software security facets, including systems hardening, automated and manual penetration testing, automated vulnerability scanning for compliance, and issue remediation.
  • To identify security flaws, you will perform manual and automated code reviews for complex embedded and clinical application software.
  • You will develop and implement security policies and procedures to ensure compliance with industry standards.
  • You will integrate automated security testing into all phases of SDLC.
  • You will automate routine tasks and extract valuable data using various scripting languages like PowerShell, Ruby, or Python.
  • You will research and implement best practices in the product cybersecurity architecture around security systems, including improper access control, code injection, information exposure, firewalls, and multi-factor authentication.
  • You will support cybersecurity documentation requests from legal and sales teams as needed.
  • You will participate in incident response, V&E assessments and manage the resolution of security incidents.
Minimum Qualifications
  • Bachelor's degree in Software Engineering/ Computer Science or related discipline & 6+ years of work experience.
Preferred Qualifications
  • Experience with security requirements, data security, malware analysis, vulnerability assessment, and penetration testing using off-the-shelf tools and techniques is preferred.
  • Understanding one or more security standards/frameworks like NIST 800-53, IEC80001-2-8, IEC 27002, ISO 27799, IEC 15408-2, and IEC 62443-3-3.
  • Solid understanding of Linux operating systems.
  • Experience in securing medical devices or embedded devices.
  • Understanding of networking concepts.
  • Understanding quality standards like IEC 62304, IEC 60601, and 21CRF 820.
  • Experience with threat modeling and risk assessment.
  • Security certifications such as CISSP, CSSLP, or CISM are a plus.

Travel Percentage: 10%

Stryker is one of the world’s leading medical technology companies and, together with its customers, is driven to make healthcare better. We offer innovative products and services in Orthopaedics, Medical and Surgical, and Neurotechnology and Spine that help improve patient and hospital outcomes. We are proud to be named one of the World’s Best Workplaces! For more information, visit: www.stryker.com

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Staff Product Security Engineer
Staff Product Security Engineer

PowerToFly • Gurugram District

On-site
INR 1,500,000 - 2,600,000
Staff Product Security Engineer
Staff Product Security Engineer

Stryker • Gurugram District

On-site
INR 1,400,000 - 2,000,000
Senior Principal Engineer Robotics
Senior Principal Engineer Robotics

Stryker Corporation • India

On-site
Confidential
Sr. Staff Engineer
Sr. Staff Engineer

Stryker • Bengaluru

On-site
INR 3,500,000 - 5,200,000
Senior Embedded / Firmware Engineer
Senior Embedded / Firmware Engineer

Stryker Corporation • India

On-site
Confidential
Project Engineer, Product Transfer
Project Engineer, Product Transfer

Stryker Corporation • India

Hybrid
Confidential
Engineer Validation
Engineer Validation

Stryker Corporation • India

Hybrid
Confidential
Restaurant d'entreprise
Senior Engineer, GPE Lifecyle Management
Senior Engineer, GPE Lifecyle Management

Stryker Corporation • Gurugram District

Hybrid
Confidential
Hybrid work model
Senior Engineer, GPE Lifecyle Management
Senior Engineer, GPE Lifecyle Management

Stryker Corporation • India

Hybrid
Confidential
Senior Design Engineer
Senior Design Engineer

Stryker Corporation • India

Hybrid
Confidential