Job Summary
We are seeking a Senior Software Engineer(Cybersecurity) with strong expertise in Application Security and exposure to AI-assisted tools and techniques to design, secure, and enhance innovative healthcare technology solutions within our Front Line Care product portfolio. This role focuses on embedding security into scalable, high-quality software and device solutions that directly impact patient care and clinical outcomes. The ideal candidate is technically strong, passionate about secure product development, and motivated by contributing to life-saving healthcare technologies.
Key Responsibilities
Partner closely with software development teams to promote a security-by-design mindset by defining secure implementations and coding practices aligned with the Application Security Program.
•
Design and implement secure coding solutions, patterns, and guidelines for embedded and cloud environments, ensuring compliance with security and privacy requirements defined in security plans, risk assessments, policies, and procedures.
•
Support security project governance activities, including planning, scheduling, prioritization, and tracking of security initiatives.
•
Proactively drive security solution implementations in collaboration with development leads, security architects, and product owners.
•
Lead feature implementations aligned with system architecture through design, coding, reviews, and testing; perform Proof of Concept (POC) activities as needed.
•
Review, analyze, and mitigate findings from SAST, DAST, SCA, and penetration testing in collaboration with development teams across electromechanical medical device product lifecycles.
•
Assess existing software security controls and implement security enhancements across multiple medical devices and platforms.
•
Participate in post-market product analysis to support vulnerability investigations and contribute to continuous security monitoring efforts.
•
Leverage AI-assisted techniques to secure the system.
Skill Requirements
Key Skills required:
1. 6+ yrs experience as a Cyber security engineer (Btech /BE/Mtech/MCA)
2. Strong understanding of Application Security & Secure Coding
3. Expertise in OWASP Top 10 vulnerabilities
4. Hands-on experience with Security Testing & Vulnerability Management
5. Knowledge of Cryptography & Data Protection
6. Understanding of
a) Embedded / IoT Security
b) Threat modeling & risk assessment
c) Security governance & compliance
Other Requirements
Bachelor’s degree in Computer Science, Computer Engineering, or a related field, or equivalent practical experience.
•
Minimum of 6+ years of experience in cybersecurity design and development; experience with embedded systems is preferred.
•
Hands-on experience with Java, C++, C#, Linux, and secure software design within complex systems.
•
Proven experience analyzing, interpreting, and remediating security findings from SAST, DAST, SCA, and penetration testing tools.
•
Experience with embedded data-at-rest security implementations, including Code Signing, Secure Boot, and flash encryption.
•
Experience in designing and implementing secure wired and wireless networking solutions for embedded/IoT systems across multiple OSI layers.
•
Hands-on experience with IoT and embedded PKI solutions and implementations.
•
Demonstrated experience in cybersecurity development for embedded and digital products.
•
Strong ability to guide software development teams on secure coding practices and the interpretation of application security testing reports across multiple programming languages and operating environments.
•
Solid understanding of secure software development lifecycle (SSDLC) practices, including SAFe and Agile methodologies.
•
Strong knowledge of security-by-design principles and architecture-level security concepts.
•
Proficient understanding and practical application of security technologies such as cryptographic algorithms and cipher suites, PKI, hardware/embedded authentication protocols, Secure Boot mechanisms, and data-at-rest encryption.
•
Experience implementing and enforcing OWASP Top 10 application security guidelines.
•
Knowledge of embedded system architecture and security controls, including firewall configurations, border routers, wireless communication architectures, and messaging authentication protocols.
•
Experience generating, reviewing, and validating penetration test results using standard methodologies and tools, including threat modeling, security analysis, and system security audits.
•
Up-to-date knowledge of current and emerging security threats, attack techniques, and vulnerability exploitation methods.
•
Exposure to international privacy regulations and cross-industry security trends.
•
Exposure to AI-assisted tools and techniques.