Jobs Companies GE HealthCare Staff Cyber Security Engineer

À propos de ce poste Staff Cyber Security Engineer chez GE HealthCare

GE HealthCare · Sur site · IND19-01-Bengaluru-EPIP 122 (Phase II)

Job Description Summary

The Staff Cyber Security Engineer will serve as the Product Security Representative (PSR) for AIS Digital Ecosystems – Imaging360, a cloud-enabled enterprise healthcare platform that connects with on-premises imaging scanners and integrates with third-party products and services. This role is responsible for embedding cybersecurity, privacy, and regulatory expectations into product design, software development, cloud operations, integrations, and lifecycle management.

The successful candidate will partner with Product Security Leaders, engineering, architecture, product management, cloud operations, quality, compliance, and external vendor teams to ensure Imaging360 follows the GE HealthCare Design Engineering Privacy and Security (DEPS) process. The role requires strong experience securing enterprise-scale cloud products, distributed healthcare workflows, hybrid cloud/on-premises connectivity, APIs, identity and access management, third-party integrations, vulnerability management, and secure product lifecycle practices.

The Senior Cyber Security Engineer will be expected to leverage open-source technology and industry standard programming languages to enhance cyber security operations. Success in this role will require delivery of engineering, software development, and build-automation projects in an agile environment.

GE Healthcare is a leading global medical technology and digital solutions innovator. Our mission is to improve lives in the moments that matter. Unlock your ambition, turn ideas into world-changing realities, and join an organization where every voice makes a difference, and every difference builds a healthier world.

Job Description

Key Responsibilities

  • Serve as the Product Security Representative for multiple Imaging360 products and releases, representing cybersecurity and privacy requirements throughout the product lifecycle.

  • Drive execution of the GEHC DEPS process, including security and privacy planning, threat modeling, cybersecurity risk assessment, secure design reviews, vulnerability management, lifecycle security artifacts, and phase-appropriate security deliverables from concept through development and evaluation.

  • Own Security Design Reviews across the product lifecycle, including concept definition, architecture and design, development execution, verification / evaluation, and release readiness for Imaging360 capabilities and integrations.

  • Partner with Product Security Leaders and product teams to interpret and apply GEHC cybersecurity standards, regulatory expectations, and quality management system requirements.

  • Lead threat modeling and security architecture reviews for cloud-hosted enterprise applications, APIs, data flows, scanner connectivity, on-premises integrations, identity services, and third-party product integrations.

  • Assess cybersecurity risks associated with hybrid deployments involving cloud services, customer networks, on-premises scanners, edge components, and external vendor systems.

  • Define and influence implementation of security controls for authentication, authorization, encryption, audit logging, secrets management, network segmentation, secure communication, data protection, and system hardening.

  • Own or support cybersecurity management plans, vulnerability triage, remediation planning, risk acceptance discussions, and closure tracking across multiple product teams.

  • Coordinate SAST, SCA, DAST, penetration testing, infrastructure scanning, container security, cloud security reviews, and remediation activities in partnership with engineering and operations teams.

  • Generate, maintain, and assess Software Bill of Materials (SBOM) content, including open-source, commercial, and third-party components integrated into the product.

  • Evaluate third-party product integrations for cybersecurity, privacy, data protection, interface security, supportability, and operational risk.

  • Collaborate with architecture, platform, DevOps, cloud operations, quality, regulatory, privacy, and program teams to ensure secure-by-design and compliant delivery.

  • Provide cybersecurity guidance to scrum teams, review design and implementation decisions, and help teams adopt secure SDLC and DevSecOps practices.

  • Support fielded product security activities, including vulnerability impact assessments, customer notifications, remediation planning, patch strategy, and lifecycle risk management.

  • Champion Imaging360-level security KPI reporting, governance dashboards, and ongoing monitoring of security health indicators, including vulnerability posture, remediation progress, open risks, security test coverage, SBOM readiness, and DEPS compliance status.

  • Prepare clear technical and leadership-level communication on security posture, risks, remediation status, and product security readiness.

Education Qualification

Bachelor’s degree in Computer Science, Computer Engineering, Cybersecurity, Information Security, Software Engineering, or a related STEM discipline

Technical Skill Set

  • 12+ years of experience in software engineering, product security, application security, cloud security, or cybersecurity engineering for enterprise products.

  • Hands-on experience securing cloud-hosted enterprise applications and distributed systems, preferably in AWS, Azure, or similar cloud environments.

  • Experience with enterprise products that integrate with on-premises systems, connected devices, customer networks, or scanner / equipment workflows.

  • Strong understanding of secure software development lifecycle practices, threat modeling, cybersecurity risk management, vulnerability management, and security control implementation.

  • Working knowledge of application, API, container, infrastructure, network, and cloud security concepts.

  • Experience with security assessment tools and practices such as SAST, SCA, DAST, penetration testing, container scanning, cloud posture management, SBOM generation, and dependency vulnerability analysis.

  • Knowledge of OWASP Top 10, secure coding principles, identity and access management, encryption, audit logging, secure communications, and privacy-by-design principles.

  • Ability to work effectively in a regulated product development environment and maintain compliance with quality, privacy, and cybersecurity processes.

  • Demonstrated technical leadership, stakeholder management, and communication skills across engineering, product, quality, regulatory, security, and leadership audiences.

Desired Skills

  • Experience serving as a Product Security Representative, security architect, or product security owner for multiple products or releases.

  • Experience with healthcare software, medical device software, imaging workflows, DICOM environments, or connected clinical systems.

  • Familiarity with GEHC DEPS or equivalent product cybersecurity lifecycle processes in regulated industries.

  • Understanding of applicable cybersecurity and privacy frameworks such as FDA cybersecurity guidance, NIST, ISO 27001, IEC 81001-5-1, HIPAA, GDPR, SOC 2, or similar standards.

  • Experience assessing third-party products, SaaS services, APIs, vendor integrations, and data exchange workflows for cybersecurity and privacy risk.

  • Hands-on experience with tools such as threat modeling tools, Black Duck, Syft, Grype, SonarQube, Burp Suite, Wiz, Twistlock / Prisma Cloud, or equivalent security platforms.

  • Experience with DevSecOps practices, CI/CD security gates, automated security testing, infrastructure-as-code security, container security, and cloud-native monitoring.

  • Strong understanding of identity federation and access control technologies such as SAML, OAuth, OIDC, SCIM, RBAC, and least-privilege access models.

  • Security certifications such as CISSP, CSSLP, CISM, CCSP, CEH, or equivalent credentials are a plus.

  • Ability to influence without authority, simplify complex security topics, and drive timely risk-based decisions across global and cross-functional teams.

Inclusion and Diversity

GE Healthcare is an Equal Opportunity Employer where inclusion matters. Employment decisions are made without regard to race, colour, religion, national or ethnic origin, sex, sexual orientation, gender identity or expression, age, disability, protected veteran status or other characteristics protected by law.

We expect all employees to live and breathe our behaviours: to act with humility and build trust; lead with transparency; deliver with focus, and drive ownership – always with unyielding integrity.

Our total rewards are designed to unlock your ambition by giving you the boost and flexibility you need to turn your ideas into world-changing realities. Our salary and benefits are everything you would expect from an organization with global strength and scale, and you will be surrounded by career opportunities in a culture that fosters care, collaboration and support.

#LI-Hybrid
#LI-MP2

Additional Information

Relocation Assistance Provided: Yes

Prêt à postuler chez GE HealthCare ?
Postuler chez GE HealthCare

À propos de GE HealthCare

At GE HealthCare, we see possibilities through innovation. We’re partnering with our customers to fulfill healthcare’s greatest potential through groundbreaking medical technology, intelligent devices, and care solutions. Better tools enabling better patient care. Together, we are not only building a healthier future but living our purpose to create a world where healthcare has no limits.

Voir tous les emplois chez GE HealthCare →

Emplois similaires

SciTec
Lead Application Security Engineer
SciTec
⚡ Postuler tôt Boulder, Colorado, United Stat... Sur site $155,000–$185,000
● Nouveau 👁 Vu ✓ Postulé il y a 3 h
Solirius Reply
Automation Engineer (Back End) - (Security Cleared)
Solirius Reply
⚡ Postuler tôt London, England, United Kingdo... Sur site
● Nouveau 👁 Vu ✓ Postulé il y a 4 h
payabl.
Senior Product Security Engineer
payabl.
⚡ Postuler tôt Limassol, Limassol, Cyprus Sur site
● Nouveau 👁 Vu ✓ Postulé il y a 4 h
Slash Financial
Software Engineer, Security
Slash Financial
⚡ Postuler tôt San Francisco Office Sur site $250,000–$350,000
● Nouveau 👁 Vu ✓ Postulé il y a 4 h
HUD
Security Engineer
HUD
⚡ Postuler tôt San Francisco Sur site
● Nouveau 👁 Vu ✓ Postulé il y a 4 h
Applied Intuition
Cybersecurity Software Engineer - New Grad (December 2027)
Applied Intuition
⚡ Postuler tôt Sunnyvale Sur site $130,000–$158,000
● Nouveau 👁 Vu ✓ Postulé il y a 5 h
Applied Intuition
Cloud Security Engineer
Applied Intuition
⚡ Postuler tôt Sunnyvale Sur site $133,000–$230,000
● Nouveau 👁 Vu ✓ Postulé il y a 5 h
Baseten
Security Engineer
Baseten
⚡ Postuler tôt San Francisco Hybride $150,000–$250,000
● Nouveau 👁 Vu ✓ Postulé il y a 5 h
Applied Intuition
Enterprise Security Engineer
Applied Intuition
⚡ Postuler tôt Sunnyvale Sur site $140,000–$180,000
● Nouveau 👁 Vu ✓ Postulé il y a 5 h

Inscrivez-vous pour des suggestions adaptées aux emplois que vous ouvrez et aux recherches que vous enregistrez.

Plus d’emplois chez GE HealthCare

Voir tous les emplois chez GE HealthCare →

Postuler maintenant
🤖

Doucement — un instant

JobsRadar a été conçu pour de vraies personnes qui traversent une période difficile dans leur recherche d’emploi — pas pour des requêtes automatisées. Vous cliquez beaucoup trop vite et vous êtes maintenant temporairement bloqué.

Revenez plus tard. Si vous cherchez réellement un emploi, nous sommes de votre côté — agissez simplement comme un être humain.

Catch your next role the second it’s posted.

Create a free account and we’ll watch the boards for you — the instant a job matches your search, it lands in your inbox or Telegram. No digging, no refreshing.

Create free account

Free forever · takes 30 seconds · already have one?

Prenez une longueur d’avance dans votre recherche d’emploi.

Rejoignez notre canal Telegram pour ce qui vous aide à décrocher le poste — références salariales, le pouls hebdomadaire du marché et les annonces de nouveautés. Pas de spam, que du signal.

Rejoindre le canal — c’est gratuit