Verified today
Staff Site Reliability Engineer
About the role
The Product Security team in Gurugram, India seeks a Staff Site Reliability Engineer to design cyber-secure medical devices and applications. Day-to-day work includes leading product cybersecurity risk analysis, threat modeling, penetration testing, code reviews, and integrating automated security testing across the SDLC for robotics and enabling technology products. This is a hybrid role requiring 10% travel.
What you’ll do
- Participate in project planning, product cybersecurity risk analysis, and risk mitigation strategies
- Lead product cybersecurity tasks and activities established by product design controls and SDLC procedures
- Work with cross-functional teams including Quality, Regulatory, and Marketing to drive alignment on product Cybersecurity and HIPAA compliance
- Provide input to project management on scheduling, milestone achievement, and project challenges
- Perform systems hardening, automated and manual penetration testing, automated vulnerability scanning, and issue remediation
- Develop and implement security policies and procedures to ensure compliance with industry standards
- Research and implement best practices in product cybersecurity architecture around access control, code injection, information exposure, firewalls, and multi-factor authentication
- Support cybersecurity documentation requests from legal and sales teams and participate in incident response, V&E assessments, and security incident resolution
What you’ll bring
- Bachelor's degree in Software Engineering, Computer Science, or related discipline
- 6+ years of work experience
- Perform cybersecurity risk analysis and threat modeling
- Develop mitigation strategies and security policies for compliance
- Conduct manual and automated penetration testing and vulnerability scanning
- Perform manual and automated code reviews for embedded and clinical application software
- Integrate automated security testing into all phases of SDLC
- Automate routine tasks and extract data using PowerShell, Ruby, or Python
Nice to have
- Experience with malware analysis, vulnerability assessment, and penetration testing using off-the-shelf tools
- Understanding of security standards/frameworks like NIST 800-53, IEC80001-2-8, IEC 27002, ISO 27799, IEC 15408-2, and IEC 62443-3-3
- Solid understanding of Linux operating systems
- Experience in securing medical devices or embedded devices
- Understanding of networking concepts
- Understanding of quality standards like IEC 62304, IEC 60601, and 21CRF 820
- Experience with threat modeling and risk assessment
- Security certifications such as CISSP, CSSLP, or CISM
Skills
Education
Bachelor's degree in Software Engineering/ Computer Science or related discipline