Senior Security Engineer / Threat Analyst
IND Bengaluru - Technology Campus, India
BD (Becton, Dickinson and Co.)
The primary work will involve vulnerability assessments, which includes threat research and analysis, potential impact, exploitability. Assessments will involve product and code analysis to determine the exploitability of vulnerability, as well as assessing safety risk, severity and likelihood.Job Description
Responsibilities:
- Develop and implement strategies to identify, analyze, and mitigate cyber threats targeting BD products.
- Enhance threat hunting activities to detect and respond proactively to potential security risks.
- Conduct in-depth threat research on vulnerabilities, attack vectors, and possible impacts.
- Develop and maintain artefacts required for ATO submissions, including vulnerability scans, System Security Plans (SSPs), and Risk Assessment Reports
- Determine and document likelihood of exploitability and potential safety risks for potentially impacted products.
- Calculate residual risk for vulnerabilities by considering compensating controls, mitigations, and operational environments.
- Document all threat research and vulnerability assessments in clear, concise, and actionable reports.
- Work with BD public relations teams, providing accurate and timely information on threat status, impact, and analysis for product leadership and customers.
- Partner with product security officers and cross-functional teams to define threat impacts, implement mitigations, and coordinate responses.
- Support the preparation of regular threat intelligence reports and briefings to senior management and stakeholders.
- Continuously enhance threat intelligence processes, tools, and technologies.
- Stay up to date with the latest cybersecurity trends, vulnerabilities, and emerging threats.
- May perform other duties as required.
Qualifications:
- At least 5 years of experience in cybersecurity, with expertise in threat hunting and vulnerability analysis.
- Strong knowledge of cybersecurity threats, vulnerabilities, attack vectors, and controls (e.g., authentication, cryptography, secure coding).
- Familiarity with DevSecOps practices and tools for SCA, SAST, DAST, and vulnerability scanning.
- Experience with security frameworks such as NIST 800-53, ISO 27001, GDPR, or IEC 81001-5.
- Knowledge and experience with various programming languages such as C/C++, C#, Python, JavaScript, Ruby, PHP, Go, Swift a plus
- Strong understanding of MS Windows and Linux operating systems (past and current) and the .NET framework.
- Experience with threat intelligence platforms, threat hunting tools, and cybersecurity frameworks.
- Experience implementing and demonstrating compliance to security frameworks such as NIST 800-53, IEC 81001-5, HITRUST, HIPAA, GDPR, ISO 27001, SOC 2
- Ability to work in a fast-paced, dynamic environment and manage multiple priorities.
- Strong analytical and problem-solving abilities.
- Strong written and verbal communication skills.
- Strong technical acumen.
- Relevant certifications such as Security+, CEH, or GIAC are a plus.
Required Skills
Optional Skills
.
Primary Work LocationIND Bengaluru - Technology CampusAdditional LocationsWork Shift* Salary range is an estimate based on our InfoSec / Cybersecurity Salary Index 💰
Tags: C CEH Code analysis Compliance Cryptography DAST DevSecOps GDPR GIAC HIPAA HITRUST ISO 27001 JavaScript Linux Monitoring NIST NIST 800-53 PHP Product security Python Risk assessment Risk Assessment Report Ruby SAST SOC SOC 2 System Security Plan Threat detection Threat intelligence Threat Research Vulnerabilities Vulnerability scans Windows
More jobs like this
Explore more career opportunities
Find even more open roles below ordered by popularity of job title or skills/products/technologies used.