Principal Engineer – Cyber Security
BANGL/RND - BANGALORE R&D, India
Baxter International Inc.
Aquí es donde salvas y sostienes vidas
En Baxter, estamos profundamente conectados por nuestra misión. No importa tu rol en Baxter, tu trabajo tiene un impacto positivo en la gente alrededor del mundo. Sentirá un propósito en toda la organización, ya que sabemos que nuestro trabajo mejora los resultados para millones de pacientes.
Los productos y terapias de Baxter se encuentran en casi cada hospital del mundo, el clínicas y en los hogares. Por más de 85 años hemos sido pioneros en innovaciones médicas significativas que transforman el cuidado en salud.
Juntos creamos un lugar donde somos felices, exitosos y nos inspiramos mutuamente. Aquí es donde puedes hacer tu mejor trabajo.
Únete a nosotros en la intersección de salvar y sostener vidas-donde tu propósito acelera nuestra misión.
Position Overview
A Principal Engineer, Cyber Security will be responsible for development of products and providing creative solutions associated with the design, development, and sustaining engineering for our new and existing product portfolio. The successful candidate will possess solid “hands-on” technical abilities, an excitement and energy for product development, and a passion for their work and the impact it has on meeting the needs of patients.
Essential Duties and Responsibilities:
- Work directly with software developers in building a “security by design” mindset by defining implementations and coding in line with the Application Security Program mandates.
- Implement embedded/cloud secure code solutions, design patterns, and coding guidelines that meet security and privacy requirements defined in the security plans, risk assessments, policies, and procedures.
- Support security project governance through scheduling activities, planning and prioritization.
- Proactively drive security solutions implementation in-alignment with the development leads, security architects and product owner(s).
- Drive feature implementations in line with the architecture via designs, coding, reviews and tests. Perform Proof of Concept (POC) activities as necessary.
- Review, analyze and mitigate SAST, DAST, SCA and penetration test findings in collaboration with the developers for various electromechanical medical devices product lifecycles.
- Review current software security control measures and implement security enhancements across multiple medical devices.
- Participate in post-market product analysis to support vulnerability investigations as required as well as be engaged in continuous security monitoring.
Qualifications / Experience and/or Background
- Bachelor's degree in Computer Science, Computer Engineering, a related field or equivalent demonstrated experience and knowledge.
- Minimum 5+ years of experience in software development or related fields.
- Minimum 3 years technical experience working with cyber security design/development for embedded systems.
- Experience working with each of the following:
Experience with C/C++, Python, Linux and/or security design within real-time operating systems.
Experience analyzing, interpreting, and mitigating security findings from multiple sources including SAST, DAST, SCA and penetration tests.
Embedded data at rest security implementations including Code Signing, Secure boot, and flash encryption implementations.
Embedded/IoT wired and wireless secure networking implementations within multiple layers of the OSI stack.
IoT/Embedded PKI solutions and implementation.
- Experience working with cyber security design/development for cloud systems/products is a plus.
- Experienced security developer able to interpret and guide software development teams on secure coding practices and application security test report interpretation for various coding languages and operating environments.
- Strong knowledge of secure software development lifecycle and practices including SAFe/ Agile methodologies for software development.
- Understanding of security by design principles and architecture level security concepts.
- Sound understanding and experience in implementing security technologies/techniques such as, Cryptographic Algorithms/Cipher Suites, Public key Infrastructure (PKI), Hardware/embedded authentication protocols, Secure Boot, and data-at-rest encryption methods.
- Experience implementing OWASP Top10 application security guidelines .
- Knowledge of embedded system architecture and security controls (e.g., firewall and border router configurations, wireless communication architectures, messaging authentication protocols.
- Experienced in generating, defining, and reviewing penetration test results through knowledge standard methodologies and tools including environmental configuration definition, security analysis, threat modeling, and system security audits.
- Knowledge of current and emerging security threats and techniques for exploiting security vulnerabilities.
- Exposure to international privacy requirements & cross-industry trends.
Personal Characteristics
- Excellent communication, inter-personal and leadership skills
- Firm decision maker and shall possess good influencing skills
- Openness to collaborate in interest of project/organization.
- Proactive and self-driven, possesses due sense of urgency
- Shall possess systems mindset and good problem-solving abilities.
- Working with multisite teams, Quality conscious and Process & customer Oriented
- Coaching capabilities.
A Career That Matters
Baxter’s employees are united in a mission to save and sustain lives. We are passionate about applying scientific innovation to meet the needs of the millions of people worldwide who depend on our medically necessary therapies and technologies. We focus on increasing access to healthcare, innovating in crucial areas of unmet need, and pursuing creative collaborations that bring our mission to life for patients every day.
Equal Employment Opportunity
Baxter is an equal opportunity employer. Baxter evaluates qualified applicants without regard to race, color, religion, gender, national origin, age, sexual orientation, gender identity or expression, disability/handicap status or any other legally protected characteristic.
Adaptaciones razonables
Baxter está comprometida para trabajar y proveer ajustes razonables para personas con discapacidades, a nivel global. Si por una condición médica o discapacidad, necesitas algún ajuste en cualquier etapa del proceso de aplicación o entrevista, por favor ingresa a este enlace y déjanos saber la naturaleza de tu requerimiento junto a tu información de contacto.
Recruitment Fraud Notice
Baxter has discovered incidents of employment scams, where fraudulent parties pose as Baxter employees, recruiters, or other agents, and engage with online job seekers in an attempt to steal personal and/or financial information. To learn how you can protect yourself, review our Recruitment Fraud Notice.
* Salary range is an estimate based on our InfoSec / Cybersecurity Salary Index 💰
Tags: Agile Application security Audits C Cloud Computer Science DAST Encryption Firewalls Governance IoT Linux Monitoring OWASP PKI Privacy Python Risk assessment SAST SDLC Security analysis Vulnerabilities
Perks/benefits: Career development
More jobs like this
Explore more career opportunities
Find even more open roles below ordered by popularity of job title or skills/products/technologies used.