Sr. Product Cybersecurity Engineer
Johnson Controls India COEE1
Applications have closed
Johnson Controls
Applying data from both inside buildings and beyond, our customers can now manage operations systemically.Job Title: Sr. Product Cybersecurity Engineer
Location: Pune, India
What you will do:
In this pivotal role within the Global Product Security team, you will be responsible for driving continuous improvement initiatives aligned with our cybersecurity maturity framework, ensuring proactive management of security and data privacy risks throughout the product lifecycle. You will leverage your expertise in secure software development practices to embed security and privacy by design within our product offerings.
How you will do it:
- Provide cybersecurity guidance and expertise to product development teams and business leaders during all phases of the software development lifecycle.
- Architect security and privacy by design into software applications for mobile, embedded systems, and cloud environments.
- Drive secure SDLC activities including security requirements, architectures, threat models, and testing.
- Periodically assess and refine security policies, standards, and compliance metrics.
- Quantify product risk and identify appropriate security controls.
- Review product architectures for security vulnerabilities and collaborate on remediation strategies.
- Coordinate with third-party penetration testing teams to ensure comprehensive security assessments.
- Maintain awareness of current security threats and vulnerabilities impacting our products.
- Support incident response operations and vulnerability remediation activities.
- Drive security awareness and training initiatives across the organization.
What we look for:
- Bachelor's or higher degree in Engineering, Cybersecurity, or a related technical field.
- 8-12 years of experience in product or application cybersecurity.
- Strong knowledge of secure SDLC practices, security architectures, and compliance activities.
- Proven experience in delivering results using agile methodologies.
- Solid understanding of security threats, attack vectors, and appropriate security controls.
- Excellent problem-solving and analytical skills.
- Strong communication and interpersonal skills to convey complex security concepts to diverse audiences.
- Familiarity with security frameworks such as NIST, ISO 27001, and GDPR.
- Relevant cybersecurity certifications (e.g., CISSP, CEH) are a plus.
What we offer:
- Competitive salary and performance-based bonuses.
- Comprehensive benefits package including health, dental, and retirement plans.
- Opportunities for professional development and continuous learning.
- Collaborative and inclusive work environment.
* Salary range is an estimate based on our InfoSec / Cybersecurity Salary Index 💰
Tags: Agile CEH CISSP Cloud Compliance GDPR Incident response ISO 27001 NIST Pentesting Privacy Product security SDLC Security assessment Vulnerabilities
Perks/benefits: Career development Competitive pay Health care
More jobs like this
Explore more career opportunities
Find even more open roles below ordered by popularity of job title or skills/products/technologies used.