Sr. Product Cybersecurity Engineer

Johnson Controls India COEE1

Johnson Controls

Applying data from both inside buildings and beyond, our customers can now manage operations systemically.

View all jobs at Johnson Controls

Job Title: Sr. Product Cybersecurity Engineer

Location: Pune, India

What you will do:

In this pivotal role within the Global Product Security team, you will be responsible for driving continuous improvement initiatives aligned with our cybersecurity maturity framework, ensuring proactive management of security and data privacy risks throughout the product lifecycle. You will leverage your expertise in secure software development practices to embed security and privacy by design within our product offerings.

How you will do it:

  • Provide cybersecurity guidance and expertise to product development teams and business leaders during all phases of the software development lifecycle.
  • Architect security and privacy by design into software applications for mobile, embedded systems, and cloud environments.
  • Drive secure SDLC activities including security requirements, architectures, threat models, and testing.
  • Periodically assess and refine security policies, standards, and compliance metrics.
  • Quantify product risk and identify appropriate security controls.
  • Review product architectures for security vulnerabilities and collaborate on remediation strategies.
  • Coordinate with third-party penetration testing teams to ensure comprehensive security assessments.
  • Maintain awareness of current security threats and vulnerabilities impacting our products.
  • Support incident response operations and vulnerability remediation activities.
  • Drive security awareness and training initiatives across the organization.

What we look for:

  • Bachelor's or higher degree in Engineering, Cybersecurity, or a related technical field.
  • 8-12 years of experience in product or application cybersecurity.
  • Strong knowledge of secure SDLC practices, security architectures, and compliance activities.
  • Proven experience in delivering results using agile methodologies.
  • Solid understanding of security threats, attack vectors, and appropriate security controls.
  • Excellent problem-solving and analytical skills.
  • Strong communication and interpersonal skills to convey complex security concepts to diverse audiences.
  • Familiarity with security frameworks such as NIST, ISO 27001, and GDPR.
  • Relevant cybersecurity certifications (e.g., CISSP, CEH) are a plus.

What we offer:

  • Competitive salary and performance-based bonuses.
  • Comprehensive benefits package including health, dental, and retirement plans.
  • Opportunities for professional development and continuous learning.
  • Collaborative and inclusive work environment.

* Salary range is an estimate based on our InfoSec / Cybersecurity Salary Index 💰

Job stats:  0  0  0

Tags: Agile CEH CISSP Cloud Compliance GDPR Incident response ISO 27001 NIST Pentesting Privacy Product security SDLC Security assessment Vulnerabilities

Perks/benefits: Career development Competitive pay Health care

Region: Asia/Pacific
Country: India

More jobs like this

Explore more career opportunities

Find even more open roles below ordered by popularity of job title or skills/products/technologies used.