Talent.com
This job offer is not available in your country.
Product Security Governance Engineer

Product Security Governance Engineer

IN19 Alcon Laboratories (India) Pvt Ltd Companybangalore, India
18 hours ago
Job description

Summary of the Position

Alcon is looking to hire Product Security Governance Engineer.

JOB PURPOSE

Support Product Security and Threat Intelligence solutions.

Provide support for performing penetration tests, SAST / DAST / SCA and preparing reports for findings for Alcon Products (SaMD-Software As a Medical Device, SiMD-Software In a Medical Device and Digital Applications).

Communicate prioritization of vulnerabilities for remediation to stakeholders.

Build competencies with gap analysis, process changes, and integration of automated tools across the product lifecycle.

Review and recommend remediations from security software tooling analysis.

Well-versed in the product security landscape.

Work closely with the Bangalore and Lake Forest Product Security functions, Software Development, Verification and Validation, Quality, Regulatory and Digital Health Software teams to coordinate oversight of security framework.

Help in building and developing automation with automated scripts and tools as applicable.

Help in leading efforts to close the security related gaps in Alcon’s product security framework.

Build strong collaboration with cross-functional stakeholders and teams across the product development lifecycle.

Communicate stakeholders concerning discovered vulnerabilities and remediation suggestions.

Contribute to analyzing product security risks, assessing security gaps, and recommending possible solutions.

Provides accurate documentation of existing metrics and KPIs, and security process.

Collaborating with the Product Security Incident Response Team to support incident response activities and address identified incidents as needed.

Works closely with the Product Security team to support product security activities and associated deliverables

JOB FUNCTIONS

Essential Functions

You will be responsible for maintaining robust product security measures across all stages of our product development and post launch process. Supporting Alcon Product Security Process by performing product security activities for all Alcon products. Perform / support Post Market Monitoring risk analysis of in-market products; document and score findings, communicate results to development teams. Support yearly penetration tests, SAST / DAST / SCA as needed and directed, create or reviewing final reports. You will collaborate with cross-functional teams to integrate security best practices and ensure the protection of our products against potential threats. Implement and enforce security best practices throughout the entire software development lifecycle (SDLC) Stay updated on the latest security trends, regulatory standards, vulnerabilities, and mitigation strategies. Summarize product risks for stakeholder reports. Interact with outside vendors, write / modify / convey host module requirements, and be able to identify and hold outside vendors accountable for their deliverables. Review security updates for possible negative affects against in-market products and monitor media for new vulnerabilities. As needed write and / or review patching and update communications to customers and disseminate. Support preparation software for SAST, DAST, Vulnerability scans, fuzzing scans; review and document results, provide recommendations for remediations.

QUALIFICATIONS

Minimum Requirement

BS of Computer engineering or Information Security or other related discipline with 6 years’ experience; or 8 years of relevant experience. Solid understanding of Software Development Lifecycle Management (SDLC) – (Agile / Scrum, iterative) Proven experience in a Product Security field or in a similar role. Familiar with the following types of tools : SAST, DAST, SBOM, network forensics tools, fuzzing, standard penetration test tools and GRC tool are a plus. Knowledge of cybersecurity concepts, networking and software development process is plus. Ability to coordinate and balance activities between multiple associates Ability to work independently, proactively identify issues, recommend, and implement solutions, and deliver quality results on schedule while managing multiple tasks and internal customers. Ability to follow directions, identify issues, recommend and deliver quality results on schedule. Good interpersonal & Communication skills to build positive departmental and inter-departmental relationships in a virtual, remote and asynchronous environment. Prior experience on medical device software and data integrity. Understanding of FDA / ISO regulations related to medical device software. Strong understanding of secure coding principles, encryption, and authentication protocols

Familiarity with industry standards and frameworks such as OWASP, NIST, UL-2900 and ISO 27001.

Excellent communication and collaboration skills. Good interpersonal & Communication skills to build positive departmental and inter-departmental relationships in a virtual, remote, and asynchronous environment. Understanding of Window OS services, processes, driver and registry configurations and analysis techniques is a plus Fluent English; excellent verbal and written communication skills

Knowledge, Skills and Abilities

Personal Effectiveness Competencies :

Project Excellence - Fundamental

Continuous Learning - Intermediate

Digital and Technology Savvy - Intermediate

Operational Excellence - Intermediate

Breakthrough Analysis - Intermediate

Organizational Savvy - Intermediate

Skills and Knowledge :

STEAM – Applied Science, Technology, Engineering, Arts and Math

Technical Development Methodology for Medical Devices (21 CFR 820.30, ISO 13485)

Systems Engineering or Risk Management for Medical Device (ISO 14971)

Medical Device Software – Software Life Cycle Processes (IEC 62304)

Regulations and Guidelines associated with software development.

Excellent verbal English communication skill (in a remote environment)

Microsoft Office suite (i.e., Word, Excel, Visio)

Experiences

Cross Functional collaboration - Primary

New Product Innovation - Secondary

Accountability - Primary

Influencing without Authority - Primary

Managing Crisis – Secondary

Functional Breadth - Secondary

Employment scams : Alcon is aware of employment scams which make false use of our company name or leader’s names to defraud job seekers. Alcon does not offer any positions without interview and never asks candidates for money. All our current job openings are displayed here on the Careers section of our website, where you can search for open positions and apply directly.

If you have encountered a job posting or been approached with a job offer that you suspect may be fraudulent, we strongly recommend you do not respond, send money or personal information, and check our website for current job openings.

Create a job alert for this search

Product Security Engineer • bangalore, India

Related jobs
  • Promoted
Senior Product Security Engineer

Senior Product Security Engineer

sliceBengaluru, Karnataka, India
We’ve all felt how slow, confusing, and complicated banking can be.We’re building every product from scratch to be fast, transparent, and feel good, because we believe that the best products transc...Show moreLast updated: 30+ days ago
  • Promoted
Saviynt IGA Engineer / Developer - Identity Governance & Administration (IGA)

Saviynt IGA Engineer / Developer - Identity Governance & Administration (IGA)

Sentinelhosur, tamil nadu, in
Saviynt IGA Engineer / Developer - Identity Governance & Administration (IGA).The security function of a world renowned manufacturing organisation for power tools is seeking a Saviynt IGA Engineer ...Show moreLast updated: 1 day ago
  • Promoted
Cyber Security Engineer

Cyber Security Engineer

YASH Technologieshosur, tamil nadu, in
The AppSec Engineer is a specialized cybersecurity role focused on DevOps engineering principles.While the expectation of their sibling role – SAE – is to have practical working security knowledge,...Show moreLast updated: 25 days ago
  • Promoted
Lead Application Security Engineer

Lead Application Security Engineer

InMobi AdvertisingBengaluru, India
InMobi is the leading provider of content, monetization, and marketing technologies that fuel growth for industries around the world. Our end-to-end advertising software platform, connected content,...Show moreLast updated: 30+ days ago
  • Promoted
Senior Product Security Engineer

Senior Product Security Engineer

Pocket FMBengaluru, Karnataka, India
Pocket FM is the world’s largest audio entertainment platform, revolutionizing the way stories are told and consumed.We bring together storytelling, technology, and creativity to deliver an immersi...Show moreLast updated: 30+ days ago
  • Promoted
Lead Security Engineer

Lead Security Engineer

ArcanaBengaluru, IN
As our Lead Security Engineer, you'll own and elevate Arcana's overall security posture - cloud, on-prem, and everything in between. You'll design and enforce policies, automate controls, and harden...Show moreLast updated: 30+ days ago
  • Promoted
Lead Security Engineer

Lead Security Engineer

interface.aiBangalore, IN
Our cutting-edge Generative AI-powered platform serves over 100 banks and credit unions, delivering hyper-personalized customer interactions across voice, chat, and employee-assisting solutions.To ...Show moreLast updated: 28 days ago
  • Promoted
Loop Health - Security Engineer

Loop Health - Security Engineer

Loop healthBangalore
About Us : Were a fast-growing fintech company transforming how people access insurance and healthcare services.With a team of 50+ engineers split across multiple pr...Show moreLast updated: 18 days ago
  • Promoted
Cyber Security Engineer with Splunk

Cyber Security Engineer with Splunk

IntraEdgeHosur, Tamil Nadu, India
Position : Cyber Security Engineer (L3) Location : Remote Experience Level : 5+ Years Job Type : Full-time Job Summary : This role will lead the development and implementation of intelligent securi...Show moreLast updated: 30+ days ago
  • Promoted
Security Engineer (Remote)

Security Engineer (Remote)

DigiHelic Solutions Pvt. Ltd.hosur, tamil nadu, in
Remote
We are looking for a proactive and experienced.In this role, you will design, implement, and maintain.The ideal candidate will have deep. Monitor cloud environments for.AWS-native and third-party to...Show moreLast updated: 1 day ago
  • Promoted
Security Engineer - Applications Security

Security Engineer - Applications Security

theSocialsBangalore
Job Description : We are seeking an experienced Security Engineer with strong expertise in Application Security, Cloud Security, and VAPT to join our client's en...Show moreLast updated: 28 days ago
Security Defense Engineer

Security Defense Engineer

SAP FioneerBengaluru, KA, IN
Quick Apply
Innovation is and will always be the core of SAP Fioneer, and it is the promise of why we were spun out of SAP : agility, innovation, and delivery. SAP Fioneer builds on a heritage of outstanding tec...Show moreLast updated: 30+ days ago
  • Promoted
Product Security Engineer II

Product Security Engineer II

FICOBengaluru, Karnataka, India
Join our world-class team today and fulfill your career potential!.As a Product Security Engineer II in Cyber Security, you will be supporting security governance for a wide set of customer-facing ...Show moreLast updated: 23 days ago
  • Promoted
Pluralsight - Product Security Engineer - SAST / DAST

Pluralsight - Product Security Engineer - SAST / DAST

PluralsightBangalore
Job Description : The Product Security Engineers work closely with engineering teams to secure our Pluralsight platform.They will work on various Secure SDL programs ...Show moreLast updated: 8 days ago
Product Security - Practice Head

Product Security - Practice Head

Saaki Argus & Averil ConsultingBangalore Rural, Karnataka, India
Quick Apply
Our client is a leading Engineering & R&D company, having presence globally.Product Security - Practice Head.Bangalore, Pune (Work from Office). Understand client pain points and provide pro...Show moreLast updated: 30+ days ago
  • Promoted
Cyber Security Engineer

Cyber Security Engineer

CUS Techhosur, tamil nadu, in
We are seeking a highly skilled and detail-oriented.The ideal candidate will have strong technical expertise in security tools, frameworks, and compliance standards, along with a proactive approach...Show moreLast updated: 26 days ago
  • Promoted
Senior Security Engineer - Product Security

Senior Security Engineer - Product Security

People Gamut HR SolutionsBangalore
As a part of the world-class engineering team, that is focused on solving some unique problems in the space (and one that has been delivering to commitments, as per our customer testimonials) we ar...Show moreLast updated: 30+ days ago
  • Promoted
EdgeVerve - Product Security Engineer - Penetration Testing

EdgeVerve - Product Security Engineer - Penetration Testing

EdgeverveBangalore
Job Objective : As a Product Security Engineer, you'll play a vital role in ensuring the security of our products, particularly those catering to the financial ...Show moreLast updated: 30+ days ago
  • Promoted
Product Security Engineer

Product Security Engineer

TravelokaBengaluru, Karnataka, India
Product Security Engineer at Traveloka will be required to ensure that our products and services are shipped with high security standards through application security testing, hardening, and secure...Show moreLast updated: 30+ days ago
  • Promoted
  • New!
▷ [Immediate Start] Product Security Engineer II

▷ [Immediate Start] Product Security Engineer II

FICOBengaluru, Karnataka, India
FICO (NYSE : FICO) is a leading global analytics software company, helping businesses in 100+ countries make better decisions. Join our world-class team today and fulfill your career potential! The ...Show moreLast updated: 2 hours ago