Overview
As a Principal Product Security Engineer, you will lead product security vulnerability management activities, create and maintain software bills of materials (SBOMs), and support remediation and compliance efforts.
What you'll do
- Contribute towards triaging all vulnerabilities, regardless of severity, across all SBOMs in the tool.
- Generate SBOMs according to FDA requirements.
- Include end-of-support and software level-of-support information for each component in SBOMs.
- Continuously monitor, review, and triage newly identified vulnerabilities from SBOM monitoring activities.
- Own and automate SBOM generation.
- Analyze identified vulnerabilities and provide patching recommendations and other appropriate remediation actions.
- Technically lead a group of engineers working on Product Security and vulnerabilities.
- Propose solutions.
- Create and maintain SBOMs for products and related software components.
- Review, analyze, and triage vulnerabilities identified by SBOM scanning tools.
- Partner with cross-functional teams to assess risk and prioritize remediation efforts.
- Monitor and track vulnerability status to ensure timely and effective resolution.
- Develop or use scripts to automate and improve vulnerability management processes.
- Maintain thorough and accurate documentation of findings, actions taken, and outcomes.
- Provide recommendations for component upgrades based on vulnerability findings and observed trends.
What you'll need
- Bachelor’s degree in computer science, software engineering, or equivalent.
- 12 to 16 years of relevant experience in product security, threat modelling, threat analysis, and CVSS scoring.
- Understanding of product architecture, identification of security gaps, security-enabled technical proposals, and risk assessment.
- Proficiency in Python or another scripting language.
- Experience developing Python scripts and automation utilities to improve vulnerability management workflows.
- Experience in vulnerability management.
- Vulnerability assessment and triage experience.
- Experience working in a regulated industry.
- Familiarity with SBOM management tools such as Dependency-Track.
- Medical device cybersecurity guidance documentation and audit readiness.
Nice to have
- Experience in medical device cybersecurity or other regulated industries.
- Familiarity with FDA Cybersecurity Guidance, IEC 62304, IEC 81001-5-1, or similar standards.
- Experience supporting product security compliance initiatives.
- Knowledge of software composition analysis (SCA) tools and open-source governance.
Details
- Location: Nanakramguda, Hyderabad, India.
Read the full description and apply on the company’s own careers page.