Senior product Security Analyst

Company : GE HealthCare
Job Description

In this role, you will:• Be able to scope and participate in hardware and software penetration tests, vulnerability identification and vulnerability risk assessment• Engage in incident response methods lead incident response processes related to product cyber• Create and track meaningful metrics around product cyber risk and compensating controls• Create vulnerability and incident trend analysis to improve product design• Maintain cyber Bills of Material and conduct proactive vulnerability monitoring and assessment on cyber components• Engage and administer End Of Life processes for digital products• Consult, architect on security requirements and utilize best practices to meet them• Engage in application and domain-specific threat modeling and attack surface analysis/reduction• Help prepare reports at appropriate levels of confidentiality for stakeholders to view• Responding promptly and in detail to customer-sponsored penetration tests• Provides guidance on automated testing tools and techniques
Desired Characteristics:• Experience with cyber security framework (NIST 800-53, ISO 27001, IEC 62443, etc.) implementation and governance• Program and Project Management experience; expertise with Agile development teams• Experience with secure coding principles; code signing; secure boot• Experience with penetration testing and ethical hacking• Knowledge of CI/CD and automation tools (Chef, Git, Jenkins)• Knowledge of Identity management and identity federation (SAML, Oauth, SCIM, XACML)• Experienced in developing web services (SOAP/REST)• Must be available for on call for potential security response• Knowledge of application risk identification and evaluation techniques• Knowledge of Cyber Security and full knowledge of multiple related engineering functions• Experience securing applications within cloud platforms such as AWS, Azure and alike.• Experience with broad set of information security technologies and processes within a SaaS, IaaS, PaaS, or cloud environment