GE Healthcare

Senior Software Engineer

IND19-01-Bengaluru-EPIP 122 (Phase II) Full time

Job Description Summary

We are looking for a Security and Privacy Specialist responsible for safeguarding the confidentiality, integrity, and availability of our medical products throughout their lifecycle. This role will act as the primary liaison for all security and privacy concerns, working closely with cross-functional teams to identify, evaluate, and mitigate risks in alignment with regulatory requirements and industry best practices.

GE Healthcare is a leading global medical technology and digital solutions innovator. Our mission is to improve lives in the moments that matter. Unlock your ambition, turn ideas into world-changing realities, and join an organization where every voice makes a difference, and every difference builds a healthier world.

Job Description

Key Responsibilities

  • Act as the security and privacy liaison for medical product development teams.

  • Perform risk assessments and threat modeling for new and existing products.

  • Identify and evaluate OS and kernel-level vulnerabilities, ensuring secure system architecture.

  • Assess network and software-level vulnerabilities, including protocol weaknesses and application security flaws.

  • Define and enforce security requirements aligned with HIPAA, GDPR, and other relevant regulations.

  • Collaborate with engineering teams to implement secure coding practices and vulnerability remediation.

  • Monitor emerging threats and maintain a proactive security posture for medical devices.

  • Prepare and maintain documentation for compliance audits and regulatory submissions.

Required Qualifications

  • Bachelor's Degree in Computer Science or “STEM” Majors (Science, Technology, Engineering and Math) or Cybersecurity with a minimum of 6+ years of experience in product security, preferably in healthcare or regulated industries.

  • Proficiency in Operating System and Kernel-level vulnerabilities (e.g., privilege escalation, memory corruption).

  • Network security (e.g., TCP/IP stack, encryption protocols, intrusion detection).

  • Software vulnerabilities (e.g., OWASP Top 10, secure coding principles).

  • Hands-on experience with risk assessment methodologies (e.g., ISO 14971, NIST RMF, STRIDE, DREAD).

  • Familiarity with medical device security standards (e.g., FDA cybersecurity guidance, IEC 62304).

  • Proficiency in vulnerability scanning tools and penetration testing frameworks.

Preferred Skills

  • Experience with embedded systems and real-time operating systems (RTOS).

  • Knowledge of cryptographic algorithms and secure key management.

  • Certifications such as CISSP, CSSLP, or HCISPP are a plus.

Soft Skills

  • Excellent communication and stakeholder management skills.

  • Ability to translate technical risks into business impact.

  • Good analytical and problem-solving mindset.

Inclusion and Diversity

GE Healthcare is an Equal Opportunity Employer where inclusion matters. Employment decisions are made without regard to race, color, religion, national or ethnic origin, sex, sexual orientation, gender identity or expression, age, disability, protected veteran status or other characteristics protected by law.

We expect all employees to live and breathe our behaviors: to act with humility and build trust; lead with transparency; deliver with focus, and drive ownership – always with unyielding integrity.

Our total rewards are designed to unlock your ambition by giving you the boost and flexibility you need to turn your ideas into world-changing realities. Our salary and benefits are everything you’d expect from an organization with global strength and scale, and you’ll be surrounded by career opportunities in a culture that fosters care, collaboration and support.

#LI-AM11

#LI-Hybrid

Additional Information

Relocation Assistance Provided: Yes