JobRaahGet matched free

Jobs

Product Security Engineer

smithnephew · IND - NonGBS-Pune-Kharadi · India · Hybrid

Posted Oct 5, 2026

Apply with JobRaah

Sign up free: we match you to jobs like this, tailor your application and fill the form. 2 free applications every day.

Life Unlimited. At Smith+Nephew, we design and manufacture technology that takes the limits off living. We're on the lookout for an individual who is ready to make an impact in medical equipment industry. If you're eager to be part of a dynamic environment that fosters growth and collaboration, look no further. Explore our latest job opening for Product Security Engineer role and you will as Product Cybersecurity Engineer focus on product security tooling, will provide hands on cybersecurity tool engineering in support of the Product Security team with the goal of ensuring Smith + Nephew products and their data is secure and resilient to cybersecurity threats. We encourage you to apply for this exciting opportunity. What will you be doing? Your will collaborate with a diverse cohort of internal stakeholders to design, engineer, and ensure implementation of security tools that are utilized through the entire product lifecycle (e.g. threat model, Static Application Security Testing, Dynamic Application Security Testing, Software Composition Analysis). You will be responsible for running security scans (e.g. Static Application Security Testing, Dynamic Application Security Testing, Software Composition Analysis) and support the creation of Software Bill of Materials (SBOMs) based on an understanding of the products and the tools. Technical Cybersecurity Architecture and Engineering Services - Lead the strategy and ensure the maintenance of cybersecurity tools in support of multiple Smith + Nephew technologies, capital devices, digital accessories, connected infrastructures and software applications. Product Security Testing and Assessment - Lead the execution and integration of cybersecurity testing and assessment activities throughout the development lifecycle - which includes but is not limited to Static Application Security Testing, Dynamic Application Security Testing, and Software Composition Analysis. Vulnerability response support - Provide technical expertise in evaluating and assessing potential vulnerabilities, support vulnerability response efforts, and effectively communicate risks and mitigation strategies to the business. Secure-Software Development Life Cycle - Help develop and mature Global Product Security Strategy and Secure-Software Development Life Cycle (S-SDLC) to ensure robust cyber security controls are present and effective in our products from product conceptualization through commercial launch and ultimately product/product family decommissioning. Threat model - Provide technical leadership and competency in creating comprehensive threat models using industry-standard methods in close collaboration with the product teams and the product security engineers. What will you need to be successful? Education: Bachelor's or equivalent experience or Master’s degree in Computer Science or Information Technology. Licenses/Certifications : Current CISM, CISSP, CRISC, or similar certification preferred. …