23 hours ago
Bengaluru, IndiaSenior
Responsibilities
- Own and execute product-security engineering work for Cortenic connectivity solutions, including security debt reduction, remediation SLAs, dashboards, and continuous improvement.
- Design, maintain, and improve GitHub security pipelines and standard workflows for dependency, secret, code-quality, artifact, container, and cloud-security scans.
- Onboard repositories and projects to security workflows and validate branches, environments, secrets, images, and release-stage configurations.
- Review cloud, Kubernetes, Artifact Registry, IAM, workload identity, monitoring, and logging configurations for security gaps.
- Triage, prioritize, remediate, and verify findings from Dependabot, JFrog Xray, SonarQube, Orca, Tanium, CrowdStrike, Burp Suite, and Secret Scanning.
- Partner with developers to resolve high and critical dependency and container vulnerabilities before pull-request merge or release.
- Configure security quality gates, generate SBOMs, prepare release-security reports, assess exceptions, and provide evidence for Quality, audit, and release sign-off.
- Create security runbooks, onboarding checklists, configuration guides, evidence packs, and technical reference material.
- Support penetration testing through scope definition, environment preparation, report review, remediation planning, and closure evidence.
- Support incident response, customer and security-contract questions, newly disclosed vulnerability assessments, compliance readiness, and audit activities.
Requirements
- Bachelor’s degree in Computer Science, Information Security, Cybersecurity, Software Engineering, or a related field.
- At least 7 years of hands-on cybersecurity, product security, cloud security, or DevSecOps experience in software or product engineering environments.
- Strong Google Cloud Platform experience preferred, plus AWS or Azure experience.
- Practical experience with CI/CD security, GitHub workflows, vulnerability and dependency scanning, container/image scanning, secret scanning, and release-security gates.
- Experience with tools such as Dependabot, SonarQube, JFrog Xray, Orca, Tanium, CrowdStrike, Burp Suite, SAST/DAST tools, and SIEM or logging platforms.
- Ability to translate scan findings into prioritized remediation plans, collaborate with engineering teams, and produce audit-ready evidence.
- Working knowledge of ISO 27001, SOC 2, NIST, GDPR, HIPAA, GxP, SaMD, medical-device cybersecurity, or other regulated product-security expectations is preferred.
- Experience with enterprise or global cybersecurity teams, cybersecurity management plans, cyber test reports, security requirements, risk assessments, threat modeling, and security governance is preferred.
- Experience supporting incident response, customer escalations, external disclosures, vulnerability assessments, certification readiness, and Quality audits is preferred.
- Familiarity with Jira, Confluence, Scrum practices, developer enablement, sprint-backlog integration, and cross-functional stakeholder communication.
Tech Stack
Categories
About Bayer
Bayer is a global life-sciences company that develops and sells prescription pharmaceuticals, consumer health brands (including Aspirin), and agricultural seeds, traits, and crop-protection products, plus digital farming tools, for patients, consumers, and farmers. It is a public company founded in 1863 and headquartered in Leverkusen, Germany. Bayer acquired Monsanto in 2018, making Crop Science one of its three core businesses alongside Pharmaceuticals and Consumer Health.
