Baxter International

Principle Engineer, Cybersecurity

Baxter International
Apply
18 hours ago
Bengaluru, IndiaStaff+

Responsibilities

  • Lead cybersecurity architecture and implementation for medical devices, connected systems, digital platforms, and hosted solutions.
  • Create and maintain threat models, security requirements, risk assessments, DPIAs, product security whitepapers, MDS2 statements, SBOMs, and security evidence packages.
  • Lead threat modeling, security architecture reviews, vulnerability assessments, penetration testing, fuzz testing, secure code analysis, and vulnerability scanning.
  • Establish product vulnerability and cybersecurity risk management governance processes.
  • Monitor threat intelligence, CVEs, CWEs, and zero-day vulnerabilities and assess their impact on Baxter products.
  • Assess third-party software, open-source components, and off-the-shelf technologies for secure use.
  • Support cybersecurity audits, compliance initiatives, incident investigations, response, and recovery activities.
  • Represent product cybersecurity with regulatory agencies and external stakeholders and contribute to customer-facing security communications.
  • Lead cybersecurity project planning and execution while mentoring junior engineers and technical teams.

Requirements

  • Bachelor’s degree in Computer Science, Engineering, Information Security, Mathematics, Information Management, or a related technical discipline is required; an advanced degree is preferred.
  • At least 5 years of experience in software development, cybersecurity engineering, product security, or secure software development lifecycle activities.
  • Strong understanding of application security and secure development practices throughout the software lifecycle.
  • Experience with OWASP Top 10 vulnerabilities, threat modeling, security risk assessments, secure design reviews, and vulnerability analysis.
  • Experience with threat modeling methodologies such as STRIDE, DREAD, LINDDUN, PASTA, or similar frameworks.
  • Experience with vulnerability scanning, penetration testing, fuzz testing, and secure code analysis tools.
  • Experience with tools such as Coverity, Black Duck, Fortify, Nessus, or equivalent technologies.
  • Experience analyzing threat intelligence, CVEs, and CWEs and translating findings into product improvements.
  • Strong technical writing, communication, analytical, and problem-solving skills.
  • Ability to influence technical direction, lead cross-functional initiatives, and drive business-aligned decisions.
  • Preferred experience includes cybersecurity requirements for medical devices, connected healthcare systems, cloud platforms, and hosted software applications.
  • Preferred familiarity with NIST 800-53, ISO 27001/27002, IEC TR 80001, UL 2900, FIPS 140, ICS-CERT guidance, and privacy-by-design principles.
  • Preferred security certifications include CSSLP, CAP, CISSP, or equivalent.

Categories

Baxter International

About Baxter International

10,000+ employees

For nearly a century, we have delivered on our commitment to saving and sustaining the lives of patients, working alongside clinicians and providers around the world. We believe every person — regardless of who they are or where they are from — deserves a chance to live a healthy life, free from illness and full of possibility. At the intersection of progress and purpose is where we are redefining what it means to be a global medtech leader. It is where we are relentlessly pursuing healthcare transformation, fueled by our compassion for patients and providers and the challenges they face. It is where bold ideas meet the promise for meaningful change in the world around us. We are there, at every step of the journey, to help clinicians deliver the best care possible.

Contact me