Senior Product Security Engineer

Security EngineerSecurity EngineerFull TimeRemoteSeniorTeam 10,001+H1B No SponsorCompany SiteLinkedIn

Location

United States

Posted

4 days ago

Salary

$96K - $132K / year

Seniority

Senior

Job Description

Senior Product Security Engineer

Baxter International Inc.

Title: Senior Product Security Engineer Location: United States of America - Remote time type Full time job requisition id JR - 205862 Job Description: This is where your work makes a difference. At Baxter, we believe every person—regardless of who they are or where they are from—deserves a chance to live a healthy life. It was our founding belief in 1931 and continues to be our guiding principle. We are redefining healthcare delivery to make a greater impact today, tomorrow, and beyond. Our Baxter colleagues are united by our Mission to Save and Sustain Lives. Together, our community is driven by a culture of courage, trust, and collaboration. Every individual is empowered to take ownership and make a meaningful impact. We strive for efficient and effective operations, and we hold each other accountable for delivering exceptional results. Here, you will find more than just a job—you will find purpose and pride. Job Description Your role at Baxter At Baxter Healthcare Corporation, we invite a driven Senior Product Security Engineer who is passionate about contributing to healthcare improvements. This opportunity puts you on the frontline of cybersecurity, developing world-class products that touch millions of lives. Your responsibility will be essential in establishing cybersecurity standards and technologies for both present and new products, assuring that our solutions are consistently highly secure. This is where your expertise helps people Your expertise will be instrumental in helping people by ensuring the safety and security of our healthcare products. You will play a meaningful role in safeguarding sensitive data and preserving the privacy of our customers and patients. You will work alongside various groups during every stage of development to guarantee our products uphold the highest levels of security and privacy. Identifying possible threats, assessing security risks, and cooperating to address findings will be important parts of your role. What you'll be doing - Working together with the product development teams to establish cyber security requirements, plans, and policies. - Establish governance around vulnerability management in products. - Assist in responses to and recovery from a security breach in conjunction with other team members and business units. - Use tools to scan for and test possible product vulnerabilities; investigate security breaches. - Stay ahead of and advised about industry zero day discoveries and react to assess products. - Build technical documentation around the security of a product including threat modeling, privacy assessments, whitepapers, etc. - Participate in project planning and prioritisation of security related deliverables and activities. What you'll bring - Bachelor’s degree or equivalent experience in Computer Science or a related field desired. - 2+ years of secure software development life-cycle experience. - Experience developing or analyzing secure coding practices with technologies such as ASP.Net (C#), SQL Server, HTML, C++. - Experience in crafting secure networks, systems, and application architectures. - Certification in security such as CAP, CCSP, or equivalent preferred but not required. - Keen attention to detail, critical thinking, and analytical abilities. - Proven interpersonal and communication (verbal, written, presentation) skills. - Proven understanding of application security throughout the software life-cycle. - Experience in addressing OWASP Top 10 vulnerabilities. Baxter prioritizes accommodating flexibility in the workplace. This is reflected in our flexible workplace policy, which requires employees to be on-site a minimum number of days weekly. The policy supports in-person interaction and teamwork to further our Mission. It is governed by local legal standards and requirements. Baxter reserves the right to modify, suspend, or terminate the policy as business demands shift. We understand compensation is an important factor as you consider the next step in your career. At Baxter, we are committed to equitable pay for all employees, and we strive to be more transparent with our pay practices. The estimated base salary for this position is $96,000 - $132,000 annually. The estimated range is meant to reflect an anticipated salary range for the position. We may pay more or less than the anticipated range based upon market data and other factors, all of which are subject to change. Individual pay is based upon location, skills and expertise, experience, and other relevant factors. This position may also be eligible for discretionary bonuses. For questions about this, our pay philosophy, and available benefits, please speak to the recruiter if you decide to apply and are selected for an interview. Applicants must be authorized to work for any employer in the U.S. We cannot sponsor or transfer employment visas at this time. #LI-TV1 US Benefits at Baxter (except for Puerto Rico) This is where your well-being matters. Baxter offers comprehensive compensation and benefits packages for eligible roles. Our health and well-being benefits include medical and dental coverage that start on day one, as well as insurance coverage for basic life, accident, short-term and long-term disability, and business travel accident insurance. Financial and retirement benefits include the Employee Stock Purchase Plan (ESPP), with the ability to purchase company stock at a discount, and the 401(k) Retirement Savings Plan (RSP), with options for employee contributions and company matching. We also offer Flexible Spending Accounts, educational assistance programs, and time-off benefits such as paid holidays, paid time off ranging from 20 to 35 days based on length of service, family and medical leaves of absence, and paid parental leave. Additional benefits include commuting benefits, the Employee Discount Program, the Employee Assistance Program (EAP), and childcare benefits. Join us and enjoy the competitive compensation and benefits we offer to our employees. For additional information regarding Baxter US Benefits, please speak with your recruiter or visit our Benefits site: Benefits | Baxter Equal Employment Opportunity Baxter is an equal opportunity employer. Baxter evaluates qualified applicants without regard to race, color, religion, gender, national origin, age, sexual orientation, gender identity or expression, protected veteran status, disability/handicap status or any other legally protected characteristic. Know Your Rights: Workplace Discrimination is Illegal Reasonable Accommodations Baxter is committed to working with and providing reasonable accommodations to individuals with disabilities globally. If, because of a medical condition or disability, you need a reasonable accommodation for any part of the application or interview process, please click on the link here and let us know the nature of your request along with your contact information. Recruitment Fraud Notice Baxter has discovered incidents of employment scams, where fraudulent parties pose as Baxter employees, recruiters, or other agents, and engage with online job seekers in an attempt to steal personal and/or financial information. To learn how you can protect yourself, review our Recruitment Fraud Notice.

Related Categories

Related Job Pages

More Security Engineer Jobs

Mitsubishi UFJ Financial Group - MUFG logo

Global Director of Autonomous Cyber Defense and Security Event Triage

Mitsubishi UFJ Financial Group - MUFG

Mitsubishi UFJ Financial Group (MUFG) is a global financial services network with more than 2,700 locations across Asia, the Americas, Europe, the Middle East,

Title: Global Director of Autonomous Cyber Defense and Security Event Triage (SOC) Location: Tempe, AZ Jersey City, NJ time type Full time job requisition id 10076418-WD Do you want your voice heard and your actions to count? Discover your opportunity with Mitsubishi UFJ Financial Group (MUFG), one of the world’s leading financial groups. Across the globe, we’re 150,000 colleagues, striving to make a difference for every client, organization, and community we serve. We stand for our values, building long-term relationships, serving society, and fostering shared and sustainable growth for a better world. With a vision to be the world’s most trusted financial group, it’s part of our culture to put people first, listen to new and diverse ideas and collaborate toward greater innovation, speed and agility. This means investing in talent, technologies, and tools that empower you to own your career. Join MUFG, where being inspired is expected and making a meaningful impact is rewarded. The selected colleague will work at an MUFG office or client sites four days per week and work remotely one day. A member of our recruitment team will provide more details. The Global Director of Autonomous Cyber Defense and Security Event Triage leads the strategy, execution, and continuous improvement of a 24/7 global cyber defense and security event triage function. This role is accountable for globally protecting enterprise assets and services by driving outcomes across detection engineering, automated response, incident triage, and threat hunting. The director oversees global cyber operations performance, operating rhythms, and service delivery across multiple environments and partners, while owning budget planning and financial stewardship for the function. Additionally, the role advances autonomous defense capabilities by applying AI/ML and LLM-enabled workflows to improve alert quality, reduce time to detect/respond, and standardize decisioning, documentation, and remediation at scale. The director also ensures continuous validation of controls and detections through purple team execution aligned to adversary behaviors. Major Responsibilities - Direct and mature a 24/7 global cyber operations model for security event monitoring, triage, incident response partnership, and threat hunting across multiple environments - Own functional strategy, multi-year roadmap, and KPI/OKR outcomes for autonomous cyber defense and security event triage (e.g., MTTD/MTTR, false-positive reduction, containment SLAs) - Work with the Global Head to define the vision for Autonomous Cyber Defense and Security Event Triage, and execute against that vision in alignment with the strategic design - Oversee budget planning, vendor management, and financial governance for global cyber operations tooling, services, and staffing; optimize spend to risk reduction and service performance - Lead, mentor, and scale high-performing global teams (employees and partners); define operating rhythms, coverage models, escalation paths, and on-call expectations - Serve as a lead escalation contact in a 24/7 environment; guide appropriate resources to resolution - Provide executive-level oversight for audit, risk, and regulatory engagements related to cyber operations; ensure processes, evidence, and metrics meet policy and compliance requirements - Deliver leadership reporting on cyber operations health, emerging threats, and risk posture; translate technical findings into business impact and prioritized actions - Drive AI/ML/LLM-enabled autonomous defense initiatives, including alert enrichment, case summarization, analyst co-pilots, automated containment, and continuous learning to improve signal-to-noise - Establish governance for detection engineering, triage decisioning, playbooks, and automation (SOAR/EDR/SIEM) to standardize response, reduce gaps, and improve response times - Lead critical incident triage and escalation governance; partner with incident response, infrastructure, identity, and application teams to coordinate containment and recovery - Oversee monitoring of third-party security service providers and managed tooling to ensure coverage, quality, and alignment to enterprise standards and SLAs - Build an operations analytics program to measure and continuously improve triage accuracy, response efficiency, backlog health, and automation effectiveness across regions and shifts - Sponsor and execute a purple team program (red/blue collaboration) to validate detections and response through adversary emulation aligned to MITRE ATT&CK; track gaps to closure - Oversee proactive threat hunting and continuous control validation to identify adversary behaviors, reduce dwell time, and harden critical services - Provide global operational leadership during cyber events by coordinating communications, handoffs, and technical execution across regions, functions, and time zones - Integrate threat intelligence, vulnerability insights, and attacker TTP research into detection logic, triage guidance, and autonomous response workflows - Produce and govern recurring and ad-hoc reporting on threats, trends, and program performance; ensure consistent narratives and decision support for stakeholders - Champion innovation and modernization of cyber defense tooling and techniques, including evaluation and adoption of new capabilities that measurably reduce risk - Partner with technology, product, and business leaders to align cyber operations priorities, drive remediation ownership, and embed security-by-design practices Qualifications - Bachelor’s degree in Information Technology, Cyber Security, Computer Science, or related discipline or equivalent work experience - 7+ years of experience working in the Cybersecurity Operations or Information Security - Relevant technical and industry certifications, such as CISSP, ISSMP, GCIA, CISM, CEH, GCFA, GCFE, GCIH, or GSEC are preferred - Experience in one or more security domains including Security Governance and Oversight, Security Risk Management, Network Security, Threat and Vulnerability Management, or Incident Response and Forensics preferred - Experience with information security risk management, including information security audits, reviews, and risk assessments Desired Skills - Experience with security data collection, analysis and correlation - Well-developed analytic, qualitative, and quantitative reasoning skills - Demonstrated creative problem-solving abilities - Security event monitoring, investigation, and overall incident response process - Strong time management skills to balance multiple activities and lead junior analysts as needed - Understanding of offensive security to include common attack methods - Understanding of how to pivot across multiple datasets to correlate artifacts for a single security event - A diverse skill base in both product security and information security including organizational structure and administration practices, system development and maintenance procedures, system software and hardware security controls, access controls, computer operations, physical and environmental controls, and backup and recovery procedures. - Detailed knowledge and experience in security and regulatory frameworks (ISO 27001, NIST 800 series, FFIEC, SOC2, FedRAMP, STAR, etc.) - Ability to guide and mentor junior analysts in investigations - Understanding of enterprise detection and response technologies and processes (advanced threat detection tools, intrusion detection/prevention systems, network packet analysis, endpoint detection and response, firewalls, Anti malware/anti-virus, Security Information and Event Management tools, etc.) - Experienced with Endpoint Detection & Response, email security, web application firewall, and cloud security tooling. - Ability to perform risk analysis utilizing logs and other information compiled from various sources - Understanding of network protocols, operating systems (Windows, Unix, Linux, MacOS, databases), and mobile device security - Knowledge of the various types of cyber-attacks and their implementations - A fundamental understanding of enterprise cybersecurity frameworks such as MITRE ATT&CK and Cyber Kill Chain - Ability to document and explain technical details in a concise, understandable manner - Experience in operational processes such as security monitoring, data correlation, troubleshooting, security operations, etc. - Preferred experience with Torq, 7AI, CrowdStrike, Tanium, Snowflake, Splunk, and ELK - Scripting/programming experience preferred - Education •Bachelor's degree in Computer Science or a closely-related discipline, or an equivalent combination of formal education and experience “Visa sponsorship/support is based on business needs. We do not anticipate providing visa sponsorship/support for this position.” The typical base pay range for this role is as follows: - New York / New Jersey: $182k-227k - Non–New York / New Jersey: $203k-249k depending on job-related knowledge, skills, experience and location. This role may also be eligible for certain discretionary performance-based bonus and/or incentive compensation. Additionally, our Total Rewards program provides colleagues with a competitive benefits package (in accordance with the eligibility requirements and respective terms of each) that includes comprehensive health and wellness benefits, retirement plans, educational assistance and training programs, income replacement for qualified employees with disabilities, paid maternity and parental bonding leave, and paid vacation, sick days, and holidays. For more information on our Total Rewards package, please click the link below. Our hybrid work schedule is four days on-site and work remotely one day per week. MUFG Benefits Summary We will consider for employment all qualified applicants, including those with criminal histories, in a manner consistent with the requirements of applicable state and local laws (including (i) the San Francisco Fair Chance Ordinance, (ii) the City of Los Angeles’ Fair Chance Initiative for Hiring Ordinance, (iii) the Los Angeles County Fair Chance Ordinance, and (iv) the California Fair Chance Act) to the extent that (a) an applicant is not subject to a statutory disqualification pursuant to Section 3(a)(39) of the Securities and Exchange Act of 1934 or Section 8a(2) or 8a(3) of the Commodity Exchange Act, and (b) they do not conflict with the background screening requirements of the Financial Industry Regulatory Authority (FINRA) and the National Futures Association (NFA). The major responsibilities listed above are the material job duties of this role for which the Company reasonably believes that criminal history may have a direct, adverse and negative relationship potentially resulting in the withdrawal of conditional offer of employment, if any. The above statements are intended to describe the general nature and level of work being performed. They are not intended to be construed as an exhaustive list of all responsibilities duties and skills required of personnel so classified. We are proud to be an Equal Opportunity Employer and committed to leveraging the diverse backgrounds, perspectives and experience of our workforce to create opportunities for our colleagues and our business. We do not discriminate on the basis of race, color, national origin, religion, gender expression, gender identity, sex, age, ancestry, marital status, protected veteran and military status, disability, medical condition, sexual orientation, genetic information, or any other status of an individual or that individual’s associates or relatives that is protected under applicable federal, state, or local law.

Arizona + 1 moreAll locations: Arizona | New Jersey
$182K - $249K / year
Full TimeRemoteTeam 51-200Since 2013H1B No Sponsor

• Improve Indico’s technical security posture across AWS, Kubernetes, CI/CD, product security, internal systems, and incident response. • Partner with the CISO and CTO to turn security priorities into practical technical controls, standards, reviews, and operating processes. • Review Engineering work against security standards, with authority to request changes where needed. • Partner with Engineering on AWS security controls, including IAM, networking, account structure, logging, encryption, key management, backups, production access, and customer-dedicated environments. • Review and improve Kubernetes and container security controls, including workload identity, RBAC, network boundaries, image security, runtime monitoring, and deployment patterns. • Define and improve secure CI/CD patterns, including GitHub permissions, branch protections, privileged workflows, secrets handling, release controls, and deployment access. • Define and oversee processes for vulnerability management, committed-secret response, secure development, incident response, and access control while Engineering, Platform, IT/Ops, and system owners operate them in their domains. • Provide product security support, including secure design review, threat modeling for sensitive features, scanner tuning, and high-risk change review. • Improve detection and response coverage across tools such as CloudTrail, GuardDuty, CrowdStrike, SIEM/logging platforms, vulnerability scanners, and secrets detection. • Own day-to-day security monitoring and response operations, including alert routing, triage expectations, escalation paths, and detection improvements. • Coordinate technical containment during security incidents across Engineering, Platform, IT/Ops, and leadership. • Maintain incident response runbooks and partner with the CISO on severity, executive escalation, counsel/compliance coordination, and customer communication strategy. • Create practical security guidance, standards, procedures, and runbooks for security-sensitive work such as production access, secrets handling, vulnerability remediation, incident response, customer data handling, and secure engineering. • Maintain reusable technical security documentation, standard responses, and evidence packages for customer due diligence and compliance support. • Evaluate security tools and vendors with a focus on technical coverage, operational fit, and reducing manual work. • Build or sponsor lightweight automation, checks, dashboards, and workflows that make security controls repeatable.

United States
Zensar logo

Saviynt IAM Specialist

Zensar

At Zensar, we’re “experience-led everything”. We are committed to conceptualizing, designing, engineering, marketing, and managing digital solutions and experiences for over 130 leading enterprises. We are a company driven by a bold purpose: Together, we shape experiences for better futures. Whether for our clients, our people, or the world around us, this belief powers everything we do. At the heart of our culture is ONE with Client - a set of four core values that reflect who we are and how we work: One Zensar, Nurturing, Empowering, and Client Focus. Part of the $4.8 billion RPG Group, we’re a community of 10,000+ innovators across 30+ global locations, including Milpitas, Seattle, Princeton, Cape Town, London, Zurich, Singapore, and Mexico City. We believe the best work happens when individuality is celebrated, growth is encouraged, and well-being is prioritized. We are an equal employment opportunity (EEO) and affirmative action employer, committed to creating an inclusive workplace. All qualified applicants will be considered without regard to race, creed, color, ancestry, religion, sex, national origin, citizenship, age, sexual orientation, gender identity, disability, marital status, family medical leave status, or protected veteran status.

Full TimeRemoteTeam 10,001

Role Description Design and implement IAM solutions using Saviynt. - Installation of Saviynt Connect and configuration - Create custom rules and workflows related to Joiner, Mover, Leaver (JML) processes - Integrate Saviynt with HR systems, Active Directory, Azure AD, Exchange, ServiceNow, and other enterprise applications using out-of-the-box and custom connectors - Develop and document IAM policies, procedures, and standards - Ensure compliance with regulatory requirements and industry best practices - Strong understanding of IAM concepts and best practices - Build custom connectors for onboarding applications - Develop and manage REST API connectors for web applications and authoritative sources like SAP, PeopleSoft, and Workday - Develop and enforce security policies related to identity and access management - Implement periodic access reviews to ensure appropriate access levels - Automate access review processes to streamline compliance checks - Generate reports on access review findings and actions taken - Provide technical support and guidance to internal teams and stakeholders - Conduct training sessions for end-users and IT staff on Saviynt functionalities - Experience with other IAM tools like SailPoint, Okta, or CyberArk - Proficiency in Java and scripting languages (e.g., PowerShell, Python) - Excellent problem-solving and analytical skills - Strong communication and interpersonal skills Qualifications - Experience with IAM solutions, particularly Saviynt - Knowledge of regulatory compliance and industry best practices - Technical proficiency in relevant programming and scripting languages Requirements - Strong understanding of IAM concepts - Experience with integration of IAM solutions with enterprise applications - Ability to develop and enforce security policies - Experience in conducting training sessions Benefits - Inclusive workplace culture - Opportunities for growth and development - Commitment to employee well-being

India
Pinnacle Treatment Centers, Inc. logo

Director of Security and Network

Pinnacle Treatment Centers, Inc.

Addiction Treatment & Healing. Aegis. Recovery Works. HealthQwest. And More. A Pinnacle Family of Companies.

Full TimeRemoteTeam 1,001-5,000Since 2006H1B No Sponsor

• Serve as Pinnacle's cybersecurity leader and Security Officer while overseeing enterprise networking and infrastructure security initiatives. • Develop and execute Pinnacle's multi-year cybersecurity strategy and roadmap. • Lead information security governance, risk management, compliance, and security operations. • Direct enterprise security monitoring and incident response practices • Conduct security assessments, audits, and risk mitigation initiatives. • Drive security awareness and best practices across the organization. • Partner with Compliance and business leaders to maintain a strong security culture. • Manage and optimize enterprise security technologies including: SIEM platforms, Endpoint Protection (EPP), Data Loss Prevention (DLP), Firewalls, Vulnerability Management, PKI, RADIUS, Network Access Control (NAC). • Lead enterprise LAN, WAN, and wireless networking strategy. • Design and implement scalable, resilient network solutions. • Drive modernization and simplification initiatives across multi-site environments. • Ensure secure connectivity for all Pinnacle facilities and applications. • Lead security strategy and governance for Microsoft 365, Microsoft Azure, Conditional Access, Multi-Factor Authentication (MFA), Role-Based Access Control (RBAC), Microsoft Intune, Windows AutoPilot. • Lead and mentor a team of security and network engineers. • Manage vendor partnerships, procurement, and technology investments. • Establish effective escalation and on-call support processes. • Communicate project status and strategic initiatives to executive stakeholders.

United States