This list contains only the countries for which job offers have been published in the selected language (e.g., in the French version, only job offers written in French are displayed, and in the English version, only those in English).
As a Principal Product Security Engineer at Baxter, you will help drive cybersecurity requirements and technologies for existing and new products. You will monitor potential threats, analyze security risks, and collaborate to remediate findings while staying ahead of industry zero-day discoveries.
Job Responsibility:
Create technical documentation around the security of a product including threat modeling and interface architecture, Data Protection Impact Assessment, and Product Security whitepapers
Work collaboratively with the product development teams to establish information security requirements, plans, and policies
Establish governance around vulnerability management in products
Assist in responses to and recovery from a security breach in conjunction with other team members and business units
Use tools (Tenable Nessus, Fortify, Coverity, etc.) to scan for and test possible product vulnerabilities
Stay ahead of and advise about industry zero day discoveries and react to assess products
Work collaboratively with product teams on annual SOC2 and HiTrust audits for products
Investigate security breaches
Participate in project planning and scoping of security related deliverables and activities
Assess 3rd party and off the shelf components for secure use.
Requirements:
Bachelor’s degree in Computer Science or a related field desired
5+ years of secure software development life-cycle experience
Solid understanding of application security throughout the software life-cycle
Experience in addressing OWASP Top 10 vulnerabilities
Experience developing or analyzing secure coding practices with technologies such as ASP.Net (C#), SQL Server, HTML, C++
Strong technical writing skills
Familiarity with the privacy by design framework
Experience with Threat modeling methodologies like STRIDE, DREAD, LINDDUN, or PASTA
Experience performing security risk assessments and the ability to communicate impact of risk
Experience analyzing and documenting possible vulnerabilities found during development
Familiarity with industry standards and guidance such as IEC TR 80001, NIST 800-53, ISO IEC 27001 & 27002, etc.
Expertise in designing secure networks, systems, and application architectures
Certification in security such as CAP, CSSLP, or equivalent desired but not required
Keen attention to detail, critical thinking and analytical abilities
Proven interpersonal and communication (verbal, written, presentation) skills.
Nice to have:
Certification in security such as CAP, CSSLP, or equivalent desired but not required.
What we offer:
Support for Parents
Continuing Education/ Professional Development
Employee Health & Well-Being Benefits
Paid Time Off
2 Days a Year to Volunteer
Medical and dental coverage that start on day one
Insurance coverage for basic life, accident, short-term and long-term disability, and business travel accident insurance
Welcome to
CrawlJobs.com
– Your Global Job Discovery Platform
At CrawlJobs.com, we simplify finding your next career opportunity by bringing job listings directly to you from all corners of the web. Using cutting-edge AI and web-crawling technologies, we gather and curate job offers from various sources across the globe, ensuring you have access to the most up-to-date job listings in one place.
We use cookies to enhance your experience, analyze traffic, and serve personalized content. By clicking “Accept”, you agree to the use of cookies.