CrawlJobs Logo

Principal Product Security Engineer

https://www.baxter.com/ Logo

Baxter

Location Icon

Location:
United States, Skaneateles Falls

Category Icon
Category:
IT - Software Development

Job Type Icon

Contract Type:
Employment contract

Salary Icon

Salary:

104000.00 - 143000.00 USD / Year

Job Description:

As a Principal Product Security Engineer at Baxter, you will help drive cybersecurity requirements and technologies for existing and new products. You will monitor potential threats, analyze security risks, and collaborate to remediate findings while staying ahead of industry zero-day discoveries.

Job Responsibility:

  • Create technical documentation around the security of a product including threat modeling and interface architecture, Data Protection Impact Assessment, and Product Security whitepapers
  • Work collaboratively with the product development teams to establish information security requirements, plans, and policies
  • Establish governance around vulnerability management in products
  • Assist in responses to and recovery from a security breach in conjunction with other team members and business units
  • Use tools (Tenable Nessus, Fortify, Coverity, etc.) to scan for and test possible product vulnerabilities
  • Stay ahead of and advise about industry zero day discoveries and react to assess products
  • Work collaboratively with product teams on annual SOC2 and HiTrust audits for products
  • Investigate security breaches
  • Participate in project planning and scoping of security related deliverables and activities
  • Assess 3rd party and off the shelf components for secure use.

Requirements:

  • Bachelor’s degree in Computer Science or a related field desired
  • 5+ years of secure software development life-cycle experience
  • Solid understanding of application security throughout the software life-cycle
  • Experience in addressing OWASP Top 10 vulnerabilities
  • Experience developing or analyzing secure coding practices with technologies such as ASP.Net (C#), SQL Server, HTML, C++
  • Strong technical writing skills
  • Familiarity with the privacy by design framework
  • Experience with Threat modeling methodologies like STRIDE, DREAD, LINDDUN, or PASTA
  • Experience performing security risk assessments and the ability to communicate impact of risk
  • Experience analyzing and documenting possible vulnerabilities found during development
  • Familiarity with industry standards and guidance such as IEC TR 80001, NIST 800-53, ISO IEC 27001 & 27002, etc.
  • Expertise in designing secure networks, systems, and application architectures
  • Certification in security such as CAP, CSSLP, or equivalent desired but not required
  • Keen attention to detail, critical thinking and analytical abilities
  • Proven interpersonal and communication (verbal, written, presentation) skills.

Nice to have:

Certification in security such as CAP, CSSLP, or equivalent desired but not required.

What we offer:
  • Support for Parents
  • Continuing Education/ Professional Development
  • Employee Health & Well-Being Benefits
  • Paid Time Off
  • 2 Days a Year to Volunteer
  • Medical and dental coverage that start on day one
  • Insurance coverage for basic life, accident, short-term and long-term disability, and business travel accident insurance
  • Employee Stock Purchase Plan (ESPP)
  • 401(k) Retirement Savings Plan
  • Flexible Spending Accounts
  • Educational assistance programs
  • Paid holidays
  • Family and medical leaves of absence
  • Paid parental leave
  • Commuting benefits
  • Employee Discount Program
  • Employee Assistance Program (EAP)
  • Childcare benefits.

Additional Information:

Job Posted:
March 20, 2025

Employment Type:
Fulltime
Work Type:
On-site work
Job Link Share:
Welcome to CrawlJobs.com
Your Global Job Discovery Platform
At CrawlJobs.com, we simplify finding your next career opportunity by bringing job listings directly to you from all corners of the web. Using cutting-edge AI and web-crawling technologies, we gather and curate job offers from various sources across the globe, ensuring you have access to the most up-to-date job listings in one place.