Alcon

Product Security Governance Engineer

Remote Bengaluru, India
Description

Summary of the Position

Alcon is looking to hire Product Security Governance Engineer.

JOB PURPOSE

  • Support Product Security and Threat Intelligence solutions.

  • Provide support for performing penetration tests, SAST/DAST/SCA and preparing reports for findings for Alcon Products (SaMD-Software As a Medical Device, SiMD-Software In a Medical Device and Digital Applications).

  • Communicate prioritization of vulnerabilities for remediation to stakeholders.

  • Build competencies with gap analysis, process changes, and integration of automated tools across the product lifecycle.

  • Review and recommend remediations from security software tooling analysis.

  • Well-versed in the product security landscape.

  • Work closely with the Bangalore and Lake Forest Product Security functions, Software Development, Verification and Validation, Quality, Regulatory and Digital Health Software teams to coordinate oversight of security framework.

  • Help in building and developing automation with automated scripts and tools as applicable.

  • Help in leading efforts to close the security related gaps in Alcon’s product security framework.

  • Build strong collaboration with cross-functional stakeholders and teams across the product development lifecycle.

  • Communicate stakeholders concerning discovered vulnerabilities and remediation suggestions.

  • Contribute to analyzing product security risks, assessing security gaps, and recommending possible solutions.

  • Provides accurate documentation of existing metrics and KPIs, and security process.

  • Collaborating with the Product Security Incident Response Team to support incident response activities and address identified incidents as needed.

  • Works closely with the Product Security team to support product security activities and associated deliverables

JOB FUNCTIONS

Essential Functions

Duties are listed in order of greatest importance.  Other responsibilities may be assigned. 

You will be responsible for maintaining robust product security measures across all stages of our product development and post launch process. Supporting Alcon Product Security Process by performing product security activities for all Alcon products. Perform/support Post Market Monitoring risk analysis of in-market products; document and score findings, communicate results to development teams. Support yearly penetration tests, SAST/DAST/SCA as needed and directed, create or reviewing final reports. You will collaborate with cross-functional teams to integrate security best practices and ensure the protection of our products against potential threats. Implement and enforce security best practices throughout the entire software development lifecycle (SDLC) Stay updated on the latest security trends, regulatory standards, vulnerabilities, and mitigation strategies. Summarize product risks for stakeholder reports. Interact with outside vendors, write/modify/convey host module requirements, and be able to identify and hold outside vendors accountable for their deliverables. Review security updates for possible negative affects against in-market products and monitor media for new vulnerabilities. As needed write and/or review patching and update communications to customers and disseminate. Support preparation software for SAST, DAST, Vulnerability scans, fuzzing scans; review and document results, provide recommendations for remediations.

QUALIFICATIONS

Minimum Requirement

BS of Computer engineering or Information Security or other related discipline with 6 years’ experience; or 8 years of relevant experience. Solid understanding of Software Development Lifecycle Management (SDLC) – (Agile/Scrum, iterative) Proven experience in a Product Security field or in a similar role. Familiar with the following types of tools: SAST, DAST, SBOM, network forensics tools, fuzzing, standard penetration test tools and GRC tool are a plus. Knowledge of cybersecurity concepts, networking and software development process is plus. Ability to coordinate and balance activities between multiple associates Ability to work independently, proactively identify issues, recommend, and implement solutions, and deliver quality results on schedule while managing multiple tasks and internal customers. Ability to follow directions, identify issues, recommend and deliver quality results on schedule. Good interpersonal & Communication skills to build positive departmental and inter-departmental relationships in a virtual, remote and asynchronous environment. Prior experience on medical device software and data integrity. Understanding of FDA/ISO regulations related to medical device software. Strong understanding of secure coding principles, encryption, and authentication protocols

Familiarity with industry standards and frameworks such as OWASP, NIST, UL-2900 and ISO 27001.

Excellent communication and collaboration skills. Good interpersonal & Communication skills to build positive departmental and inter-departmental relationships in a virtual, remote, and asynchronous environment. Understanding of Window OS services, processes, driver and registry configurations and analysis techniques is a plus Fluent English; excellent verbal and written communication skills

Knowledge, Skills and Abilities

Personal Effectiveness Competencies:

  • Project Excellence - Fundamental

  • Continuous Learning - Intermediate

  • Digital and Technology Savvy - Intermediate

  • Operational Excellence - Intermediate

  • Breakthrough Analysis - Intermediate

  • Organizational Savvy - Intermediate

Skills and Knowledge:

  • STEAM – Applied Science, Technology, Engineering, Arts and Math

  • Technical Development Methodology for Medical Devices (21 CFR 820.30, ISO 13485)

  • Systems Engineering or Risk Management for Medical Device (ISO 14971)

  • Medical Device Software – Software Life Cycle Processes (IEC 62304)

  • Regulations and Guidelines associated with software development.

  • Excellent verbal English communication skill (in a remote environment)

  • Microsoft Office suite (i.e., Word, Excel, Visio)

Experiences

  • Cross Functional collaboration - Primary

  • New Product Innovation - Secondary

  • Accountability - Primary

  • Influencing without Authority - Primary

  • Managing Crisis – Secondary

  • Functional Breadth - Secondary

Employment scams: Alcon is aware of employment scams which make false use of our company name or leader’s names to defraud job seekers. Alcon does not offer any positions without interview and never asks candidates for money. All our current job openings are displayed here on the Careers section of our website, where you can search for open positions and apply directly.
If you have encountered a job posting or been approached with a job offer that you suspect may be fraudulent, we strongly recommend you do not respond, send money or personal information, and check our website for current job openings.

ATTENTION: Current Alcon Employee/Contingent Worker

If you are currently an active employee/contingent worker at Alcon, please click the appropriate link below to apply on the Internal Career site.

Find Jobs for Employees

Find Jobs for Contingent Worker

  

Alcon is an Equal Opportunity Employer and takes pride in maintaining a diverse environment. We do not discriminate in recruitment, hiring, training, promotion or other employment practices for reasons of race, color, religion, gender, national origin, age, sexual orientation, gender identity, marital status, disability, or any other reason.

There are more than 50,000 engineering jobs:

Subscribe to membership and unlock all jobs

Engineering Jobs

60,000+ jobs from 4,500+ well-funded companies

Updated Daily

New jobs are added every day as companies post them

Refined Search

Use filters like skill, location, etc to narrow results

Become a member

🥳🥳🥳 452 happy customers and counting...

Overall, over 80% of customers chose to renew their subscriptions after the initial sign-up.

To try it out

For active job seekers

For those who are passive looking

Cancel anytime

Frequently Asked Questions

  • We prioritize job seekers as our customers, unlike bigger job sites, by charging a small fee to provide them with curated access to the best companies and up-to-date jobs. This focus allows us to deliver a more personalized and effective job search experience.
  • We've got about 70,000 jobs from 5,000 vetted companies. No fake or sleazy jobs here!
  • We aggregate jobs from 5,000+ companies' career pages, so you can be sure that you're getting the most up-to-date and relevant jobs.
  • We're the only job board *for* software engineers, *by* software engineers… in case you needed a reminder! We add thousands of new jobs daily and offer powerful search filters just for you. 🛠️
  • Every single hour! We add 2,000-3,000 new jobs daily, so you'll always have fresh opportunities. 🚀
  • Typically, job searches take 3-6 months. EchoJobs helps you spend more time applying and less time hunting. 🎯
  • Check daily! We're always updating with new jobs. Set up job alerts for even quicker access. 📅

What Fellow Engineers Say

Sid avatar
Sid
Very nice portal for searching jobs in this rough market.
Mar 6, 2025
Michael Duran avatar
Michael Duran
Software Engineer
I've been using this job search site for a while now, and it’s honestly one of the best out there! The clean and easy-to-navigate UI makes the whole job-hunting process so much smoother. Plus, the job postings are always up-to-date, so I never feel like I’m wasting time. The cherry on top is the owner—super kind and always quick to respond. Definitely recommend checking it out if you're on the job hunt!
Aug 21, 2024
Sai avatar
Sai
It’s really great website for finding jobs based on skills it’s really helpful give a go
Aug 21, 2024
Adinadh avatar
Adinadh
What I like most about Echo Jobs is how easy it is to use. The platform helps me quickly find jobs that match my skills and interests, thanks to its great recommendations and filters. Yes, I would definitely recommend Echo Jobs to a friend. It makes job searching simple and efficient, making it a great tool for anyone looking for a new job.
Jul 23, 2024
As a student navigating the job market, I've found LinkedIn increasingly frustrating due to numerous fake postings by consultancies. In contrast, this job posting website has been a game-changer for me. It offers genuine opportunities and a straightforward application process, making it much easier to find and apply for real jobs. Highly recommend it to fellow students seeking reliable job listings!
Jul 16, 2024
Cliff Gor avatar
Echo Jobs has been exceptional in my job hunt where it provides one platform to job hunt and I don't have to open 10 websites just to look for a job. It has also helped me focus much on the job skill and the location filtering out the onsite jobs and remote ones. The only feature that I would request is to display fully remote jobs that are not restricted to a country since the one available shows ie, Remote, US yet. But if it could show remote only, that would be helpful not only to me but to other people applying for full remote and not tied to only US candidates
Apr 22, 2024
I found EchoJobs in 2022, and I love it. It has a lot of remote jobs. It's exclusive to software and technology jobs (helpful for devs like me). What I like the most are its filters and its API. If you're a tech professional seeking remote work, I highly recommend giving it a try to EchoJobs.
Mar 4, 2024
Would definitely recommend it! Excellent product, dedicated founder, Jobs are easier to find. Congrats 🎉 to the entire team!
Mar 3, 2024
Brandon Banks avatar
Brandon Banks
Echo Jobs is really impressive. It provides a great user experience with an ability to quickly search through the many job postings. There is an impressive amount of jobs here and it is quickly updated. The details in the each job posting is helpful when determining if it is worth pursuing. I would highly recommend using Echo Jobs to find the next step in your career.
Mar 2, 2024
Tyler Young avatar
Tyler Young
tylerayoung.com
Best wishes with EchoJobs—it's become my favorite job board overnight!
Dec 16, 2023
Simply put, it's the most up to date tech jobs aggregator I’ve found. I'm like... "I don't have to check 10+ jobs boards daily just to see if there's a new job listing? sign me up!" The filters are also quite helpful! The UI is very clean and straightforward. Love it!
Oct 5, 2023