Analyst - Product Security
insc ind gbs india
📍 bengaluru ka india🕐 9d ago🔗 workday
Job Description
* Support the integration of cybersecurity requirements into the design, development, change management, and maintenance activities of assigned products and platforms.
* Perform product-focused security analysis, including threat modeling, vulnerability assessments, and cybersecurity risk evaluations for software, hardware, APIs, and connected systems.
* Support the implementation, validation, and monitoring of technical security controls in alignment with secure development and product security requirements.
* Assess product changes, newly identified vulnerabilities, software updates, and deviations from a product-specific cybersecurity perspective, and support remediation activities where required.
* Utilize established procedures and security workflows to perform routine product security activities, including tracking findings, maintaining records, and supporting compliance and health monitoring processes for assigned products.
* Maintain up-to-date knowledge of emerging cybersecurity threats, security technologies, software and hardware vulnerabilities, secure engineering practices, and evolving threat vectors relevant to product security.
* Assist in the development and enhancement of security automation use cases, scripts, and tooling to improve the efficiency and effectiveness of product security assessments and monitoring activities.
* Maintain and support product-level cybersecurity documentation, including risk assessments, threat models, security requirements, test evidence, and regulatory or audit-related records for assigned products.
* Support post-market cybersecurity activities for assigned products, including vulnerability monitoring, incident analysis, remediation coordination, and cybersecurity issue tracking where product expertise is required.
* Participate in cross-functional security and product initiatives, collaborating with Engineering, Quality, Regulatory, DevOps, and other stakeholders to address cybersecurity requirements and risks.
* Act as a technical point of contact for cybersecurity-related activities within assigned product teams, supporting issue resolution, security reviews, and ongoing compliance efforts.
* Ensure compliance with the Code of Business Conduct, organizational cybersecurity policies, secure development standards, and all applicable local, state, federal, and industry regulations.
* Participate in recurring operational, project, and governance meetings to support effective coordination, knowledge sharing, issue tracking, and continuity of product cybersecurity activities.