Senior Cyber Security Engineer
Bayer · State of Karnataka, India
Free to search · AI fit score against your CV · tailor your résumé in one click
Bayer · State of Karnataka, India
At Bayer we’re visionaries, driven to solve the world’s toughest challenges and striving for a world where ,Health for all, Hunger for none’ is no longer a dream, but a real possibility. We’re doing it with energy, curiosity and sheer dedication, always learning from unique perspectives of those around us, expanding our thinking, growing our capabilities and redefining ‘impossible’. There are so many reasons to join us. If you’re hungry to build a varied and meaningful career in a community of brilliant and diverse minds to make a real difference, there’s only one choice. Senior Cyber Security Engineer POSITION PURPOSE: Bayer Radiology R&D is currently seeking a Senior Cybersecurity Engineer to support and strengthen cybersecurity for its connectivity cloud-based SaMD solutions and product-security operating model. This role requires deep hands-on expertise in cloud security, DevSecOps, vulnerability management, release assurance, monitoring, incident response, and audit-ready security evidence. You will work closely with product development teams, Global Cybersecurity, Quality, Cyber Central / CSF, and Connectivity Product Leadership to embed security into day-to-day engineering, release gates, remediation planning, and continuously improving product-security operations. YOUR TASKS AND RESPONSIBILITIES: • Own and execute product-security engineering work for Cortenic connectivity solutions, including security debt reduction, remediation SLAs, operating dashboards and continuous improvement of inherited security gaps. • Design, maintain and improve central GitHub security pipelines and standard caller workflows across connectivity repositories, including dependency, secret, code-quality, artifact, container and cloud-security scans. • Onboard repositories and projects to standard security workflows, map branches and environments, validate secrets versus variables, and ensure the correct image and configuration are used across release stages. • Review cloud, Kubernetes, Artifact Registry and IAM configurations; identify misconfigurations, over-permissive access, registry exposure, data-classification gaps and monitoring/logging coverage issues. • Identify, triage, prioritize and drive closure of findings from Dependabot, Xray, SonarQube, Orca, Tanium, CrowdStrike, Burp Suite and Secret Scanning, including re-scans and evidence-based verification. • Partner with development teams during sprints to interpret scan reports, fix findings before PR merge or release, remediate High/Critical dependency and container vulnerabilities, and validate fixes through pipeline re-runs. • Configure and maintain security quality gates, generate SBOMs for production releases, prepare release security reports, assess gate exceptions and provide evidence for Quality, audit and release sign-off. • Create and maintain security runbooks, repository onboarding checklists, branch/environment/secrets guides, audit-ready evidence packs and technical reference material for reviews, approvals and stakeholder briefings. • Support penetration testing by defining scope, preparing architecture/access/environment details, reviewing reports, creating remediation plans with development teams and providing closure evidence. • Respond to cybersecurity incidents, customer/security-contract questions, Cyber Central requests and newly disclosed vulnerabilities with impact assessments, approved evidence, clear documentation and timely follow-through. • Support compliance and certification readiness by providing scan artifacts, risk and vulnerability evidence, control implementation inputs and audit support in partnership with Global Cybersecurity and Quality. WHO YOU ARE: Required • Bachelor’s degree in Computer Science, Information Security, Cybersecurity, Software Engineering, or a related field. • 7+ years of hands-on cybersecurity, product security, cloud security or DevSecOps experience in software/product engineering environments. • Strong experience with GCP preferred and at least one additional cloud platform such as AWS or Azure. • Practical experience with CI/CD security, GitHub workflows, vulnerability scanning, dependency scanning, container/image scanning, secret scanning and release security gates. • Experience with tools such as Dependabot, SonarQube, JFrog Xray, Orca, Tanium, CrowdStrike, Burp Suite, SAST/DAST tools, SIEM/logging platforms or equivalent technologies. • Ability to translate scan findings into prioritized remediation plans, work with engineering teams to close findings, and produce audit-ready evidence. • Working knowledge of ISO 27001, SOC 2, NIST, GDPR, HIPAA, GxP, SaMD, medical device cybersecurity or other regulated product-security expectations is preferred. • Strong analytical, documentation, stakeholder-management and communication skills, with the ability to support developers, Quality, Global Cybersecurity and leadership stakeholders. • Cloud Security: Google Cloud Platform preferred, plus AWS or Azure; cloud, Kubernetes, Artifact Registry, IAM, workload identity, secrets, variables and registry exposure reviews • DevSecOps & Security Tooling: GitHub security pipelines, Dependabot, Secret Scanning, SonarQube, JFrog Xray, Orca, Tanium, CrowdStrike, Burp Suite, SAST/DAST and CI/CD security gates • Vulnerability & Remediation Management: severity and exploitability-based prioritization, High/Critical dependency and container fixes, patch verification, re-scans and closure evidence • Release Assurance: security quality gates, SBOM generation, release security reports, exception assessments, control checklists and evidence for Quality/release sign-off • Monitoring & Incident Response: cybersecurity signal triage, SIEM/log-source coverage, incident support, newly disclosed CVE impact assessment and escalation handling • Security Documentation & Evidence: runbooks, onboarding checklists, branch/environment/secrets guides, audit-ready evidence packs and tech