Posted 7 days ago

Senior Analyst - Product Security

INSC IND GBS India India, IND GBS Bangalore - Office
Remote Full Time

Job description

PRINCIPAL DUTIES AND RESPONSIBILITIES: Support execution of product cybersecurity post-market surveillance activities across the product portfolio by monitoring security events, vulnerabilities, and emerging threats impacting products and connected systems. Monitor, track, analyze, and document cybersecurity complaints, incidents, vulnerabilities, threat intelligence findings, and post-market security observations in accordance with established processes and regulatory requirements. Assist in maintaining cybersecurity risk registers, issue trackers, remediation status reports, metrics dashboards, and portfolio-level security records to support ongoing risk management activities. Support coordinated vulnerability disclosure (CVD) and product security incident response processes through vulnerability triage, stakeholder coordination, remediation tracking, escalation support, and documentation management. Contribute to vulnerability assessments, penetration testing activities, phishing simulations, threat intelligence reviews, and security monitoring initiatives to identify and mitigate product and application security risks. Support the preparation and maintenance of post-market surveillance (PMS) evidence, cybersecurity assessment reports, audit documentation, compliance records, and risk analysis artifacts. Maintain and enhance standardized cybersecurity procedures, templates, SOPs, playbooks, and operational guidelines to ensure consistency across product security and surveillance activities. Coordinate recurring cybersecurity operational activities with cross-functional teams including R&D, Quality, Regulatory, Engineering, Privacy, and IT stakeholders to support timely risk assessment and remediation efforts. Support portfolio-wide documentation readiness for internal audits, external assessments, regulatory submissions, and compliance reviews related to product cybersecurity. Assist in refining security monitoring capabilities, incident detection processes, reporting mechanisms, and automation opportunities to improve operational efficiency and threat response effectiveness. Maintain awareness of evolving cybersecurity threats, software and hardware vulnerabilities, medical device cybersecurity regulations, and industry best practices relevant to product security and post-market monitoring. Support awareness and communication initiatives by contributing to cybersecurity training, knowledge-sharing activities, and stakeholder guidance related to product security risks and responsibilities. Prepare periodic reports and metrics on cybersecurity incidents, vulnerabilities, remediation status, and post-market surveillance trends, including recommendations for continuous improvement and risk mitigation. Participate in operational review meetings, cross-functional governance discussions, and status tracking activities to ensure effective coordination, transparency, and continuity of cybersecurity operations and post-market surveillance activities. Creating a future worth living. For patients. Worldwide. Every day. Fresenius Medical Care is the world's leading provider of products and services for individuals with kidney disease of which approximately 4.5 million patients worldwide regularly undergo dialysis treatment. United by a shared purpose of creating a future worth living for chronically and critically ill people, we care for around 292,000 dialysis patients around the globe. In addition, we operate around 35 global production sites to provide products such as dialysis machines, dialyzers, and related disposables. We aim to continuously improve our patients’ quality of life by offering them high-quality products as well as innovative technologies and treatment concepts.