Senior Cyber Security Engineer
Bayer · Bengaluru
- Experience7–8 yrs
- SalaryNot disclosed
- Work modeonsite
- Levelexecutive
- Posted16 Sept 2026
About Bayer
Bayer is hiring in Bengaluru in pharma biotech. This role looks for around 7+ years of experience.
Skills
- Cloud Security
- DevSecOps
- Google Cloud Platform
- AWS
- Azure
- Kubernetes
- IAM
- GitHub
- CI/CD
- Vulnerability Scanning
- Dependency Scanning
- Container Scanning
- Secret Scanning
- SAST
- DAST
- Security Quality Gates
- Vulnerability Management
- Incident Response
- Security Information and Event Management
- Penetration Testing
- SBOM
- Agile
- Jira
- Confluence
The role
A cybersecurity engineer at a pharmaceutical product company secures cloud-based medical software through DevSecOps and regulated product security, manages vulnerability remediation and release assurance, and supports incident response. The role also applies Kubernetes and penetration testing to strengthen product-security operations and audit readiness.
Full job description
At Bayer we’re visionaries, driven to solve the world’s toughest challenges and striving for a world where ,Health for all, Hunger for none’ is no longer a dream, but a real possibility. We’re doing it with energy, curiosity and sheer dedication, always learning from unique perspectives of those around us, expanding our thinking, growing our capabilities and redefining ‘impossible’. There are so many reasons to join us. If you’re hungry to build a varied and meaningful career in a community of brilliant and diverse minds to make a real difference, there’s only one choice.
Senior Cyber Security Engineer
POSITION PURPOSE:
Bayer Radiology R&D is currently seeking a Senior Cybersecurity Engineer to support and strengthen cybersecurity for its connectivity cloud-based SaMD solutions and product-security operating model. This role requires deep hands-on expertise in cloud security, DevSecOps, vulnerability management, release assurance, monitoring, incident response, and audit-ready security evidence. You will work closely with product development teams, Global Cybersecurity, Quality, Cyber Central / CSF, and Connectivity Product Leadership to embed security into day-to-day engineering, release gates, remediation planning, and continuously improving product-security operations.
YOUR TASKS AND RESPONSIBILITIES:
Own and execute product-security engineering work for Cortenic connectivity solutions, including security debt reduction, remediation SLAs, operating dashboards and continuous improvement of inherited security gaps. Design, maintain and improve central GitHub security pipelines and standard caller workflows across connectivity repositories, including dependency, secret, code-quality, artifact, container and cloud-security scans. Onboard repositories and projects to standard security workflows, map branches and environments, validate secrets versus variables, and ensure the correct image and configuration are used across release stages. Review cloud, Kubernetes, Artifact Registry and IAM configurations; identify misconfigurations, over-permissive access, registry exposure, data-classification gaps and monitoring/logging coverage issues. Identify, triage, prioritize and drive closure of findings from Dependabot, Xray, SonarQube, Orca, Tanium, CrowdStrike, Burp Suite and Secret Scanning, including re-scans and evidence-based verification. Partner with development teams during sprints to interpret scan reports, fix findings before PR merge or release, remediate High/Critical dependency and container vulnerabilities, and validate fixes through pipeline re-runs. Configure and maintain security quality gates, generate SBOMs for production releases, prepare release security reports, assess gate exceptions and provide evidence for Quality, audit and release sign-off. Create and maintain security runbooks, repository onboarding checklists, branch/environment/secrets guides, audit-ready evidence packs and technical reference material for reviews, approvals and stakeholder briefings. Support penetration testing by defining scope, preparing architecture/access/environment details, reviewing reports, creating remediation plans with development teams and providing closure evidence. Respond to cybersecurity incidents, customer/security-contract questions, Cyber Central requests and newly disclosed vulnerabilities with impact assessments, approved evidence, clear documentation and timely follow-through. Support compliance and certification readiness by providing scan artifacts, risk and vulnerability evidence, control implementation inputs and audit support in partnership with Global Cybersecurity and Quality.
WHO YOU ARE:
Required
Bachelor’s degree in Computer Science, Information Security, Cybersecurity, Software Engineering, or a related field. 7+ years of hands-on cybersecurity, product security, cloud security or DevSecOps experience in software/product engineering environments. Strong experience with GCP preferred and at least one additional cloud platform such as AWS or Azure. Practical experience with CI/CD security, GitHub workflows, vulnerability scanning, dependency scanning, container/image scanning, secret scanning and release security gates. Experience with tools such as Dependabot, SonarQube, JFrog Xray, Orca, Tanium, CrowdStrike, Burp Suite, SAST/DAST tools, SIEM/logging platforms or equivalent technologies. Ability to translate scan findings into prioritized remediation plans, work with engineering teams to close findings, and produce audit-ready evidence. Working knowledge of ISO 27001, SOC 2, NIST, GDPR, HIPAA, GxP, SaMD, medical device cybersecurity or other regulated product-security expectations is preferred. Strong analytical, documentation, stakeholder-management and communication skills, with the ability to support developers, Quality, Global Cybersecurity and leadership stakeholders. Cloud Security: Google Cloud Platform preferred, plus AWS or Azure; cloud, Kubernetes, Artifact Registry, IAM, workload identity, secrets, variables and registry exposure reviews DevSecOps & Security Tooling: GitHub security pipelines, Dependabot, Secret Scanning, SonarQube, JFrog Xray, Orca, Tanium, CrowdStrike, Burp Suite, SAST/DAST and CI/CD security gates Vulnerability & Remediation Management: severity and exploitability-based prioritization, High/Critical dependency and container fixes, patch verification, re-scans and closure evidence Release Assurance: security quality gates, SBOM generation, release security reports, exception assessments, control checklists and evidence for Quality/release sign-off Monitoring & Incident Response: cybersecurity signal triage, SIEM/log-source coverage, incident support, newly disclosed CVE impact assessment and escalation handling Security Documentation & Evidence: runbooks, onboarding checklists, branch/environment/secrets guides, audit-ready evidence packs and technical reference material Penetration Testing Support: scope definition, architecture/access/environment readiness, report review, remediation planning and closure evidence Regulated Product Security: healthcare or SaMD product security, ISO 27001, SOC 2, NIST, HIPAA, GDPR, GxP/release audit support and security-risk evidence Agile & Collaboration: Jira, Confluence, Scrum practices, developer enablement, stakeholder Q&A, sprint backlog integration and clear communication with cross-functional teams
Preferred
Experience working in enterprise/global cybersecurity teams on cybersecurity management plans, cyber test reports, security requirements, release security reviews, risk assessments and risk-management reporting. Familiarity with global cybersecurity governance activities such as policy and procedure creation, security-gate design, centralized control checklists, threat modeling and cybersecurity control ownership mapping. Understanding of regulated product-security deliverables, including Cybersecurity Management Plans, Cyber Test Reports, Security Risk Management Plans/Reports, Threat Modeling Reports, residual-risk decisions and release-security evidence packs. Ability to support global teams with incident response, customer escalations, external disclosures, newly disclosed vulnerability assessments and documented impact/risk decisions. Exposure to certification and compliance readiness work with Quality, including ISO certification scope, certification strategy, control evidence, submission support and audit-ready security-risk documentation.
Ever feel burnt out by bureaucracy? Us too. That's why we're changing the way we work- for higher productivity, faster innovation, and better results. We call it Dynamic Shared Ownership (DSO). Learn more about what DSO will mean for you in your new role here
https://www.bayer.com/enfstrategyfstrategy
Bayer does not charge any fees whatsoever for recruitment process. Please do not entertain such demand for payment by any individuals / entities in connection with recruitment with any Bayer Group entity(ies) worldwide under any pretext.
Please don’t rely upon any unsolicited email from email addresses not ending with domain name “bayer.com” or job advertisements referring you to an email address that does not end with “bayer.com”. For checking the authenticity of such emails or advertisement you may approach us at HRSUPPORT_INDIA@BAYER.COM.
YOUR APPLICATION
Bayer is an equal opportunity employer that strongly values fairness and respect at work. We welcome applications from all individuals, regardless of race, religion, gender, age, physical characteristics, disability, sexual orientation etc. We are committed to treating all applicants fairly and avoiding discrimination.
Location: India : Karnataka : Bangalore
Division: Pharmaceuticals
Reference Code: 884292
Contact Us
022-25311234