GE HealthCare
Staff Cyber Security Engineer
Full details on LinkedIn
The complete job description, requirements, and application details are available on the original posting.
View Full Job Details on LinkedInAbout GE HealthCare
GE HealthCare is a prominent American health technology company based in Chicago, Illinois. It specializes in medical technology, pharmaceutical diagnostics, and digital healthcare solutions, serving over one billion patients each year. With a workforce of around 51,000 employees, the company has an extensive installed base of more than 4 million pieces of equipment across over 160 countries. Founded in 1893, GE HealthCare has a long history of innovation, evolving from its origins in dental supplies to pioneering advancements in medical imaging technologies like CT and MRI. The company offers a wide range of products and services, including diagnostic imaging systems, pharmaceutical diagnostics, life sciences tools, healthcare IT solutions, and patient care systems. GE HealthCare also provides consulting and support services to enhance the performance and reliability of medical equipment. Its diverse portfolio and global reach make it a key player in the healthcare sector.
Security at GE HealthCare
Compiled from public job postings, careers pages, and company materials. Data may not reflect current state — verify during interviews.
Security Philosophy
- GE HealthCare's AppSec philosophy mandates that application development occurs in a secured environment.
- Leadership views their role as enabling business objectives.
- Prior to project initiation, third parties must request an application's risk classification.
- Static Application Security Testing (SAST) is required for all applications, and Dynamic Application Security Testing (DAST) is required for all browser-based applications.
- All confirmed high/critical vulnerabilities must be corrected before release.
Security Team
GE HealthCare requires third parties to have a designated application security representative. A key public-facing leader is the SVP, Global Chief Information Security Officer and Head of Infrastructure. The company actively seeks to embed security into every phase of the product lifecycle. Specific team size estimates are not publicly available, despite LinkedIn searches.
Key Initiatives
GE HealthCare mandates formally defined security requirements for all new application development and requires software development teams to use GEHC-provided version control. All high/critical vulnerabilities must be corrected before release. They offer product cybersecurity services, including customized security controls and rigorous lifecycle monitoring. Their Skeye offering provides 24/7 monitoring, AI-driven threat detection, and compliant remediation. Information on a Security Champions program or explicit shift-left practices is not publicly available. Recent initiatives include formal requirements outlined in the Third-Party Cyber Security Requirements document.
Preparing for an AppSec interview?
Get the weekly briefing 2,000+ security pros trust.
Interested in this role?
Apply on LinkedIn