Philips
Software Technologist - Security Engineer
At a Glance
About This Role
Responsibilities
- Drive security throughout the software development lifecycle by designing, building, and securing cloud-native applications
- Implement authentication, authorization, and identity management solutions
- Remediate vulnerabilities identified in code and deployments
- Recommend security frameworks and best practices
- Perform container security scanning and analysis
- Triage penetration testing results and security assessments
- Work with development teams to shift security left in the pipeline
- Conduct and support ethical penetration testing activities
- Manage bug-bounty triage and vulnerability coordination
Requirements
- Java and C#/.NET programming languages
- Spring Boot and ASP.NET frameworks
- OAuth2, JWT, SAML, and MFA implementation
- SonarQube static code analysis
- GitHub Advanced Security (GHAS) and SCA/secrets detection
- Burp Suite for DAST and penetration testing
- Container security scanning and analysis
- Docker and Kubernetes
- GitHub Actions and CI/CD pipeline security
- Azure Key Vault and AWS Secrets Manager
- Azure and AWS IAM controls
- Cloud-native application security
- Bug-bounty triage and vulnerability management
- Security assessment and ethical hacking capabilities
About Philips
Koninklijke Philips N.V. (Royal Philips) is a leading global company in health technology and medical innovation, based in Eindhoven, the Netherlands. Founded in 1891, Philips has transformed from a light bulb manufacturer into a major electronics conglomerate, known for its diverse portfolio. Philips offers a wide range of products across various sectors. In consumer electronics, it produces radios, televisions, and kitchen appliances. The company has made significant contributions to audio and media, co-developing the compact audio cassette and the compact disc. In healthcare, Philips provides medical imaging equipment, sleep and respiratory care solutions, and other health technology products. The company also offers innovative lighting solutions, including Philips Hue. With a strong international presence, Philips operates sales offices in Europe, China, Australia, and Brazil. The company has a rich history of innovation and quality, reflecting its commitment to advancing health technology.
Security at Philips
Compiled from public job postings, careers pages, and company materials. Data may not reflect current state — verify during interviews.
Security Philosophy
- Philips is committed to comprehensive security ensuring the safety of patient, personal, and business data with a "Security Designed In" philosophy.
- Security by Design is a mindset requiring an end-to-end approach beginning with architecture and high-level design progressing through coding, testing, and post-market support.
- The AppSec engineer role frames security as a builder function: "drive security throughout the software development lifecycle by designing, building, and securing cloud-native applications." Risk philosophy includes documented SDLC gates via PSRA (Product Security Risk Assessment) and Privacy Assessment (PIA) processes, with SBOM mandate integrated into every product's secure development lifecycle.
Security Team
- AppSec / Product Security sits under the Global CISO organization led by Wim Sonnemans.
- A global network of Product Security Officers (PSOs) and their teams manage vulnerability information at the product level.
- A centralized Security Center of Excellence (SCoE) houses ethical-hacker "security ninjas." The team is distributed across multiple regions with at least 1 explicit AppSec-engineer posting visible, suggesting a multi-team distributed structure rather than a small centralized team.
Key Initiatives
- Shift-left practices include implementing authentication, authorization, and identity management solutions embedded in SDLC.
- SBOM integrated into the build process and inspection of source code/binaries.
- Container security scanning with penetration testing and security assessments executed in pipeline.
- Vulnerability management includes coordinated vulnerability disclosure support, triage/response via documenting communication, opening corrective action programs, developing solutions, and authoring incident reports.
- Secure SDLC artifacts include Product Security Risk Assessment (PSRA), Privacy Assessment (PIA) processes, static code analysis, third-party SBOM analysis, ethical penetration testing, and continuous security training.
Preparing for an AppSec interview?
Get the weekly briefing 2,000+ security pros trust.
Interested in this role?
Apply on LinkedIn