AppSec Jobs
← Back to all jobs

Philips

Software Technologist - Security Engineer

Onsite
Bengaluru, Karnataka, IndiaPosted 2 weeks agoWebsite
Apply on LinkedIn →

At a Glance

AWSAzureJavaC#/.NETKubernetesDocker

About This Role

Software Technologist - Security Engineer position based in Bangalore, Karnataka, India. Full-time role focused on driving security throughout the software development lifecycle by designing, building, and securing cloud-native applications. The role involves implementing authentication, authorization, and identity management solutions, remediating vulnerabilities, recommending security frameworks, container security scanning, triaging penetration testing, and security assessments.

Responsibilities

  • Drive security throughout the software development lifecycle by designing, building, and securing cloud-native applications
  • Implement authentication, authorization, and identity management solutions
  • Remediate vulnerabilities identified in code and deployments
  • Recommend security frameworks and best practices
  • Perform container security scanning and analysis
  • Triage penetration testing results and security assessments
  • Work with development teams to shift security left in the pipeline
  • Conduct and support ethical penetration testing activities
  • Manage bug-bounty triage and vulnerability coordination

Requirements

JavaSonarQubeSCABurp SuiteDASTDockerKubernetesCI/CDAzureAWS
  • Java and C#/.NET programming languages
  • Spring Boot and ASP.NET frameworks
  • OAuth2, JWT, SAML, and MFA implementation
  • SonarQube static code analysis
  • GitHub Advanced Security (GHAS) and SCA/secrets detection
  • Burp Suite for DAST and penetration testing
  • Container security scanning and analysis
  • Docker and Kubernetes
  • GitHub Actions and CI/CD pipeline security
  • Azure Key Vault and AWS Secrets Manager
  • Azure and AWS IAM controls
  • Cloud-native application security
  • Bug-bounty triage and vulnerability management
  • Security assessment and ethical hacking capabilities

About Philips

Koninklijke Philips N.V. (Royal Philips) is a leading global company in health technology and medical innovation, based in Eindhoven, the Netherlands. Founded in 1891, Philips has transformed from a light bulb manufacturer into a major electronics conglomerate, known for its diverse portfolio. Philips offers a wide range of products across various sectors. In consumer electronics, it produces radios, televisions, and kitchen appliances. The company has made significant contributions to audio and media, co-developing the compact audio cassette and the compact disc. In healthcare, Philips provides medical imaging equipment, sleep and respiratory care solutions, and other health technology products. The company also offers innovative lighting solutions, including Philips Hue. With a strong international presence, Philips operates sales offices in Europe, China, Australia, and Brazil. The company has a rich history of innovation and quality, reflecting its commitment to advancing health technology.

Industry

hospital & health care

Employees

66,000

13040 engineers

Revenue

$21B

Website

Visit →

Security at Philips

Compiled from public job postings, careers pages, and company materials. Data may not reflect current state — verify during interviews.

3 Intel Signals

Security Philosophy

  • Philips is committed to comprehensive security ensuring the safety of patient, personal, and business data with a "Security Designed In" philosophy.
  • Security by Design is a mindset requiring an end-to-end approach beginning with architecture and high-level design progressing through coding, testing, and post-market support.
  • The AppSec engineer role frames security as a builder function: "drive security throughout the software development lifecycle by designing, building, and securing cloud-native applications." Risk philosophy includes documented SDLC gates via PSRA (Product Security Risk Assessment) and Privacy Assessment (PIA) processes, with SBOM mandate integrated into every product's secure development lifecycle.

Security Team

  • AppSec / Product Security sits under the Global CISO organization led by Wim Sonnemans.
  • A global network of Product Security Officers (PSOs) and their teams manage vulnerability information at the product level.
  • A centralized Security Center of Excellence (SCoE) houses ethical-hacker "security ninjas." The team is distributed across multiple regions with at least 1 explicit AppSec-engineer posting visible, suggesting a multi-team distributed structure rather than a small centralized team.

Key Initiatives

  • Shift-left practices include implementing authentication, authorization, and identity management solutions embedded in SDLC.
  • SBOM integrated into the build process and inspection of source code/binaries.
  • Container security scanning with penetration testing and security assessments executed in pipeline.
  • Vulnerability management includes coordinated vulnerability disclosure support, triage/response via documenting communication, opening corrective action programs, developing solutions, and authoring incident reports.
  • Secure SDLC artifacts include Product Security Risk Assessment (PSRA), Privacy Assessment (PIA) processes, static code analysis, third-party SBOM analysis, ethical penetration testing, and continuous security training.

Preparing for an AppSec interview?

Get the weekly briefing 2,000+ security pros trust.

Interested in this role?

Apply on LinkedIn