Search by job, company or skills

Security System Engineer – Product Security R&D

Security System Engineer – Product Security R&D

Netsach
10-15 Years
Not Disclosed
Early Applicant
Quick Apply
  • Posted a day ago
  • Be among the first 30 applicants

Job Description

Job Overview

We are looking for an experienced Security System Engineer to join the Product Security R&D organization and take ownership of security engineering and vulnerability management activities for Andrew's telecom and enterprise radio network products.

The role will be responsible for establishing, operating, and continuously improving the Product Vulnerability Management lifecycle, including vulnerability discovery, assessment, risk prioritization, remediation tracking, verification, and security reporting.

The ideal candidate will have a strong combination of telecom/radio network domain knowledge, product security, vulnerability management, DevSecOps tooling, and regulatory compliance experience. The candidate should be comfortable working closely with R&D, software engineering, system engineering, product management, PSIRT, QA, and customer-facing/presales teams.

This is primarily an R&D/Product Security Engineering role, with hands-on technical responsibilities rather than a traditional SOC/IT security operations position.

Job Title: Security System Engineer – Product Security R&D

Exp: 10-15yrs

Job Type : Fulltime

Work Location: Bangalore - Onsite

Please register and upload your resume at www.netsachglobal.com.

Kindly click the link to apply for this job role - https://www.netsachglobal.com/job/security-system-engineer-product-security-r-d-netsach-23a56b

Job Description

Mandatory

  • 10–15 years of overall experience in cybersecurity, product security, system security, telecom security, or a closely related engineering discipline.
  • Strong experience in telecom, enterprise networking, radio systems, DAS, wireless infrastructure or embedded/network products.
  • Hands-on experience with vulnerability assessment and security testing tools.
  • Strong Linux and networking knowledge.
  • Experience working directly with R&D/software engineering teams.
  • Experience managing vulnerabilities through remediation and retesting.
  • Ability to independently analyze technical security findings and determine product impact.

Preferred

  • Experience building or managing a centralized Vulnerability Management / Product Security platform.
  • Experience with Dependency-Track and DefectDojo.
  • Experience implementing SBOM-based vulnerability management.
  • Experience with CRA/RED compliance.
  • Experience responding to AT&T CSO or equivalent Tier-1 telecom customer security requirements.
  • Experience supporting presales/RFP/RFQ activities.
  • Security certifications such as CISSP, CSSLP, CEH, OSCP, Security+ or equivalent are desirable.

Key Responsibilities

  1. Product Vulnerability Management
  • Own and manage the end-to-end Product Vulnerability Management lifecycle for Andrew telecom and radio network products.
  • Establish vulnerability identification, triage, risk assessment, remediation, retesting, and closure processes.
  • Continuously monitor vulnerabilities affecting product software, operating systems, open-source components, third-party libraries, firmware, containers, and other dependencies.
  • Perform vulnerability analysis using CVSS, EPSS, CISA KEV and product-specific risk factors.
  • Determine applicability and exploitability of vulnerabilities in Andrew products.
  • Work with R&D teams to define appropriate remediation, mitigation, compensating controls, or risk acceptance.
  • Track vulnerabilities through their complete lifecycle and maintain audit-ready evidence.
  • Prepare product security vulnerability reports and management dashboards.

  1. Security Assessment & Vulnerability Scanning

The candidate should be hands-on with industry-standard security assessment tools, including:

  • Tenable Nessus – infrastructure and vulnerability assessment.
  • Burp Suite – web application/API security testing.
  • OWASP ZAP – DAST and web/API security testing.
  • JFrog Xray / JFrog security scanning – binary, package and dependency vulnerability analysis.
  • Coverity – SAST and source-code security analysis.
  • OWASP Dependency-Check and similar SCA tools.
  • Ability to interpret scan results, eliminate false positives, perform technical validation, and translate findings into actionable R&D defects.

The engineer will be expected to understand what the tools identify, their limitations, and how to technically validate whether a vulnerability is actually exploitable in the product environment.

  1. Centralized Vulnerability Management Platform

Own and continuously improve the centralized vulnerability management ecosystem based on:

  • Dependency-Track
  • SBOM ingestion and management.
  • Software component identification.
  • CVE/CWE monitoring.
  • Component-to-vulnerability correlation.
  • SBOM-based vulnerability tracking.
  • Support for CycloneDX/SPDX and related SBOM formats.
  • DefectDojo
  • Centralized ingestion of Nessus, Burp Suite, ZAP, Coverity, SAST/SCA and other security assessment results.
  • Finding deduplication and normalization.
  • Vulnerability triage and workflow management.
  • Remediation tracking.
  • Verification/retesting and closure.
  • Security metrics and reporting.
  • Establish and maintain integration between CI/CD, SBOM generation, Dependency-Track, scanning tools, DefectDojo and defect-management systems such as Jira.
  • Ensure that vulnerability data is traceable from discovery → assessment → R&D defect → remediation → retest → closure.

  1. Telecom / Enterprise Radio Product Security

Apply cybersecurity principles to Andrew's telecom and enterprise radio products, including technologies such as:

  • Distributed Antenna Systems (DAS).
  • Enterprise radio networks.
  • Radio Access / RF infrastructure.
  • Network management systems.
  • Edge/embedded systems.
  • Linux-based telecom platforms.
  • Network appliances and controllers.
  • Web-based management interfaces.
  • SSH/SFTP and other network services.
  • Embedded firmware and software components.

The candidate should be capable of understanding the interaction between radio systems, networking, Linux, embedded software, management systems, and cybersecurity controls.

  1. Regulatory & Customer Security Compliance

Support product security compliance with applicable regulatory and customer requirements, including:

  • EU Cyber Resilience Act (CRA).
  • EU Radio Equipment Directive (RED) and applicable cybersecurity requirements.
  • AT&T CSO/security checklists and customer security requirements.
  • IEC/EN 62443 and other relevant industrial/product cybersecurity standards where applicable.
  • Customer-specific cybersecurity questionnaires and security requirements. Responsibilities include:
  • Mapping product security controls to regulatory and customer requirements.
  • Identifying compliance gaps.
  • Working with R&D to close security gaps.
  • Maintaining technical evidence for compliance assessments.
  • Supporting preparation of security documentation and audit evidence.
  • Supporting vulnerability disclosure and security reporting obligations where applicable.

  1. Security Architecture & R&D Collaboration
  • Participate in product security architecture and design reviews.
  • Review security requirements for new products and major product releases.
  • Identify security weaknesses in system architecture, interfaces, protocols and deployment models.
  • Provide security requirements and recommendations to software, hardware and system engineering teams.
  • Review implementation of controls such as:
  • Secure Boot.
  • Firmware/software signing.
  • Authentication and authorization.
  • Encryption and secure communications.
  • Certificate and PKI management.
  • Key management.
  • Secure update mechanisms.
  • Hardening.
  • Least privilege.
  • Network segmentation.
  • Secure configuration.
  • Logging and auditability.

  1. Vulnerability Remediation & PSIRT Collaboration
  • Work closely with Product Security/PSIRT teams to investigate reported vulnerabilities.
  • Perform technical impact analysis of newly disclosed CVEs.
  • Determine affected product versions and configurations.
  • Coordinate remediation activities with R&D.
  • Support development of security patches and mitigations.
  • Validate fixes through security retesting.
  • Provide technical inputs for customer vulnerability advisories and security communications.
  • Maintain evidence supporting vulnerability closure and product security decisions.

  1. Presales & Customer Security Support

The engineer will also provide technical support to Presales, Sales Engineering and Product Management for cybersecurity-related customer engagements.

Responsibilities include:

  • Responding to customer security questionnaires.
  • Supporting RFP/RFQ security requirements.
  • Responding to customer vulnerability/CVE questions.
  • Explaining product security architecture and controls.
  • Supporting customer security assessments.
  • Reviewing customer-specific security requirements.
  • Providing technical responses to AT&T CSO and other enterprise customer security checklists.
  • Participating in customer security discussions and technical presentations when required.

The candidate should be able to translate complex cybersecurity concepts into clear, technically accurate customer-facing responses.

Required Technical Skills Vulnerability Management

  • Strong understanding of CVE, CWE, CVSS, EPSS and CISA KEV.
  • Vulnerability triage and risk prioritization.
  • Vulnerability remediation and verification.
  • Vulnerability lifecycle management.

Security Tools

Hands-on experience with several of the following is required:

Area Preferred Tools

Vulnerability Assessment Tenable Nessus

DAST / Web Security Burp Suite, OWASP ZAP

SCA / Binary Security JFrog Xray

SAST Coverity

SBOM Dependency-Track

Area Preferred Tools

Vulnerability Management DefectDojo

Defect Tracking Jira

CI/CD Jenkins/GitLab/GitHub or equivalent

Telecom / Networking

Strong understanding of:

  • TCP/IP and networking fundamentals.
  • IPv4/IPv6.
  • DNS, DHCP, HTTP/HTTPS.
  • SSH/SFTP.
  • TLS and certificates.
  • Linux systems.
  • Network management systems.
  • Telecom/enterprise radio networks.
  • Embedded/edge systems.
  • Virtualization and/or container technologies.

Regulatory & Security Knowledge

Experience with one or more of the following:

  • EU Cyber Resilience Act (CRA).
  • EU RED cybersecurity requirements.
  • IEC/EN 62443.
  • NIST Cybersecurity Framework.
  • ISO/IEC 27001 / 27002.
  • Secure Software Development Lifecycle (SSDLC).
  • Software Supply Chain Security.
  • SBOM requirements.
  • Vulnerability disclosure and PSIRT processes.
  • Customer security assurance programs.

Key Behavioral Competencies

The successful candidate should demonstrate:

  • Strong analytical and problem-solving skills.
  • Ability to understand complex telecom systems.
  • Strong ownership of security findings from discovery through closure.
  • Ability to work effectively with R&D and software development teams.
  • Good communication and technical documentation skills.
  • Ability to challenge engineering designs constructively from a security perspective.
  • Ability to work independently and manage multiple product security activities.
  • Strong customer-facing communication skills.
  • Ability to explain cybersecurity risks to both technical and non-technical stakeholders.

Regards

Emily Jha

[HIDDEN TEXT]

Netsach Global

www.netsachglobal.com

More Info

Job Type:
Function:
Employment Type:

Key Skills

Security System Engineer

telecom security

wireless infrastructure

security testing tools

Dependency-Track

DefectDojo

Product Vulnerability Management

Centralized Vulnerability Management Platform

CI/CD

SBOM generation

EU Cyber Resilience Act (CRA)

EU Radio Equipment Directive (RED)

Vulnerability Remediation

PSIRT Collaboration

About Company

Netsach is a Bangalore based company with professionals of great expertise & talent working within itself. We at Netsach endeavor to be the leading global provider of HR/Recruitment, IT Infrastructure, Media & Production, and Marketing Solution & Consulting of this time and in the future to come.