This role is responsible for conducting offensive security testing on Philips products, ensuring they meet security requirements before being released to the market. Given the evolving threat landscape, this position is crucial in safeguarding the security of Philips products. By contributing to the overall security process, you will gain valuable experience and knowledge, while directly impacting Philips Cost of Goods Sold and supporting the companys broader objectives and vision.
Technical Skills And Experience
2-4 years of progressive experience in manual vulnerability exploitation, report generation, identifying vulnerabilities, and providing detailed recommendations for exploitation. Expertise in one or more of the following areas:
Preferred Expertise (This is in addition to the outlined Required Expertise):
System Testing: Proficiency in kiosk bypass techniques, hardening bypass methods, and bypassing application whitelisting solutions.
Required Expertise
Thick Client Testing: Hands-on penetration testing experience with fat client applications developed in .NET, Java, C++, Electron, etc.
Keywords: Desktop application security, Thick client penetration/security testing, dotPeek, dnSpy, Procmon, Process Hacker, Microsoft Sysinternals, Fiddler, Frida, Binary patching, Hooking, DLL Injection, Electron Security, .NET framework security.
Web Application Testing: Expertise in testing web applications built with contemporary frameworks, such as React, Angular, Node.js, and others. In-depth understanding of web application security principles, OWASP Top 10, and common vulnerabilities in both legacy and modern applications (e.g., SQL injection, XSS, CSRF, etc.).
Tools & Techniques:
Thick Client Testing: Expertise in using tools such as Microsoft Sysinternals Suite, dnSpy and reverse engineering techniques for testing fat clients. Familiarity with debugging, decompiling, and analyzing .NET, Java, C++, and Electron-based client applications.
Web Application: Proficiency with web application penetration testing tools such as Burp Suite, OWASP ZAP, and other automated or manual testing tools for vulnerabilities like SQL injection, XSS, SSTI and others.
General Tools: Familiarity with industry-standard penetration testing tools (e.g., Metasploit, Nmap, Nessus) for both web and system/thick client applications, with an emphasis on manual and automated vulnerability identification and exploitation.
Scripting: Proficiency in scripting languages such as Python, PowerShell, or Rust to automate repetitive test cases and process-related activities, streamlining testing workflows and enhancing efficiency.
Good to have Expertise(This is in addition to the outlined Required Expertise):
IoT Security testing
Bluetooth/Zigbee/Wifi security testing
Infrastructure security testing.
Cloud security assessments.
Good hands-on experience with Security Assessment / SCA tools.
Exposure to current security threats, specifically application security.
Experience/exposure to programming platforms such as Java /.Net/ C and C++, is an added advantage.
Should have experience in end-to-end application security testing for multiple products, projects, or applications, with a strong understanding of the SDLC and testing lifecycle.
Certifications: CEH/OSCP/CSSLP/CISSP/GCIH/GPEN (at least one)
Key Area Responsibility
Performs Ethical Hacking into products/solutions.
Stay current with industry trends and consistently apply this knowledge and expertise in the workplace.
Conduct training sessions and workshops within areas of expertise.
Pro-actively co-ordinate and collaborate with different stake holders at different stages of security testing in the project.
Creates and updates test specifications.
Ensure technical & testing documentation is kept up to date and audit ready.
Automate repetitive test cases and process-related activities, streamlining testing workflows and enhancing efficiency.
Personal Skills Include
Exemplifies a positive attitude and strong persistence in overcoming technical challenges and contributing to a collaborative work environment.
Excellent verbal and written communication skills.
Proven ability to thrive and adapt in a fast-paced, dynamic environment.
Proactive and capable of working effectively both independently and as part of a team.
Proven ability to handle confidential information with discretion, coupled with strong analytical and innovative problem-solving skills.
Highly passionate about security and dedicated to continuous improvement of skills and expertise.
How We Work Together
We believe that we are better together than apart. For our office-based teams, this means working in-person at least 3 days per week.
Onsite roles require full-time presence in the company’s facilities.
Field roles are most effectively done outside of the company’s main facilities, generally at the customers’ or suppliers’ locations.
About Philips
We are a health technology company. We built our entire company around the belief that every human matters, and we wont stop until everybody everywhere has access to the quality healthcare that we all deserve. Do the work of your life to help the lives of others.
Learn more about our business.
Discover our rich and exciting history.
Learn more about our purpose.
If you’re interested in this role and have many, but not all, of the experiences needed, we encourage you to apply. You may still be the right candidate for this or other opportunities at Philips. Learn more about our commitment to diversity and inclusion here.
Searching, interviewing and hiring are all part of the professional life. The TALENTMATE Portal idea is to fill and help professionals doing one of them by bringing together the requisites under One Roof. Whether you're hunting for your Next Job Opportunity or Looking for Potential Employers, we're here to lend you a Helping Hand.
Disclaimer: talentmate.com is only a platform to bring jobseekers & employers together.
Applicants
are
advised to research the bonafides of the prospective employer independently. We do NOT
endorse any
requests for money payments and strictly advice against sharing personal or bank related
information. We
also recommend you visit Security Advice for more information. If you suspect any fraud
or
malpractice,
email us at abuse@talentmate.com.
You have successfully saved for this job. Please check
saved
jobs
list
Applied
You have successfully applied for this job. Please check
applied
jobs list
Do you want to share the
link?
Please click any of the below options to share the job
details.
Report this job
Success
Successfully updated
Success
Successfully updated
Thank you
Reported Successfully.
Copied
This job link has been copied to clipboard!
Apply Job
Upload your Profile Picture
Accepted Formats: jpg, png
Upto 2MB in size
Your application for Software Engineer II - Product Security
has been successfully submitted!
To increase your chances of getting shortlisted, we recommend completing your profile.
Employers prioritize candidates with full profiles, and a completed profile could set you apart in the
selection process.
Why complete your profile?
Higher Visibility: Complete profiles are more likely to be viewed by employers.
Better Match: Showcase your skills and experience to improve your fit.
Stand Out: Highlight your full potential to make a stronger impression.
Complete your profile now to give your application the best chance!