368,941open jobs
9,452companies
47,951added this week
Browse all
Salary
$28k – $62k per year (Estimated)
Location
Remote (India)
Seniority
Senior · 5+ years exp
Employment
Full-Time
Overview
Company
Impact
Profile match
Clario is a healthcare technology company headquartered in Philadelphia, Pennsylvania, with a history dating back to 1972. The organization provides clinical trial endpoint technology and services, including electronic clinical outcome assessments, medical imaging, cardiac safety monitoring, and respiratory solutions. It operates on a global scale, supporting pharmaceutical and biotechnology firms through all phases of clinical research to generate high-quality evidence for regulatory submissions.
The Cybersecurity Engineer is a hands-on technical role responsible for strengthening Clario’s product and enterprise security posture through proactive security assessments, threat modeling, and secure design practices. This individual will partner closely with engineering, architecture, DevOps, and product teams to identify, assess, and mitigate security risks throughout the Software Development Lifecycle (SDLC).

The ideal candidate possesses deep expertise in penetration testing, threat modeling, application security, and secure development practices, with the ability to translate complex security findings into actionable remediation guidance. This role requires a security professional who can think like an attacker, validate security controls through manual and automated testing, and influence product teams to build resilient, secure solutions by design.

In addition to conducting security assessments, the Cybersecurity Engineer will help mature Clario’s DevSecOps capabilities by integrating security validation, testing, and governance into development pipelines and engineering workflows. Success in this role requires strong technical skills, effective communication, and the ability to work collaboratively across the organization to drive measurable security improvements.

Clario, part of Thermo Fisher Scientific, is seeking a highly skilled Cybersecurity Engineer to strengthen our Product Security and DevSecOps capabilities through a combination of penetration testing, threat modeling, secure design reviews, and security automation. In this role, you will conduct comprehensive security assessments across web applications, APIs, cloud environments, and supporting infrastructure to identify vulnerabilities and validate security controls. You will partner closely with Product, Engineering, Architecture, and DevOps teams to perform threat modeling exercises, review security architectures, and embed security-by-design principles throughout the Software Development Lifecycle (SDLC). The ideal candidate will have strong expertise in application security, threat modeling frameworks such as STRIDE or PASTA, secure development practices, and DevSecOps methodologies, with hands-on experience integrating security testing into CI/CD pipelines. This role also involves developing security automation, supporting vulnerability management and remediation efforts, mentoring engineering teams, contributing to security standards and governance initiatives, and driving continuous improvement across Clario's Product Security program. Success in this position requires the ability to think like an attacker, communicate risk effectively to technical and business stakeholders, and leverage modern security practices, cloud security knowledge, and automation technologies to build scalable, resilient, and secure products.

What We Offer

  • Competitive compensation

  • Provident fund and medical insurance

  • Engaging employee programs and local events

  • Modern office spaces and remote work flexibility

What You’ll Be Doing

  • Conduct comprehensive penetration testing of web applications, APIs, cloud environments, and supporting infrastructure to identify security vulnerabilities and validate security controls.

  • Lead threat modeling exercises for new and existing products, partnering with engineering and architecture teams to identify risks, attack paths, and appropriate mitigations early in the SDLC.

  • Perform secure design and architecture reviews to ensure products are built with security-by-design principles and aligned with industry standards and best practices.

  • Evaluate application, cloud, and infrastructure security controls and provide actionable recommendations to reduce risk and improve overall security posture.

  • Willingness to work in European Shift (1pm to 10pm)

  • Work closely with development teams to prioritize, track, and remediate security findings while promoting secure coding practices.

  • Integrate security testing and validation into CI/CD pipelines, enabling automated security checks and continuous risk identification throughout the development lifecycle.

  • Develop and maintain security tooling, scripts, and automation capabilities that improve the efficiency and effectiveness of security assessments.

  • Collaborate with Product, Engineering, DevOps, and Architecture teams to embed security requirements into product planning, design, development, and deployment processes.

  • Support vulnerability management activities, including validation, risk assessment, remediation guidance, and verification of fixes.

  • Contribute to the development and maintenance of security standards, secure development guidelines, and product security processes.

  • Stay current on emerging threats, attack techniques, vulnerabilities, and security technologies, applying that knowledge to improve Clario's security capabilities.

  • Provide technical guidance and mentorship to engineering teams on secure design, threat mitigation, and security best practices.

  • Assist with security audits, compliance initiatives, and evidence collection activities related to product and application security controls.

  • Drive continuous improvement of Clario's Product Security and DevSecOps programs through innovation, automation, and the adoption of industry-leading practices. Time Allocation (Typical)

  • 30-55% Product Security Engineering (Threat Modeling, Secure Design Reviews, Security Architecture Assessments, Developer Enablement)

  • 30-55% Penetration Testing and Security Validation Activities

  • 10-15% Security Automation, DevSecOps Integration, Governance, and Process Improvement

What We Look For

  • Bachelor's degree in Computer Science, Cybersecurity, Information Security, Software Engineering, or a related technical discipline, or equivalent practical experience.

  • 5+ years of experience in Cybersecurity, Application Security, Product Security, Security Engineering, or a related field.

  • Demonstrated experience performing manual and automated penetration testing of web applications, APIs, cloud environments, and supporting infrastructure.

  • Strong experience conducting threat modeling and security architecture reviews using established methodologies such as STRIDE, PASTA, ATT&CK, or equivalent frameworks.

  • Solid understanding of secure software development practices, common attack techniques, and security vulnerabilities, including the OWASP Top 10 and API Security Top 10.

  • Experience identifying, validating, and communicating security risks to technical and non-technical stakeholders.

  • Proficiency in one or more programming or scripting languages such as Python, Java, JavaScript, C#, PowerShell, Go, or similar languages.

  • Experience working within Agile development environments and integrating security practices into the SDLC.

  • Strong understanding of DevSecOps principles and experience integrating security tools into CI/CD pipelines.

  • Excellent analytical, problem-solving, communication, and collaboration skills.

  • Ability to independently drive security initiatives while partnering effectively with Engineering, Product, Architecture, and Operations teams.

  • Experience with cloud security assessments and securing environments in AWS, Azure, or Google Cloud Platform.

  • Experience with modern application architectures including microservices, APIs, containers, Kubernetes, and serverless technologies.

  • Familiarity with Static Application Security Testing (SAST), Dynamic Application Security Testing (DAST), Software Composition Analysis (SCA), Container Security, and Infrastructure-as-Code security tools.

  • Experience developing security automation, custom security tooling, or pipeline integrations to improve security coverage and efficiency.

  • Knowledge of secure architecture patterns, identity and access management, cryptography, and zero-trust security concepts.

  • Experience supporting regulatory, compliance, or audit requirements in highly regulated industries such as healthcare, life sciences, or financial services.

  • Security certifications such as:

    • OSCP (Offensive Security Certified Professional)

    • OSWE (Offensive Security Web Expert)

    • GWAPT (GIAC Web Application Penetration Tester)

    • GWEB (GIAC Web Application Defender)

    • CISSP (Certified Information Systems Security Professional)

    • CCSP (Certified Cloud Security Professional)

    • Azure, AWS, or GCP Security Certifications

  • A security-minded engineer who can think like an attacker while partnering with developers to build secure solutions.

  • Passionate about identifying and mitigating security risks before they become vulnerabilities.

  • Comfortable balancing hands-on technical work with strategic security guidance and influence.

  • Curious, self-motivated, and committed to continuously learning emerging technologies, attack techniques, and industry best practices.

  • An advocate for Security-by-Design who can drive security improvements without slowing product innovation.

  • Skilled at translating complex security concepts into practical recommendations that enable business and engineering outcomes.

  • Focused on automation, scalability, and continuous improvement to enhance both security effectiveness and developer experience.

  • Building or operating Product Security programs.

  • Leading enterprise-wide threat modeling initiatives.

  • Conducting red team or adversarial security assessments.

  • Creating security standards, secure coding guidance, or developer training programs.

  • Leveraging AI-assisted security analysis, remediation workflows, or security engineering automation.

At Clario, a part of Thermo Fisher Scientific, our purpose is to transform lives by unlocking better evidence. Whether you're advancing clinical science, building innovative technology, or supporting our global teams, your work helps bring life-changing therapies to patients faster.

The Department Head has the discretion to hire personnel with a combination of experience and education, which may vary from the above listed qualifications.

EEO Statement

Clario is an equal opportunity employer. Clario evaluates qualified applicants without regard to race, color, religion, gender, national origin, age, sexual orientation, gender identity or expression, protected veteran status, disability/handicap status, or any other legally protected characteristic.

Free account
Stop reading job ads. Get the ones that fit.
One free account turns this page into a shortlist built around your stack, your level and your pay.
Match on every job. Stack, seniority, pay and location, scored against your profile.
368,941 open roles. Read straight off company career pages, refreshed every day.
Unlimited applications. Every one you send is tracked in one place, on-site or on a company board.
3 tailored CVs a month. Rewritten for the exact job you are applying to. Included free.
Create a free account
Free forever. No card. Under a minute.

Your match

How well do you fit this role?
Two answers are enough for a real match. No account needed.
Check my fit
Answers stay in this browser until you create an account.

Recommended for you based on this role

Similar stack
Same company
India
$185k – $260k per year • Remote • Full-Time • 8+ years exp • Bachelor's Degree
DevOps
AWS
CI/CD
GCP
Kubernetes
GitHub
Cybersecurity
Clair
Dependabot
OWASP Top 10
OWASP ZAP
Snyk
Trivy
Apply
$68k – $85k per year • In office • Full-Time • Master's Degree • San Jose
Python
AI/ML
AI Agents
DevOps
Amazon EC2
AWS
AWS Lambda
Bitbucket
CI/CD
CloudFormation
Docker
Git
Kubernetes
Terraform
Amazon S3
IAM
HPC
Cybersecurity
Least Privilege
Apply
In office • Part-Time • 2+ years exp • Bachelor's Degree • Ness Ziona
C#
Java
AI/ML
Copilot
Cursor
DevOps
CI/CD
GitHub
Apply
$110k – $131k per year • Remote • Full-Time • 10+ years exp • Bachelor's Degree
DevOps
AWS
Incident Management
VMWare
Apply
$118k – $142k per year • In office • Full-Time • 2+ years exp • Bachelor's Degree • El Segundo
C++
MATLAB
Python
SystemC
SystemVerilog
Verilog
VHDL
DevOps
CI/CD
QEMU
Chips/EDA
UVM
Apply
$46k – $87k per year (Estimated) • Remote/Hybrid • Full-Time • 4+ years exp • Budapest
C#
SQL
TypeScript
JavaScript
C#
.NET
Frontend
Angular
DevOps
CI/CD
Apply
$8k – $34k per year (Estimated) • Remote • Full-Time • Bachelor's Degree • India
DevOps
AWS
Apply
PET Scientist 5 days ago
$122k – $215k per year (Estimated) • Remote • Full-Time • 5+ years exp • PhD • United States • Costa Rica
MATLAB
Python
Apply
$71k – $154k per year (Estimated) • In office • Full-Time • 10+ years exp • Bachelor's Degree • Germany
JavaScript
Python
Ruby
SQL
Apply
$101k – $187k per year (Estimated) • Remote • Full-Time • 3+ years exp • Bachelor's Degree • United States
Apply
Lead Data Steward 6 hours ago
$25k – $58k per year (Estimated) • In office • Full-Time • Gurgaon
SQL
Databases
Databricks
PostgreSQL
Snowflake
AI/ML
AI Agents
Copilot
Analytics
Power BI
Apply
$19k – $42k per year (Estimated) • In office • Full-Time • 5+ years exp • India
JavaScript
SQL
Databases
Oracle
Marketing
Salesforce
Apply
$20k – $52k per year (Estimated) • In office • Full-Time • 7+ years exp • Bachelor's Degree • India
Python
SQL
C#
TypeScript
JavaScript
C#
.NET
AI/ML
AI Agents
Frontend
Angular
Apply
$16k – $38k per year (Estimated) • In office • Full-Time • 3+ years exp • India
SQL
Databases
Azure SQL Database
DevOps
AWS
Azure
CI/CD
GitHub
Kubernetes
Terraform
Apply
$24k – $63k per year (Estimated) • In office • Full-Time • 6+ years exp • Master's Degree • India
Crystal
Groovy
JavaScript
Perl
Python
Ruby
SQL
TypeScript
Java
Java
Apache Tomcat
Gradle
Hibernate
Maven
Spring Boot
Spring MVC
Databases
Apache Kafka
Db2
Oracle
PostgreSQL
RabbitMQ
AI/ML
Fine-tuning
Frontend
Angular
JQuery
DevOps
Apache HTTP Server
AWS
Azure
CI/CD
Docker
GCP
Jenkins
Kubernetes
Rest API
Cybersecurity
Checkmarx
SonarQube
Apply
See all jobs
This is one of many
368,941 more open roles from verified company boards, updated every day.