Staff Engineer, Software (DevSecOps)
Posted on: December 03, 2025 | Job ID: R-01321920
Company Name: Thermofisher.com
Division: Research & Development / Digital Engineering
Location: Bangalore, India | Employment Type: Full-Time
Schedule: On-Site (Office-Centric) | Experience Level: 03-05 Years
About Thermo Fisher Scientific
Thermo Fisher Scientific Inc. stands as the world leader in serving science, with annual revenue exceeding $40 billion and approximately 75,000 employees across the globe. Our mission is clear and compelling: to enable our customers to make the world healthier, cleaner, and safer. From accelerating life sciences research and solving complex analytical challenges to improving patient diagnostics and developing life-changing therapies, we support groundbreaking work that impacts millions of lives worldwide.
Our global team delivers an unrivaled combination of innovative technologies, purchasing convenience, and pharmaceutical services through industry-leading brands including Thermo Scientific, Applied Biosystems, Invitrogen, Fisher Scientific, Unity Lab Services, Patheon, and PPD. With the largest investment in research and development in the industry, we invest over $1.4 billion annually to provide our teams with the resources needed to drive innovation and make significant contributions to science and society.
Position Overview
We are seeking an exceptional Staff Engineer with deep expertise in DevSecOps and vulnerability management to join our Digital Engineering team in Bangalore. This is a senior technical leadership role where you'll architect and implement enterprise-scale security solutions that protect our cloud-native applications and infrastructure while enabling development teams to build secure, scalable systems.
Why This Role Matters
At Thermo Fisher Scientific, security isn't just a checkpoint—it's embedded in everything we do. As a Staff Engineer focused on DevSecOps and vulnerability management, you'll play a critical role in protecting the systems that help scientists accelerate research, improve patient outcomes, and solve some of the world's most pressing challenges. Your work will directly impact the security posture of applications used by researchers, healthcare professionals, and laboratories worldwide.
The Digital Engineering Team
Digital Engineering serves as Thermo Fisher's Software Engineering center of excellence in Bengaluru. Our team develops and delivers cutting-edge SaaS-based applications and cloud-based digital lab tools that help scientists work more efficiently and with greater precision. We're building the next generation of scientific platforms that leverage the power and scalability of the cloud, and we need security leaders who can ensure these platforms are built with security at their foundation.
Key Responsibilities
Security Architecture & Leadership
Champion modern software development practices with security at the forefront, including secure microservices architecture, API security design, and comprehensive DevSecOps principles. Lead security architecture reviews, threat modeling sessions, and security design consultations to ensure all systems are built with defense-in-depth strategies. You'll serve as the trusted security advisor for multiple development teams, providing guidance on secure coding practices, authentication and authorization patterns, and data protection strategies. Your architectural decisions will influence how security is implemented across our entire digital platform ecosystem.
Vulnerability Management & Threat Detection
Build and maintain a comprehensive vulnerability management program that identifies, assesses, prioritizes, and remediates security vulnerabilities across our application portfolio and cloud infrastructure. Implement automated vulnerability scanning using industry-leading tools for Static Application Security Testing (SAST), Dynamic Application Security Testing (DAST), Software Composition Analysis (SCA), and Infrastructure as Code (IaC) security scanning. Develop sophisticated threat detection mechanisms that identify security anomalies, potential breaches, and suspicious activities in real-time. Create dashboards and reporting mechanisms that provide security visibility to stakeholders at all levels while maintaining detailed audit trails for compliance purposes.
Security Automation & Tool Integration
Design and implement end-to-end security automation pipelines that embed security controls throughout the software development lifecycle. Integrate security tools seamlessly into CI/CD pipelines, ensuring that security checks are automated, repeatable, and don't become bottlenecks to delivery. Develop custom security automation scripts and tools using Python, Bash, and PowerShell to address unique security challenges specific to our environment. Implement automated security remediation workflows that can fix common vulnerabilities without manual intervention, significantly reducing mean time to remediation.
Cloud Security & Infrastructure Protection
Architect and implement robust security controls for multi-cloud environments including AWS, Azure, and GCP. Ensure proper configuration of cloud security services including identity and access management, network security groups, encryption at rest and in transit, and cloud-native security monitoring. Implement container security best practices for Kubernetes-based deployments, including pod security policies, network policies, image scanning, and runtime security monitoring. Design secure infrastructure-as-code templates using Terraform and other IaC tools that enforce security standards by default.
Compliance & Risk Management
Drive implementation of security compliance requirements including industry standards and regulatory frameworks applicable to life sciences and healthcare sectors. Conduct regular security risk assessments to identify potential threats, vulnerabilities, and business impacts. Develop risk mitigation strategies and work with stakeholders to implement appropriate security controls. Maintain comprehensive security documentation including security policies, procedures, runbooks, and incident response plans that ensure organizational readiness for security events.
Team Collaboration & Mentorship
Collaborate with global development teams, infrastructure engineers, and business stakeholders to deliver high-impact security features that align with organizational priorities. Educate and mentor development teams on secure coding practices, security tools usage, and DevSecOps methodologies. Foster a culture of security awareness where every team member understands their role in maintaining security. Lead by example, demonstrating technical excellence and encouraging continuous learning and innovation in security practices.
Incident Response & Security Operations
Participate in security incident response activities, leading investigation and remediation efforts for security events. Develop and maintain incident response playbooks that enable rapid and effective response to various security scenarios. Conduct post-incident reviews to identify root causes and implement preventive measures. Collaborate with security operations teams to ensure proper monitoring, alerting, and response capabilities are in place for all critical systems.
Required Qualifications
Education
Bachelor's or Master's degree in Computer Science, Information Technology, Cyber Security, or related technical field. Equivalent professional experience in software engineering with security specialization will be considered.
Professional Experience
We're seeking candidates with 10+ years of overall software development experience, including at least 3+ years in a technical leadership role focused on DevSecOps, application security, or security engineering. Your background should demonstrate:
- Proven foundation in DevSecOps practices with hands-on experience implementing security automation in enterprise environments
- Strong experience with Linux system administration and network engineering with a security-centric approach
- Extensive knowledge of vulnerability management tools and practices including SAST, DAST, SCA, and penetration testing methodologies
- Deep understanding of secure software development lifecycle (SSDLC) and how to integrate security throughout the development process
- Experience working in Agile and DevOps environments where security is integrated into fast-paced delivery cycles
- Hands-on experience with cloud security services and cloud-native security tools across AWS, Azure, or GCP platforms
- Practical knowledge of container security including Docker and Kubernetes security best practices
Technical Skills & Expertise
Security Tools & Technologies:
- Proficiency with vulnerability scanning and management platforms
- Experience with SAST/DAST tools such as Checkmarx, Fortify, Veracode, or similar solutions
- Knowledge of SCA tools for open-source security and license compliance
- Familiarity with penetration testing tools and methodologies
- Experience with security information and event management (SIEM) systems
Cloud & Infrastructure:
- Solid grasp of network engineering concepts including firewalls, load balancers, VPNs, and network segmentation
- Deep understanding of multi-tiered architectures and enterprise application security patterns
- Expertise in Kubernetes security including RBAC, network policies, pod security, and admission controllers
- Knowledge of infrastructure-as-code security scanning and policy enforcement
- Understanding of cloud security posture management (CSPM) concepts and tools
Authentication & Authorization:
- Comprehensive knowledge of authentication and authorization protocols including SAML, OAuth 2.0, OpenID Connect, Kerberos
- Experience implementing multi-factor authentication (MFA), one-time passwords (OTP/TOTP), and modern authentication methods like WebAuthn
- Understanding of identity and access management (IAM) principles and implementation
DevOps & Automation:
- Strong scripting skills in Python, Bash, PowerShell, or similar languages
- Experience with CI/CD pipeline security including Jenkins, GitLab CI, GitHub Actions, or Azure DevOps
- Knowledge of GitOps practices and securing software supply chains
- Familiarity with configuration management tools like Ansible, Chef, or Puppet
Networking & Protocols:
- Knowledge of Internet protocols and services including DNS, DHCP, LDAP, SMTP, HTTP/HTTPS
- Understanding of network security protocols including TLS/SSL, IPSec, and secure network design
- Experience with API security including API gateways, rate limiting, and API threat protection
Certifications (Preferred)
While not mandatory, relevant security certifications demonstrate commitment to the field and are highly valued:
- AWS Certified Security Specialty or Azure Security Engineer Associate
- Certified Information Systems Security Professional (CISSP)
- Certified Ethical Hacker (CEH)
- GIAC Security Certifications (GSEC, GWAPT, GPEN)
- Certified Kubernetes Security Specialist (CKS)
Personal Attributes
- Exceptional problem-solving and analytical skills with ability to think like an attacker
- Strong communication skills with ability to explain complex security concepts to non-technical stakeholders
- Passion for staying current with emerging security threats, vulnerabilities, and mitigation strategies
- Collaborative mindset with ability to influence without direct authority
- Self-motivated with strong organizational skills and ability to manage multiple priorities
- Security-first mindset balanced with pragmatic approach to enable business objectives
Work Environment
This role is based in our modern Bangalore office with a collaborative, dynamic work environment. The position may occasionally require flexibility for global team collaboration across different time zones. While primarily office-based, occasional visits to data centers or other facilities may be required for security assessments or incident response activities.
Comprehensive Benefits Package
Thermo Fisher Scientific offers competitive compensation including base salary, annual performance bonus, and comprehensive benefits:
- Competitive salary commensurate with experience
- Annual incentive plan bonus based on individual and company performance
- Comprehensive healthcare coverage for you and your family
- Professional development opportunities including training, certifications, and conference attendance
- Career advancement opportunities within a global organization
- Collaborative work culture that values innovation, integrity, and continuous improvement
- Access to cutting-edge technologies and tools
- Work-life balance initiatives and flexible working arrangements
Our Culture
Join an organization that stands for integrity, intensity, involvement, and innovation. We foster an inclusive environment where diverse perspectives are valued and every team member can contribute their best work. Our culture encourages continuous learning, rewards innovation, and recognizes that our people are our greatest asset in achieving our mission.
Equal Opportunity Employer
Thermo Fisher Scientific is proud to be an equal opportunity employer. All qualified applicants will receive consideration for employment without regard to race, creed, religion, color, national or ethnic origin, citizenship, sex, sexual orientation, gender identity and expression, genetic information, veteran status, age, or disability status. We are committed to creating an inclusive environment where all employees can thrive.
Accessibility Support
Thermo Fisher Scientific provides accessibility services for job seekers requiring accommodations in the job application process. This may include individuals requiring assistance because of hearing, vision, mobility, or cognitive impairments. If you require accessibility assistance or an accommodation to apply for this position, please contact us with your specific needs and contact information so we can provide appropriate support throughout the application process.
Ready to Lead Security Innovation?
If you're passionate about security, excited by the challenge of protecting enterprise-scale applications, and want your work to contribute to scientific breakthroughs that improve lives worldwide, we want to hear from you. Join our team and help us build secure, scalable platforms that empower scientists to make the world healthier, cleaner, and safer.
Note: This position requires the ability to work in India and may be subject to background checks and security clearances as appropriate for the role.

