← Back to site

Tejas Bharambe

Staff Engineer II, Product Security · Medical Devices & Embedded Systems

Professional Summary

Product security engineer with 4+ years securing FDA-regulated medical devices across the full product lifecycle — from threat modeling and secure design through implementation, vulnerability management, and FDA premarket cybersecurity submissions. Builds reusable security frameworks and guardrails that scale across product lines: embedded Linux (Yocto, OpenSTLinux) and Windows golden-image hardening, Azure security baselines, DevSecOps pipeline templates, PKI automation, and SBOM intelligence. Translates regulatory expectations into engineering; partners across Regulatory, Quality, Engineering, and Project Management to ship audit-ready products. Tackles emerging industry problems including C/C++ SBOM generation via build interception, SBOM lifecycle intelligence, AI-assisted security workflows, and post-quantum cryptography readiness. Upstream Linux kernel contributor with two patches reviewed and merged into mainline.

Core Strengths

Reusable Security Frameworks & Guardrails: Windows golden images, OpenSTLinux/Yocto hardening baselines, Azure security configuration, DevSecOps pipeline templates, container/code signing, and certificate lifecycle automation that scale across multiple product programs.

Threat Modeling & Secure Design: Owns threat modeling, security requirements, and architecture reviews for embedded, cloud, and Windows-based medical device platforms; authors security architecture views aligned with FDA expectations and reused across product lines.

Shift Left & Developer Enablement: Centralized SAST/SCA, IaC-validated cloud security, self-service PKI and PIN provisioning, automated post-market vulnerability monitoring, and SBOM enrichment embedded directly into developer workflows.

Regulatory Translation: Turns FDA premarket cybersecurity guidance, FDA eSTAR, AAMI TIR57, and NIST CSF into concrete engineering deliverables, secure design artifacts, and audit-ready submission packages.

Emerging Problem Solving: C/C++ SBOM generation via build interception, SBOM end-of-life intelligence, automated cloud drift detection, AI-assisted security workflows, and post-quantum cryptography readiness.

Experience

BD (Advanced Patient Monitoring)October 2024 — Present

Staff Engineer II, Product Security — Irvine, CA · Promoted to Staff Engineer II in June 2026; joined via BD's acquisition of Edwards Lifesciences' Critical Care business unit.

  • Lead product security across multiple medical device programs — threat modeling, secure design, vulnerability management, V&V, and cybersecurity documentation for FDA premarket submissions in partnership with Regulatory, Quality, and Program Management.
  • Built hardened Windows golden images for AI-algorithm laptop platforms under a compressed FDA AI response timeline (BIOS, firmware, OS, access control, lockdown), converting urgent one-off execution into a reusable pattern projected to cut future hardening from months to ~1 week.
  • Centralized Coverity SAST scanning across product teams into a controlled, scalable model and accelerated containerized build adoption across engineering.
  • Led migration of Coverity and Black Duck (with historical scan data and checker configurations) from Edwards into BD, preserving audit continuity after the divestiture.
  • Built a C/C++ SBOM generator using build-system interception to capture statically linked and manually included dependencies, addressing a known industry gap.
  • Developed SBOM end-of-life enrichment with confidence scoring, released as the open-source SBOM Support Analyzer.
  • Built self-service security automation (Microsoft Forms + Power Automate + Azure DevOps) for PKI certificate issuance and rolling PIN provisioning, replacing manual spreadsheets with authenticated, traceable flows.
  • Built a post-market vulnerability monitoring pipeline from Black Duck and Microsoft RSS feeds into Jira, generating remediation tasks routed by ownership.
Edwards Lifesciences LLCAugust 2021 — October 2024

Senior Engineer, Product Security — Irvine, CA · Critical Care business unit divested to BD in October 2024.

  • Owned product security across the full lifecycle of a Yocto-based embedded healthcare monitor — cybersecurity management plan, threat modeling, secure design, implementation, vulnerability management, and FDA premarket submission.
  • Built the OpenSTLinux hardening baseline for the division's first embedded Linux product of its kind; reused across subsequent product programs.
  • Established a QMS workflow wiring FDA eSTAR cybersecurity artifacts directly into the Product Development Lifecycle for repeatable compliance.
  • Authored Azure security configuration requirements and built scripts validating Terraform-defined infrastructure against them — drift detection and security-as-code before it was common practice.
  • Drove creation of a dedicated DevOps function: repo structure, secure build-agent strategy, a "build once, validate, promote" model, and reusable pipeline templates integrating SCA/SAST/IaC into IDEs and PR gates.
  • Replaced Ubuntu-based containers with minimal Alpine images, cleaning up ~95% of vulnerability noise; deployed Prisma Cloud CSPM/Compute and architected a private DigiCert ONE environment for SSL, code signing, and container signing.
Esri (Environmental Systems Research Institute)October 2020 — July 2021

Security Engineer, ArcGIS Enterprise — Redlands, CA

  • Stood up the threat modeling process for ArcGIS Enterprise and its applications; designed user-level access controls with the development team.
  • Hardened Docker images on Kubernetes by triaging WhiteSource and Protecode findings; implemented runtime monitoring with Falco.
  • Conducted black-box penetration testing of the Kubernetes cluster, pods, and services; triaged Acunetix findings and verified fixes across Windows and Linux patch releases.
Syracuse UniversitySpring 2019

Graduate Research Assistant — Syracuse, NY

  • Built a Data Consistency Checker improving verification rate for distributed-systems consistency models (linearizability, eventual, sequential) by ~10%, hardened against result tampering by executing inside an Intel SGX enclave.

Open Source & Thought Leadership

Education

M.S., Cybersecurity — Syracuse University, Syracuse, NYAug 2018 — May 2020
B.E., Computer Engineering — K. J. Somaiya Institute of Engineering & IT, Mumbai, IndiaJul 2014 — May 2018

Skills

Security Architecture: Embedded Linux (Yocto, OpenSTLinux), Windows Hardening (STIG, golden images), Threat Modeling, Secure SDLC, Vulnerability Management, SBOM (CycloneDX, SPDX), DevSecOps / Shift Left, Cloud Security, PKI & Certificate Lifecycle, Container & Kubernetes Security, Runtime Monitoring, Penetration Testing, Post-Quantum Cryptography Readiness
Compliance & Regulatory: FDA Premarket Cybersecurity Guidance, FDA eSTAR, AAMI TIR57, HIPAA, NIST CSF, DISA STIG
Security Tooling: Black Duck, Coverity, Wiz, Snyk, Checkmarx, Prisma Cloud (CSPM & Compute), DigiCert ONE, Falco, OWASP Threat Dragon, Acunetix, Nessus, Metasploit, Burp Suite Pro, Wireshark, Nmap, American Fuzzy Lop
Cloud / DevOps: Azure, Azure DevOps, AKS, ACR, Terraform, Docker, Kubernetes, Power Automate, ServiceNow, Jira
Languages & Systems: C, C++, Python, Bash · RHEL, Ubuntu, Fedora, Kali, Windows