Staff Engineer II, Product Security · BD

Tejas Bharambe

I secure FDA-regulated medical devices across their entire lifecycle — from threat modeling and secure design to embedded Linux hardening, DevSecOps, and FDA premarket submissions.

4+Years in product security
2Linux kernel patches merged
4Open-source security tools

Summary

I build reusable security frameworks and guardrails that scale across product lines — embedded Linux and Windows golden images, Azure baselines, DevSecOps pipeline templates, PKI automation, and SBOM intelligence.

I translate regulatory expectations into engineering, partnering across Regulatory, Quality, Engineering, and Program Management to ship audit-ready products. I work on emerging industry problems including C/C++ SBOM generation via build interception, SBOM lifecycle intelligence, AI-assisted security workflows, and post-quantum cryptography readiness — and I'm an upstream Linux kernel contributor.

Tejas Bharambe

Core strengths.

Reusable Security Frameworks

Windows golden images, OpenSTLinux/Yocto hardening baselines, Azure security configuration, DevSecOps pipeline templates, container/code signing, and certificate lifecycle automation that scale across multiple product programs.

Threat Modeling & Secure Design

Owns threat modeling, security requirements, and architecture reviews for embedded, cloud, and Windows-based medical device platforms — authoring security architecture views aligned with FDA expectations and reused across product lines.

Shift Left & Developer Enablement

Centralized SAST/SCA, IaC-validated cloud security, self-service PKI and PIN provisioning, automated post-market vulnerability monitoring, and SBOM enrichment — embedded directly into developer workflows.

Regulatory Translation

Turns FDA premarket cybersecurity guidance, FDA eSTAR, AAMI TIR57, and NIST CSF into concrete engineering deliverables, secure design artifacts, and audit-ready submission packages.

Emerging Problem Solving

C/C++ SBOM generation via build interception, SBOM end-of-life intelligence, automated cloud drift detection, AI-assisted security workflows, and post-quantum cryptography readiness.

Cloud & Container Security

Prisma Cloud CSPM & Compute, Wiz, minimal Alpine container patterns, AKS/ACR, private DigiCert ONE PKI, and Terraform validation-as-code — operationalized well before it was common practice.

Experience.

BD Advanced Patient Monitoring

Oct 2024 — Present

Staff Engineer II, Product Security · Irvine, CA

Promoted to Staff Engineer II in June 2026. Joined BD via its acquisition of Edwards Lifesciences' Critical Care business unit, continuing with the same team.

  • Lead product security across multiple medical device programs — threat modeling, secure design, vulnerability management, V&V, and cybersecurity documentation for FDA premarket submissions in partnership with Regulatory, Quality, and Program Management.
  • Built hardened Windows golden images for AI-algorithm laptop platforms under a compressed FDA AI response timeline (BIOS, firmware, OS, access control, lockdown), turning urgent one-off work into a reusable pattern projected to cut future hardening from months to ~1 week.
  • Centralized Coverity SAST scanning across product teams into a controlled, scalable model and accelerated containerized build adoption across engineering.
  • Built a C/C++ SBOM generator using build-system interception to capture statically linked and manually included dependencies — addressing a known industry gap and guiding vendor toolchain discussions.
  • Developed SBOM end-of-life enrichment with confidence scoring, released as the open-source SBOM Support Analyzer.
  • Built self-service security automation (Microsoft Forms + Power Automate + Azure DevOps) for PKI certificate issuance and rolling PIN provisioning, replacing manual spreadsheets with authenticated, traceable flows.
  • Built a post-market vulnerability monitoring pipeline from Black Duck and Microsoft RSS feeds into Jira, generating remediation tasks routed by ownership.

Edwards Lifesciences

Aug 2021 — Oct 2024

Senior Engineer, Product Security · Irvine, CA

Critical Care business unit divested to BD in October 2024.

  • Owned product security across the full lifecycle of a Yocto-based embedded healthcare monitor — cybersecurity management plan, threat modeling, secure design, implementation, vulnerability management, and FDA premarket submission.
  • Built the OpenSTLinux hardening baseline for the division's first embedded Linux product of its kind; the resulting foundation was reused across subsequent product programs.
  • Established a QMS workflow wiring FDA eSTAR cybersecurity artifacts directly into the Product Development Lifecycle for repeatable compliance.
  • Authored Azure security configuration requirements and built scripts validating Terraform-defined infrastructure against them — drift detection and security-as-code before it was common practice.
  • Drove creation of a dedicated DevOps function: repo structure, secure build-agent strategy, a "build once, validate, promote" model, and reusable pipeline templates integrating SCA/SAST/IaC into IDEs and PR gates.
  • Replaced Ubuntu-based containers with minimal Alpine images, cleaning up ~95% of vulnerability noise and establishing a reusable secure container pattern.
  • Deployed Prisma Cloud CSPM and Compute runtime protection across Azure and on-prem hospital gateways, and architected a private DigiCert ONE environment for SSL, code signing, and container signing.

Esri ArcGIS Enterprise

Oct 2020 — Jul 2021

Security Engineer · Redlands, CA

  • Stood up the threat modeling process for ArcGIS Enterprise and its applications, and designed user-level access controls with the development team.
  • Hardened Docker images on Kubernetes by triaging WhiteSource and Protecode findings, and implemented runtime security monitoring with Falco.
  • Conducted black-box penetration testing of the Kubernetes cluster, pods, and services; triaged Acunetix findings and verified fixes across Windows and Linux patch releases.

Syracuse University

Spring 2019

Graduate Research Assistant · Syracuse, NY

  • Built a Data Consistency Checker that improved verification rate for distributed-systems consistency models (linearizability, eventual, sequential) by ~10%, hardened against result tampering by executing inside an Intel SGX enclave.

Open source & thought leadership.

Skills.

Security Architecture

Embedded Linux (Yocto, OpenSTLinux)Windows Hardening (STIG, golden images)Threat ModelingSecure SDLCVulnerability ManagementSBOM (CycloneDX, SPDX)DevSecOps / Shift LeftCloud SecurityPKI & Certificate LifecycleContainer & Kubernetes SecurityRuntime MonitoringPenetration TestingPost-Quantum Crypto Readiness

Compliance & Regulatory

FDA Premarket Cybersecurity GuidanceFDA eSTARAAMI TIR57HIPAANIST CSFDISA STIG

Security Tooling

Black DuckCoverityWizSnykCheckmarxPrisma Cloud (CSPM & Compute)DigiCert ONEFalcoOWASP Threat DragonAcunetixNessusMetasploitBurp Suite ProWiresharkNmapAmerican Fuzzy Lop

Cloud / DevOps

AzureAzure DevOpsAKSACRTerraformDockerKubernetesPower AutomateServiceNowJira

Languages & Systems

CC++PythonBashRHELUbuntuFedoraKaliWindows

Education.

M.S., Cybersecurity

Syracuse University · Syracuse, NY

Aug 2018 — May 2020

B.E., Computer Engineering

K. J. Somaiya Institute of Engineering & IT · Mumbai, India

Jul 2014 — May 2018

Let's build something secure.

Always happy to talk product security, embedded systems, or FDA cybersecurity.

Irvine, CA · +1 (315) 601-2034