Senior Product Security Engineer

Vaga não está no LinkedIn

🕒 Abril 24

🇺🇸 Estados Unidos – Remoto (EUA)

💵 $127.000 - $165.000 / ano

⏰ Tempo Integral

🟠 Sênior

👮‍♂️ Cibersegurança / Engenheiro de Segurança

🗣️🇺🇸🇬🇧 Inglês obrigatório

Candidatar-se
Encontrar Vagas Remotas Similares

📊 Verifique sua pontuação de currículo para esta vaga

Melhore suas chances de conseguir uma entrevista verificando sua pontuação de currículo antes de se candidatar.

Logo of iRhythm Technologies, Inc.

iRhythm Technologies, Inc.

1001 - 5000 funcionários

Fundada em 2006

⚕️ Seguro de Saúde

🧬 Biotecnologia

Healthcare Insurance • Biotechnology • Medical Technology

A iRhythm Technologies, Inc. é uma empresa de tecnologia em saúde que se especializa em soluções de monitoramento cardíaco. Seu produto principal, o monitor Zio ECG, é projetado para o conforto e aderência do paciente, permitindo que os profissionais de saúde forneçam diagnósticos precisos de arritmias através de análise avançada de dados e inteligência artificial. O serviço abrangente da iRhythm transforma a experiência de monitoramento cardíaco, facilitando melhores resultados para os pacientes e fluxos de trabalho eficientes para profissionais de saúde em todo o mundo.

Descrição

• Ensure compliance with FDA cybersecurity guidance and regulations in collaboration with Cybersecurity, Regulatory, Quality, and Systems Development teams. • Conduct comprehensive security risk assessments, including Cybersecurity Risk Assessments (CSRAs), to identify vulnerabilities and threats across device hardware, firmware, software, and cloud components. • Develop and maintain device-specific cyber threat models, factoring in patient safety, data privacy, and operational continuity. • Demonstrate familiarity with Software Bill of Materials (SBOM) and effectively communicate technical details. • Create and maintain cybersecurity documentation for pre- and post-market activities, ensuring regulatory alignment. • Produce detailed data flow diagrams to support the threat modeling process. • Participate in design reviews of medical device architectures and implementations, providing actionable recommendations for system security requirements. • Perform and support vulnerability analysis and coordinate the vulnerability management program, including scanning, patching, and remediation for medical devices. • Leverage and maintain application and threat detection tools (Veracode, Snyk, GitLab, or equivalent) to identify security flaws early in the SDLC. • Support investigation and remediation of device-related security incidents, minimizing impact and preventing recurrence. • Partner with the Privacy Team to ensure adherence to HIPAA, GDPR, and other data protection regulations.

🎯 Requisitos

• Bachelor’s degree in Computer Science, Information Security, or related field. • 6+ years of experience in information security, with direct focus on product security for medical devices. • Strong understanding of security principles, methodologies, and tools within the PDLC and SDLC. • Demonstrated experience conducting Cybersecurity Risk Assessments (CSRAs), vulnerability analysis, and working with modern threat detection tools (Veracode, Snyk, GitLab, or similar). • Familiarity with NIST Cybersecurity Framework, NIST SP 800-171, and deeper controls/frameworks such as NIST SP 800-53 (Security and Privacy Controls), NIST SP 800-92 (Log Management), and NIST SP 800-63 (Digital Identity Guidelines). • Hands-on experience with vulnerability identification and threat modeling within healthcare using methodologies such as STRIDE. • Experience operating in a regulated environment (FDA, HIPAA, GDPR, international regulatory frameworks). • Experience with medical device hardware or Software as a Medical Device (SaMD). • Experience with medical device software development and regulatory processes. • Excellent problem-solving, analytical, and communication skills, able to take a multi-siloed approach. • Ability to understand intro dependencies of teams across; mobile applications, hardware and cloud environments. • Demonstrated experience supporting 510(k) submissions, with a focus on product security documentation, risk assessments, and regulatory compliance.

🏖️ Benefícios

• Health insurance • 401(k) matching • Flexible work hours • Professional development opportunities

Candidatar-se

Vagas Similares

🕒 Abril 24

Emory University

10.000+ funcionários

📚 Educação

🔬 Ciência

Federated Security Engineer focused on secure application access management and integration at Emory University. Collaborating with Cybersecurity and IAM teams for efficient onboarding and compliance.

🗣️🇺🇸🇬🇧 Inglês obrigatório

🕒 Abril 24

AGFA HealthCare

1001 - 5000

Information Security Leader defining and executing the cybersecurity vision across all business units at AGFA HealthCare. Providing enterprise-wide security leadership focused on cloud-native and SaaS platforms.

🇺🇸 Estados Unidos – Remoto (EUA)

⏰ Tempo Integral

🟠 Sênior

👮‍♂️ Cibersegurança / Engenheiro de Segurança

🗣️🇺🇸🇬🇧 Inglês obrigatório

🕒 Abril 23

Boomi

1001 - 5000

☁️ SaaS

🔌 API

🏢 Corporativo

Senior Advisor overseeing cybersecurity operations and improving security practices at Boomi. Managing security tools, incident responses, and compliance efforts in a cloud environment.

🗣️🇺🇸🇬🇧 Inglês obrigatório

🕒 Abril 23

Emory University

10.000+ funcionários

📚 Educação

🔬 Ciência

Federated Security Engineer managing secure application access for Emory University. Collaborating with technical teams on IAM processes and cybersecurity compliance.

🗣️🇺🇸🇬🇧 Inglês obrigatório

🕒 Abril 23

Wiz

201 - 500

🔒 Cibersegurança

Software Security Engineer developing secure platforms and services for corporate security at Wiz. Collaborating cross-functionally to manage enterprise security practices effectively.

🗣️🇺🇸🇬🇧 Inglês obrigatório