Senior Product Security Engineer

Job not on LinkedIn

🕒 April 24

🇺🇸 United States – Remote

💵 $127k - $165k / year

⏰ Full Time

🟠 Senior

👮‍♂️ Cybersecurity / Security Engineer

Apply Now
Find Similar Remote Jobs

📊 Check your resume score for this job

Improve your chances of getting an interview by checking your resume score before you apply.

Logo of iRhythm Technologies, Inc.

iRhythm Technologies, Inc.

1001 - 5000 employees

Founded 2006

⚕️ Healthcare Insurance

🧬 Biotechnology

Healthcare Insurance • Biotechnology • Medical Technology

iRhythm Technologies, Inc. is a medical technology company that specializes in digital healthcare solutions for the management of cardiac arrhythmias. The company is best known for its ZioSuite, a comprehensive platform designed to deliver a streamlined solution for assessing heart health through advanced analytics and patient-centered data collection. iRhythm focuses on improving patient outcomes and optimizing the efficiency of healthcare providers through innovative technology in the cardiac monitoring space.

📋 Description

• Ensure compliance with FDA cybersecurity guidance and regulations in collaboration with Cybersecurity, Regulatory, Quality, and Systems Development teams. • Conduct comprehensive security risk assessments, including Cybersecurity Risk Assessments (CSRAs), to identify vulnerabilities and threats across device hardware, firmware, software, and cloud components. • Develop and maintain device-specific cyber threat models, factoring in patient safety, data privacy, and operational continuity. • Demonstrate familiarity with Software Bill of Materials (SBOM) and effectively communicate technical details. • Create and maintain cybersecurity documentation for pre- and post-market activities, ensuring regulatory alignment. • Produce detailed data flow diagrams to support the threat modeling process. • Participate in design reviews of medical device architectures and implementations, providing actionable recommendations for system security requirements. • Perform and support vulnerability analysis and coordinate the vulnerability management program, including scanning, patching, and remediation for medical devices. • Leverage and maintain application and threat detection tools (Veracode, Snyk, GitLab, or equivalent) to identify security flaws early in the SDLC. • Support investigation and remediation of device-related security incidents, minimizing impact and preventing recurrence. • Partner with the Privacy Team to ensure adherence to HIPAA, GDPR, and other data protection regulations.

🎯 Requirements

• Bachelor’s degree in Computer Science, Information Security, or related field. • 6+ years of experience in information security, with direct focus on product security for medical devices. • Strong understanding of security principles, methodologies, and tools within the PDLC and SDLC. • Demonstrated experience conducting Cybersecurity Risk Assessments (CSRAs), vulnerability analysis, and working with modern threat detection tools (Veracode, Snyk, GitLab, or similar). • Familiarity with NIST Cybersecurity Framework, NIST SP 800-171, and deeper controls/frameworks such as NIST SP 800-53 (Security and Privacy Controls), NIST SP 800-92 (Log Management), and NIST SP 800-63 (Digital Identity Guidelines). • Hands-on experience with vulnerability identification and threat modeling within healthcare using methodologies such as STRIDE. • Experience operating in a regulated environment (FDA, HIPAA, GDPR, international regulatory frameworks). • Experience with medical device hardware or Software as a Medical Device (SaMD). • Experience with medical device software development and regulatory processes. • Excellent problem-solving, analytical, and communication skills, able to take a multi-siloed approach. • Ability to understand intro dependencies of teams across; mobile applications, hardware and cloud environments. • Demonstrated experience supporting 510(k) submissions, with a focus on product security documentation, risk assessments, and regulatory compliance.

🏖️ Benefits

• Health insurance • 401(k) matching • Flexible work hours • Professional development opportunities

Apply Now

Similar Jobs

🕒 April 24

Emory University

10,000+ employees

📚 Education

🔬 Science

Federated Security Engineer focused on secure application access management and integration at Emory University. Collaborating with Cybersecurity and IAM teams for efficient onboarding and compliance.

🕒 April 24

AGFA HealthCare

1001 - 5000

Information Security Leader defining and executing the cybersecurity vision across all business units at AGFA HealthCare. Providing enterprise-wide security leadership focused on cloud-native and SaaS platforms.

🇺🇸 United States – Remote

⏰ Full Time

🟠 Senior

👮‍♂️ Cybersecurity / Security Engineer

🕒 April 23

Boomi

1001 - 5000

☁️ SaaS

🔌 API

🏢 Enterprise

Senior Advisor overseeing cybersecurity operations and improving security practices at Boomi. Managing security tools, incident responses, and compliance efforts in a cloud environment.

🕒 April 23

Emory University

10,000+ employees

📚 Education

🔬 Science

Federated Security Engineer managing secure application access for Emory University. Collaborating with technical teams on IAM processes and cybersecurity compliance.

🕒 April 23

Wiz

201 - 500

🔒 Cybersecurity

Software Security Engineer developing secure platforms and services for corporate security at Wiz. Collaborating cross-functionally to manage enterprise security practices effectively.