
Principal Cybersecurity Assurance Engineer
Posted Aug 21

Posted Aug 21
This is a fully remote position, open to applicants in Texas.
• Oversee cybersecurity assurance initiatives throughout the entire product life cycle.
• Develop cybersecurity risk management strategies and documentation.
• Conduct threat modeling and vulnerability evaluations.
• Establish security architecture and implement security controls.
• Generate and oversee software bills of materials (SBOMs).
• Handle vulnerabilities and cybersecurity risks effectively.
• Organize and supervise security testing efforts, including penetration testing.
• Ensure alignment between security controls, security requirements, and security testing activities.
• Maintain compliance with regulatory mandates and industry benchmarks.
• Report significant issues impacting patient safety, cybersecurity, customer experience, or adherence to processes.
• Serve as a cybersecurity advocate within product development teams.
• Evaluate system designs for vulnerabilities and assess cyber risk profiles.
• Collaborate with hardware and software engineers, Design Assurance, Quality, and Regulatory teams.
• Assist in meeting cybersecurity regulations and prepare for ATO readiness.
• Work alongside security teams to monitor and respond to cyber threats.
• Facilitate process enhancements, external audits and submissions, CAPA, supplier audits, and quality-related cybersecurity operations.
• Guide, mentor, and coach cybersecurity assurance engineers.
• A Bachelor’s degree or higher (must be completed and verified before starting).
• A minimum of eight (8) years in cybersecurity and/or cybersecurity risk management experience related to medical devices.
• Experience with embedded systems, Internet of Things (IoT) devices, Bluetooth, Wi-Fi, and/or cellular technologies.
• Familiarity with premarket and postmarket medical device regulations and standards, including FDA requirements, EU regulations, IEC 81001-5-1, ISO 13485, ISO 14971, IEC 62304, or similar standards.
• Proven track record in leading and documenting threat modeling and vulnerability assessments for embedded systems, connected devices, and/or IoT ecosystems.
• Experience utilizing threat modeling and vulnerability assessment frameworks such as STRIDE and CVSS.
• Background in conducting penetration testing, malformed input testing (fuzz testing), SAST, and/or DAST for embedded systems.
• Experience with software composition analysis (SCA), software bill of materials (SBOM) generation, SBOM monitoring, and related software security practices.
• Proficiency in C programming language concepts and/or cryptographic principles.
• Strong communication skills for conveying cybersecurity risks, technical findings, and recommendations both orally and in writing, including presentations.
• Ability to manage multiple projects, priorities, and deliverables across various functional teams.
• Experience collaborating with internal stakeholders and external business partners.
• Must possess legal authorization to work in the country of employment without sponsorship for a work visa.
• Medical, Dental & Vision coverage.
• Health Savings Accounts.
• Health Care & Dependent Care Flexible Spending Accounts.
• Disability Benefits.
• Life Insurance.
• Optional Voluntary Benefits.
• Paid Time Off.
• Retirement Benefits.
• Variable incentive pay, if eligible.
• Relocation Assistance may be provided.
Pair Team
Veta Virtual
Chinook Systems Inc.
Rithum
Get handpicked remote jobs straight to your inbox weekly.