
Product Security Manager
Posted Jul 18

Posted Jul 18
This is a fully remote position, open to applicants in United States.
• Ensure adherence to FDA cybersecurity guidelines and regulations through collaboration with the Cybersecurity, Regulatory, Quality, and Systems Development teams.
• Execute thorough security risk assessments, including Cybersecurity Risk Assessments (CSRAs), to pinpoint vulnerabilities and threats within device hardware, firmware, software, and cloud components.
• Create and uphold device-specific cyber threat models, considering patient safety, data privacy, and operational continuity.
• Exhibit knowledge of Software Bill of Materials (SBOM) and effectively convey technical information.
• Generate and manage cybersecurity documentation for both pre- and post-market activities, ensuring alignment with regulatory standards.
• Develop comprehensive data flow diagrams to aid the threat modeling process.
• Engage in design reviews of medical device architectures and implementations, offering actionable suggestions for system security requirements.
• Conduct and support vulnerability analysis, coordinating the vulnerability management program, which includes scanning, patching, and remediation for medical devices.
• Utilize and sustain application and threat detection tools (Veracode, Snyk, GitLab, or similar) to uncover security flaws early in the Software Development Life Cycle (SDLC).
• Assist in the investigation and resolution of device-related security incidents, mitigating impacts and preventing future occurrences.
• Collaborate with the Privacy Team to ensure compliance with HIPAA, GDPR, and other data protection regulations.
• Bachelor's degree in Computer Science, Information Security, or a related discipline.
• Over 8 years of experience in information security, specifically focused on product security for medical devices.
• Strong grasp of security principles, methodologies, and tools within the Product Development Life Cycle (PDLC) and Software Development Life Cycle (SDLC).
• Proven experience in conducting Cybersecurity Risk Assessments (CSRAs), vulnerability analysis, and utilizing modern threat detection tools (Veracode, Snyk, GitLab, or similar).
• Knowledge of the NIST Cybersecurity Framework, NIST SP 800-171, and deeper controls/frameworks like NIST SP 800-53 (Security and Privacy Controls), NIST SP 800-92 (Log Management), and NIST SP 800-63 (Digital Identity Guidelines).
• Practical experience in vulnerability identification and threat modeling within the healthcare sector using methodologies such as STRIDE.
• Experience working within a regulated environment (FDA, HIPAA, GDPR, and international regulatory frameworks).
• Familiarity with medical device hardware or Software as a Medical Device (SaMD).
• Experience in medical device software development and understanding regulatory processes.
• Outstanding problem-solving, analytical, and communication abilities, capable of taking a multi-siloed approach.
• Ability to comprehend interdependencies among teams across mobile applications, hardware, and cloud environments.
• Demonstrated history of 510k experience and successful completion.
• Reasonable accommodations for qualified individuals with disabilities during the job application process.
Lime
Threatscape
GFT Technologies
BeyondTrust
Get handpicked remote jobs straight to your inbox weekly.