
Senior Product Security Engineer – Pharma
Posted 5 days ago

Posted 5 days ago
This is a fully remote position, open to applicants in Spain, +1 more country.
• Establish technical security and privacy requirements for products, medical devices, and healthcare solutions.
• Perform Threat Modeling and Cybersecurity Risk Assessments.
• Evaluate product security posture and outline risk mitigation strategies.
• Design and uphold security and privacy controls throughout the product lifecycle.
• Oversee and evaluate vulnerabilities during both pre-market and post-market phases.
• Analyze vulnerabilities identified through SCA, SAST, DAST, IaC, Penetration Testing, and other security assessments.
• Offer technical insights for remediation plans and track remediation progress.
• Examine complex security challenges and provide technical guidance.
• Assist with Security Incident Response and forensic investigations.
• Technically coordinate external security evaluations, including penetration testing, validation of results, and follow-up on remediation efforts.
• Create and maintain technical documentation, processes, playbooks, and Product Security tools.
• Keep abreast of emerging security threats, technologies, and best practices.
• Serve as a technical reference for Product Security by sharing expertise and aiding less experienced security professionals.
• Collaborate with Software Development, Cloud, Product Security, and Incident Response teams.
• Bachelor’s degree in Engineering, Computer Science, or a related discipline.
• Over 7 years of experience in Security Engineering, Product Security, Application Security, Vulnerability Management, or similar fields.
• Practical experience collaborating with software development teams and Cloud platforms.
• Strong background in Threat Modeling and Cybersecurity Risk Assessment.
• Extensive experience in vulnerability analysis and remediation techniques.
• Hands-on experience with SCA, SAST, DAST, IaC, and/or Penetration Testing.
• Solid understanding of Application Security and security considerations throughout the Software Development Lifecycle.
• Experience in the Healthcare, Medical Devices, or other regulated sectors.
• Profound knowledge of standards and regulations such as ISO 27000, FDA Guidance, MDGC, HITRUST, and GDPR.
• Strong analytical and problem-solving capabilities, with a talent for evaluating intricate technical security issues.
• Excellent communication skills and the ability to collaborate with international technical teams.
• Fluent in English, both written and spoken.
• Willingness to travel up to 20%.
• Permanent contract.
• Opportunities for Learning & Development.
• Friend Referral Program.
• Flexible work schedule.
• 100% remote work from Spain or Portugal.
Reli Group
Second Nature
ASRC Federal
Kyndryl
Get handpicked remote jobs straight to your inbox weekly.