Назад
Company hidden
обновлено 4 дня назад

Senior Product Security Manager

151 000 - 196 000$
Формат работы
remote (только USA)
Тип работы
fulltime
Грейд
senior
Английский
b2
Страна
US
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Senior Product Security Manager (Medical Devices): Safeguarding software-driven medical devices and IoMT platforms by embedding cybersecurity across the product development and secure software development lifecycles with an accent on FDA compliance, threat modeling, and vulnerability management. Focus on reviewing secure architectures, managing SBOM and software supply chain risks, and driving PSIRT, incident response, and post-market security activities.

Location: Remote - US

Salary: $151,000–$196,000 per year

Company

hirify.global is a digital healthcare company creating wearable biosensors, cloud-based analytics, and proprietary algorithms for cardiac monitoring and clinically actionable health insights.

What you will do

  • Provide senior cybersecurity leadership across product development and influence secure design decisions.
  • Drive adoption and continuous improvement of the Secure Product Development Framework and secure SDLC practices.
  • Lead threat modeling, cybersecurity risk assessments, security design reviews, and maintenance of data flow diagrams.
  • Review secure architectures across embedded systems, applications, cloud, and IoMT platforms.
  • Oversee vulnerability management, coordinated disclosure, incident response support, and post-market monitoring.
  • Manage SBOM, third-party risk, and software supply chain security while partnering with Product, R&D, Quality, Regulatory, Privacy, and Cloud teams.

Requirements

  • Bachelor’s degree in Computer Science, Information Security, or a related field.
  • 12+ years of experience in product security or related cybersecurity roles.
  • Deep expertise securing complex, software-driven, safety-critical systems.
  • Strong knowledge of secure design, threat modeling, vulnerability management, and SDLC practices.
  • Experience with medical devices, healthcare technology, or IoMT systems and regulated environments involving FDA, HIPAA, and GDPR.
  • Familiarity with NIST, ISO 14971, IEC 62304, and related standards, plus the ability to influence cross-functional stakeholders.

Nice to have

  • Certifications such as CISSP, CISM, or CRISC.
  • Experience with SAST, DAST, SCA, CI/CD security tooling, and shift-left practices.
  • Familiarity with EU MDR, GDPR, and ISO/IEC 81001-5-1.
  • Experience supporting SBOM programs, PSIRT operations, and penetration testing.

Culture & Benefits

  • Patient-first focus on improving cardiac health outcomes.
  • Inclusive workforce welcoming diverse backgrounds, experiences, skills, and perspectives.
  • Reasonable accommodations are available for qualified individuals with disabilities during the application process.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →