Senior Product Security Manager
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
TL;DR
Senior Product Security Manager (Product Security): Safeguarding medical devices by identifying, assessing, and mitigating security risks across the product development lifecycle with an accent on secure design decisions, threat modeling, and regulatory-aligned secure SDLC. Focus on maturing risk management, leading vulnerability and PSIRT operations, and strengthening software supply chain security (SBOM) for safety-critical healthcare technology.
Location: Remote (US)
Salary: $173,000.00 - $225,000.00
Company
is a digital healthcare company delivering trusted solutions for cardiac health using wearable biosensors and cloud-based analytics.
What you will do
- Provide senior cybersecurity leadership for product development, driving secure design decisions at scale.
- Embed security across PDLC and SDLC, improving adoption of the Secure Product Development Framework (SPDF).
- Ensure compliance with FDA cybersecurity guidance (including Section 524B) and global privacy regulations (HIPAA, GDPR), maintaining required cybersecurity documentation.
- Lead threat modeling and cybersecurity risk management (CSRAs, security design reviews), including data flow diagrams and models focused on patient safety and integrity.
- Oversee vulnerability management, coordinated disclosure (PSIRT), and support incident response and post-market monitoring with root-cause analysis.
- Manage SBOM, third-party risk, and software supply chain security; partner with Product, R&D, Quality, Regulatory, Privacy, and Cloud teams to align stakeholders.
Requirements
- 12+ years of experience in product security or related cybersecurity roles.
- Deep expertise securing complex, software-driven and safety-critical systems.
- Strong knowledge of secure design, threat modeling, vulnerability management, and SDLC practices.
- Experience operating in regulated environments (FDA, HIPAA, GDPR).
- Familiarity with NIST and standards such as ISO 14971 and IEC 62304.
- Experience with medical devices, healthcare technology, or IoMT systems.
Nice to have
- CISSP, CISM, or CRISC certifications.
- Experience with CI/CD security tooling (SAST, DAST, SCA) and shift-left practices.
- Familiarity with EU MDR and ISO/IEC 81001-5-1.
- Experience supporting SBOM programs and PSIRT operations.
- Understanding of penetration testing methodologies.
Culture & Benefits
- Remote work aligned to the US location requirement.
- Inclusive workplace with equal opportunity employment.
- Reasonable accommodations available for qualified applicants with disabilities.
Hiring process
- Interviews and hiring communications come from an @tech.com email address.
- Written offers are extended via a formal offer letter from an @tech.com email address.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →