Назад
Company hidden
19 дней назад

Product Security Manager (Medtech)

10 583 - 13 750$
Формат работы
remote (только USA)
Тип работы
fulltime
Грейд
senior
Английский
b2
Страна
US
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/

TL;DR

Product Security Manager (Medtech): Safeguarding medical devices by identifying and mitigating security risks unique to healthcare technology with an accent on FDA cybersecurity compliance and secure software development lifecycles. Focus on conducting Cybersecurity Risk Assessments (CSRAs), developing threat models, and ensuring regulatory alignment across device hardware and cloud components.

Location: Remote (US)

Salary: $127,000 - $165,000

Company

A leading digital healthcare company creating wearable biosensors and cloud-based analytics to detect and prevent cardiac disease.

What you will do

  • Ensure compliance with FDA cybersecurity guidance and regulations in collaboration with cross-functional teams.
  • Conduct comprehensive Cybersecurity Risk Assessments (CSRAs) for device hardware, firmware, software, and cloud components.
  • Develop and maintain device-specific cyber threat models focusing on patient safety and data privacy.
  • Manage Software Bill of Materials (SBOM) and create critical security documentation for regulatory alignment.
  • Perform vulnerability analysis and coordinate the management program using tools like Veracode, Snyk, and GitLab.
  • Partner with the Privacy Team to maintain adherence to HIPAA, GDPR, and other data protection regulations.

Requirements

  • Bachelor’s degree in Computer Science, Information Security, or a related field.
  • 8+ years of experience in information security, with a direct focus on product security for medical devices.
  • Must be based in the US.
  • Experience conducting CSRAs, vulnerability analysis, and threat modeling using methodologies like STRIDE.
  • Proficiency with NIST frameworks (SP 800-53, 800-171, etc.) and operating within FDA, HIPAA, and GDPR regulated environments.
  • Proven track record of 510k experience and completion.

Nice to have

  • Industry certifications such as CISSP, CISM, or CISA.
  • Experience with international standards including EU MDR, JIS T 2304, or IEC 62304.
  • Understanding of penetration testing methodologies and tools.
  • Proficiency with programming languages used in medical device development.

Culture & Benefits

  • Opportunity to impact global cardiac health through innovative medical technology.
  • Collaborative environment driven by a commitment to putting patients first.
  • Inclusive workforce celebrating diversity of backgrounds and perspectives.
  • Remote work flexibility for US-based employees.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →