Назад
Company hidden
1 день назад

Product Security Specialist for Medical Devices (Cyber Security)

Формат работы
hybrid
Тип работы
fulltime
Грейд
senior
Английский
b2
Страна
UK/US/Ireland +1 еще
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Product Security Specialist for Medical Devices (Cyber Security) (Medical Device Cybersecurity): Assessing and improving the security of medical devices and IoT products through risk assessments, threat modeling, secure code reviews, and security testing with an accent on regulatory compliance and client delivery. Focus on evaluating residual risk, validating security controls, monitoring emerging medical-device threats, and leading complex stakeholder and consulting engagements.

Location: London, United Kingdom; hybrid working requires attendance at the office or client site for a minimum of 2 days per week, with assignments potentially requiring up to 5 days per week on a client site. Some UK roles may require security clearance; applicants may need to be British citizens or have at least 5 years of continuous UK residency.

Company

hirify.global is a consulting firm combining strategy, design, technology, science, engineering, and innovation expertise across sectors including health and life sciences, defence, finance, government, and transport.

What you will do

  • Define objectives, scope, timelines, and delivery methods for product security initiatives with client product and functional teams.
  • Assess security risks across medical device and IoT product portfolios and recommend remediation strategies.
  • Lead secure code reviews, threat modeling, security risk assessments, vulnerability assessments, and validation of security controls.
  • Advise on secure coding, threat modeling, security testing, embedded systems, IoT devices, and industry regulatory compliance.
  • Monitor emerging cybersecurity threats affecting IoT and medical devices and produce thought leadership.
  • Build stakeholder relationships, support business development, manage projects, and contribute to team growth and training.

Requirements

  • At least 5 years of relevant experience in the medical device industry or medical device consulting.
  • Proficiency with NIST, OWASP, MITRE ATT&CK, PASTA, STRIDE, and standards such as FDA cybersecurity guidance.
  • Experience assessing security risks using penetration test results, threat modeling, and security testing, including residual risk analysis after compensating controls.
  • Experience implementing or demonstrating compliance with NIST, IEC, HITRUST, HIPAA, GDPR, ISO 27001, and SOC 2 Type 2, plus familiarity with Quality Management Systems.
  • Experience working within a structured software development lifecycle and communicating complex security topics to technical and non-technical audiences.
  • Cybersecurity qualifications such as CISSP, CSSLP, or CISM, together with strong analytical, interpersonal, relationship-building, proposal-writing, and business development skills.

Culture & Benefits

  • Collaborative, inclusive, trust-based environment with interdisciplinary teams and peer-level coaching and mentoring.
  • Technical and non-technical learning budget, including access to professional certifications.
  • Private healthcare for employees and families, a generous pension scheme, and an annual performance-based bonus.
  • 25 days of annual leave plus a bonus half day on Christmas Eve, with the option to buy 5 additional days.
  • PA share ownership, tax-efficient benefits, and opportunities to participate in community and charity initiatives.

Hiring process

  • Initial call with a technology recruiter.
  • Two 60-minute competency and technical interviews, one of each.
  • Final 60-minute meeting with a PA leader, including a mini case study and client-centricity discussion.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →