Product Security Specialist for Medical Devices (Cyber Security)
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
Location: London, United Kingdom; hybrid working requires attendance at the office or client site for a minimum of 2 days per week, with assignments potentially requiring up to 5 days per week on a client site. Some UK roles may require security clearance; applicants may need to be British citizens or have at least 5 years of continuous UK residency.
Company
is a consulting firm combining strategy, design, technology, science, engineering, and innovation expertise across sectors including health and life sciences, defence, finance, government, and transport.
What you will do
- Define objectives, scope, timelines, and delivery methods for product security initiatives with client product and functional teams.
- Assess security risks across medical device and IoT product portfolios and recommend remediation strategies.
- Lead secure code reviews, threat modeling, security risk assessments, vulnerability assessments, and validation of security controls.
- Advise on secure coding, threat modeling, security testing, embedded systems, IoT devices, and industry regulatory compliance.
- Monitor emerging cybersecurity threats affecting IoT and medical devices and produce thought leadership.
- Build stakeholder relationships, support business development, manage projects, and contribute to team growth and training.
Requirements
- At least 5 years of relevant experience in the medical device industry or medical device consulting.
- Proficiency with NIST, OWASP, MITRE ATT&CK, PASTA, STRIDE, and standards such as FDA cybersecurity guidance.
- Experience assessing security risks using penetration test results, threat modeling, and security testing, including residual risk analysis after compensating controls.
- Experience implementing or demonstrating compliance with NIST, IEC, HITRUST, HIPAA, GDPR, ISO 27001, and SOC 2 Type 2, plus familiarity with Quality Management Systems.
- Experience working within a structured software development lifecycle and communicating complex security topics to technical and non-technical audiences.
- Cybersecurity qualifications such as CISSP, CSSLP, or CISM, together with strong analytical, interpersonal, relationship-building, proposal-writing, and business development skills.
Culture & Benefits
- Collaborative, inclusive, trust-based environment with interdisciplinary teams and peer-level coaching and mentoring.
- Technical and non-technical learning budget, including access to professional certifications.
- Private healthcare for employees and families, a generous pension scheme, and an annual performance-based bonus.
- 25 days of annual leave plus a bonus half day on Christmas Eve, with the option to buy 5 additional days.
- PA share ownership, tax-efficient benefits, and opportunities to participate in community and charity initiatives.
Hiring process
- Initial call with a technology recruiter.
- Two 60-minute competency and technical interviews, one of each.
- Final 60-minute meeting with a PA leader, including a mini case study and client-centricity discussion.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →