Product Security Cloud Engineer
Role details
Job location
Tech stack
Job description
Our client is hiring a Senior Product Security Cloud Engineer to support critical product security initiatives. The role is highly documentation-focused and centered on bringing an existing Azure-based system into full compliance with pre-market FDA standards. The ideal candidate is a hands-on cloud security professional who can independently assess current-state architecture, produce high-quality security documentation, and translate complex technical controls into clear narratives that can be understood by both technical and non-technical stakeholders in a regulated environment.
This is an opportunity to work with a global, mission-driven organization whose technology directly impacts and saves lives. The client is known for exceptionally high engineering standards, strong investment in security and compliance, and a culture that values thoughtful, well-documented work. You'll be contributing to meaningful products in a mature, well-resourced environment while collaborating with a small, highly skilled product security team that values autonomy, clarity, and quality over bureaucracy.
Day-to-Day Responsibilities:
- Develop formal threat models and security analyses to support FDA pre-market documentation
- Execute vulnerability scanning and risk-based security assessments, translating results into clear narratives for technical and non-technical stakeholders
- Generate architecture reviews, threat models, and security risk assessments
- Translate technical security implementations into clear, written narratives
- Compare current-state systems to full compliance requirements and document gaps
- Create FMEAs and risk assessments in Excel
- Produce and modify architecture diagrams highlighting security controls and trust boundaries
- Document data integrity controls ensuring data originates from known sources and is not tampered with
- Define service-to-service interactions across device endpoints and cloud endpoints
- Support IoT-to-cloud security designs within Azure environments
- Contribute to QMS and product security documentation
Requirements
- Must-Haves:
- 5 years of hands-on Azure cloud security experience
- Experience securing IoT-to-cloud architectures
- Strong background working in regulated environments
- Proven experience generating FMEAs and security risk assessments (Excel-based)
- Ability to create and modify architecture diagrams (Visio, Lucid)
- Strong technical writing skills using Microsoft Word
- Knowledge of PKI and cryptographic controls (encryption at rest and in transit)
- Experience with authentication mechanisms, token exchange, and identity controls
- Familiarity with Azure Key Vault, Azure Firewalls, and patching/update strategies
- Nice-to-Haves:
- Medical device or healthcare product security experience
- FDA-regulated product background
- Software as a Medical Device (SaMD) experience