> Markdown version of [/jobs/ext/1815617-security-engineer-med-device](https://www.wearedevelopers.com/jobs/ext/1815617-security-engineer-med-device). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Security Engineer (Med Device) - **Company:** Insight Global - **Location:** Warsaw, IN, United States - **Experience:** Expert - **Salary:** $112,320.0 - $141,440.0 - **Contract:** Permanent contract - **Skills:** Software System Penetration Testing, Cloud Computing Security, Cyber Security, Information Systems Security Architecture Professional, Systems Development Life Cycle, Secure Coding, Software Engineering, Software Vulnerability Management, Software Security, IoT Security, Vulnerability Analysis - **Published:** July 20, 2026 - **Apply:** https://jobs.insightglobal.com/jobs/find_a_job/indiana/warsaw/security-engineer-med-device-/job-549333/ ## About the Role * 5+ years of experience in Product Security, Application Security, Medical Device Security, or Cybersecurity Engineering * Experience working within recognized security frameworks and secure development practices * Experience authoring and reviewing cybersecurity requirements * Strong understanding of secure coding principles and common software vulnerabilities * Experience conducting Threat Modeling using STRIDE methodology * Experience performing Secure Architecture Reviews * Experience with Software Vulnerability Management processes - 3rd party management * Experience conducting Threat Assessments and Vulnerability Assessments * Experience utilizing CVSS scoring methodologies * Experience reviewing SBOMs (Software Bill of Materials) * Experience evaluating CVEs and CWEs * Strong understanding of SDLC and software engineering practices * Cloud security and configuration experience * Familiarity with FDA Cybersecurity Guidance * Experience with IEC 62304 and ISO 14971 Nice to Have Skills & Experience * ISO 27001 experience * HIPAA experience * GDPR/privacy experience * SaMD experience * FDA submission support * Cybersecurity risk management files * Penetration testing knowledge * Connected device/IoT security * CISSP, CSSLP, Security+ or similar certifications ## Description We are seeking a Product Security Engineer to own and lead the cybersecurity governance process for Software as a Medical Device (SaMD) products within a strategic Design History File (DHF) workspace. This individual will be responsible for maintaining and improving cybersecurity documentation, vulnerability management processes, risk management activities, and compliance artifacts required under evolving FDA cybersecurity regulations. The role is highly strategic and process-oriented, serving as the security lead embedded within one or two high-visibility SaMD teams. Responsibilities include defining security requirements, reviewing threat analyses, assessing the effectiveness of security controls, overseeing cybersecurity testing outputs, and ensuring documentation remains current as product designs evolve. The ideal candidate will drive continuous improvement of cybersecurity and risk management processes, maintain ownership of all required regulatory documentation, and partner closely with cross-functional engineering and quality teams to ensure ongoing compliance and product security. This is a leadership role without direct people management responsibilities and is focused on governance, oversight, and strategic decision-making rather than hands-on technical implementation. ## Related Videos - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [How to Cause (or Prevent) a Massive Data Breach- Secure Coding and IDOR](https://www.wearedevelopers.com/videos/39-how-to-cause-or-prevent-a-massive-data-breach-secure-coding-and-idor) - [WeAreDevelopers LIVE - Modern DevOps for IoT Devices and More](https://www.wearedevelopers.com/videos/1805-wearedevelopers-live-modern-devops-for-iot-devices-and-more) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Cyber Security: Small, and Large!](https://www.wearedevelopers.com/videos/259-cyber-security-small-and-large) - [What makes Cybersecurity different for critical infrastructure?](https://www.wearedevelopers.com/videos/571-what-makes-cybersecurity-different-for-critical-infrastructure) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [The 12 Best Jobs for Software Engineers](https://www.wearedevelopers.com/magazine/401-the-12-best-jobs-for-software-engineers) - [Top-Paying Tech Jobs (with Salaries)](https://www.wearedevelopers.com/magazine/372-top-paying-tech-jobs-with-salaries) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Fully Remote Software Engineer Jobs](https://www.wearedevelopers.com/magazine/447-fully-remote-software-engineer-jobs)