> Markdown version of [/jobs/ext/1830194-product-cybersecurity-architect](https://www.wearedevelopers.com/jobs/ext/1830194-product-cybersecurity-architect). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Product Cybersecurity Architect - **Company:** Bausch & Lomb Incorporated - **Location:** United States (Remote available) - **Experience:** Expert - **Salary:** $140,000.0 - **Contract:** Permanent contract - **Skills:** Software System Penetration Testing, Cyber Security, Information Systems Security Architecture Professional, Software Maintenance, Software Engineering, Software Vulnerability Management, EndPointSecurity, Delivery Pipeline, Software Security, GWAPT, Information Technology, GXP, Static Application Security Testing, Dynamic Application Security Testing - **Published:** July 10, 2026 - **Apply:** https://careers.bauschlomb.com/talentcommunity/apply/1366332957/?locale=en_US ## About the Role * Bachelor's degree in Engineering, Computer Science, Cybersecurity, or a related technical discipline. * 7+ years of experience in product security, application security, medical device cybersecurity, or software security within a regulated environment. * Demonstrated experience supporting or leading cybersecurity activities for medical device or other regulated product development programs. * Strong communication, collaboration, stakeholder management, and problem-solving skills. * Ability to translate technical cybersecurity risks into clear, actionable guidance for engineering, quality, and regulatory stakeholders. Specialized Technical, Regulatory & Industry Skills & Knowledge * Strong expertise in secure product design, threat modeling, vulnerability management, and secure software development practices. * Working knowledge of connected device security, embedded systems, and software-enabled product architectures. * Experience with security testing tools and methodologies, including SAST, DAST, SCA, and penetration testing. * Understanding of software supply chain security practices, including SBOM development and third-party risk management. * Experience working across cross-functional and global teams to drive cybersecurity outcomes and influence stakeholders without direct authority. * Knowledge of secure development lifecycle (SDLC) frameworks, vulnerability disclosure processes, and product incident response activities. * Familiarity with cybersecurity governance, risk assessment, and compliance processes within regulated industries. Preferred * Advanced degree in Cybersecurity, Computer Science, Engineering, or a related field. * Relevant industry certifications such as CISSP, CSSLP, OSCP, GWAPT, or equivalent. * Experience in medical device, healthcare, or other regulated industries, and/or working within a quality-managed or GxP regulated environment. * Working knowledge of medical device cybersecurity regulations and standards (e.g., FDA premarket/post market guidance, IEC 81001-5-1, AAMI TIR57, UL 2900, NIST frameworks). * Experience developing cybersecurity documentation to support regulatory submissions and audits., Applicants must be authorized to work for ANY employer in the U.S. We are unable to sponsor or take over sponsorship of an employment Visa at this time. ## Description * Architect and implement a consistent cybersecurity strategy across surgical capital equipment product lines to establish a scalable and secure product ecosystem. * Embed secure-by-design principles throughout the product lifecycle, providing guidance on secure architecture, threat modeling, design controls, cryptography, and secure communication protocols. * Lead execution of cybersecurity requirements across development programs, ensuring alignment with regulatory expectations, corporate standards, and product quality objectives. * Coordinate vulnerability management activities, including intake, triage, risk assessment, remediation tracking, and documentation of product security issues through closure. * Serve as the Surgical R&D cybersecurity representative for vulnerability disclosure and incident response activities, supporting investigations, impact assessments, root cause analyses, and remediation efforts. * Partner with engineering teams to implement security testing practices, including SAST, DAST, SCA, penetration testing, and automated security controls within development pipelines. * Support supplier and third-party security initiatives by defining security requirements, managing software supply chain risks, and maintaining Software Bill of Materials (SBOM) processes. * Collaborate with Quality, Regulatory Affairs, IT, and Corporate Product Security teams to ensure compliance with evolving cybersecurity regulations and industry standards while enabling efficient product delivery. ## Related Videos - [Blueprints for Success: Steering a Global Data & AI Architecture](https://www.wearedevelopers.com/videos/1577-blueprints-for-success-steering-a-global-data-ai-architecture) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Reporting Active Exploits in 24 Hours: Are You Ready for the CRA?](https://www.wearedevelopers.com/videos/100248-reporting-active-exploits-in-24-hours-are-you-ready-for-the-cra) - [What makes Cybersecurity different for critical infrastructure?](https://www.wearedevelopers.com/videos/571-what-makes-cybersecurity-different-for-critical-infrastructure) - [Cyber Security: Small, and Large!](https://www.wearedevelopers.com/videos/259-cyber-security-small-and-large) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [The 12 Best Jobs for Software Engineers](https://www.wearedevelopers.com/magazine/401-the-12-best-jobs-for-software-engineers) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks)