> Markdown version of [/jobs/ext/1958707-lead-cyber-security-architect](https://www.wearedevelopers.com/jobs/ext/1958707-lead-cyber-security-architect). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Lead Cyber Security Architect - **Company:** Bio-Rad Laboratories, Inc. - **Location:** Hercules, CA, United States - **Experience:** Expert - **Salary:** $179,400.0 - $246,600.0 - **Contract:** Permanent contract - **Skills:** Cloud Computing, Cyber Security, Information Security Management, Software Vulnerability Management, Software Security, Information Technology, IoT Security - **Published:** August 6, 2026 - **Apply:** https://jobs.localjobnetwork.com/apply/add/87344633/1 ## About the Role * Bachelor's degree in Computer Science, Information Security, Engineering or a related field. * 7+ years of experience in cybersecurity, including architecture design in a regulated environment (preferably FDA, healthcare, or medical devices). * A system thinker with deep expertise in medical device cybersecurity, including FDA premarket and post market cybersecurity requirements. * Expert knowledge of NIST CSF 2.0, ISO 8100151, ISO/IEC TS 27110, and ISO/IEC 27032. * Proven ability to lead crossfunctional programs in complex, matrixed organizations. * Strong technical judgment, communication skills, and executive presence. * Demonstrated ability to build, mature, and scale cybersecurity programs across organizations. * Preferred: Master's degree in a technical field. * Certifications: CISSP, CSSLP, CISM, or equivalent. * Experience with cloud-based systems, IoT security, or medical device security. ## Description The Technical Leader for the Product Cybersecurity Program and Product Security Incident Response Team (PSIRT) provides leadership for medical device cybersecurity across BioRad's Clinical Diagnostics portfolio. This role owns the strategy, governance, and execution of the product cybersecurity program, ensuring compliance with FDA cybersecurity requirements and global standards while driving program maturity across the organization and product lifecycle. This position serves as the authoritative technical leader for product cybersecurity, accountable for vulnerability management, incident response, regulatory alignment, and crossfunctional coordination. The role operates at the program level, enabling and guiding product teams rather than replacing their functional ownership. How You'll Make An Impact: Program Leadership & Governance * Own and evolve the Product Cybersecurity Program, including PSIRT governance, operating model, decision authority, and escalation paths. * Establish and maintain alignment with FDA medical device cybersecurity expectations, including premarket and post-market requirements for vulnerability management, coordinated disclosure, and incident response. * Define and maintain the cybersecurity framework aligned to NIST CSF 2.0, ISO 8100151, ISO/IEC TS 27110, and ISO/IEC 27032, and ensure integration with Global IT security practices. * Embed product cybersecurity requirements into the Global Quality Management System (QMS), including Design Controls, risk management, and change management. CrossFunctional Enablement * Lead the crossfunctional Cybersecurity Core Team, ensuring sustained engagement and prioritization across R&D, Software, Systems, QA/RA, Global Supply Chain (Manufacturing and Procurement), and Global Information Security. * Provide clear expectations, guidance, and oversight to product teams for secure design, development, and maintenance, without assuming direct development ownership. * Ensure cybersecurity considerations are integrated throughout the product lifecycle, from concept and design through postmarket support. Vulnerability & Incident Management (PSIRT) * Serve as the single point of accountability for product cybersecurity intake, triage, and prioritization. * Oversee endtoend vulnerability management, including risk assessment, remediation planning, regulatory timelines, and customer deployment. * Lead technical coordination for cybersecurity incident investigations, containment, and remediation, ensuring timely and effective response to highseverity issues. * Guide product teams on mitigations, patches, and workarounds to ensure security and regulatory expectations are met. Regulatory & External Communication * Ensure cybersecurity incidents and disclosures comply with FDA, international regulatory, and internal quality requirements. * Oversee the development and approval of security advisories, customer notifications, and regulatory communications. * Act as the technical authority in engagements with external security researchers, customers, regulators, and industry groups. Training, Metrics & Continuous Improvement * Drive cybersecurity awareness and training for R&D, Support, and Quality teams to reinforce a securityfirst culture. * Define, track, and report programlevel cybersecurity and PSIRT performance metrics to leadership. * Continuously improve program effectiveness based on metrics, lessons learned, and evolving regulatory expectations. ## Related Videos - [What makes Cybersecurity different for critical infrastructure?](https://www.wearedevelopers.com/videos/571-what-makes-cybersecurity-different-for-critical-infrastructure) - [Green Cloud Computing](https://www.wearedevelopers.com/videos/592-green-cloud-computing) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [WeAreDevelopers LIVE - Modern DevOps for IoT Devices and More](https://www.wearedevelopers.com/videos/1805-wearedevelopers-live-modern-devops-for-iot-devices-and-more) - [Cyber Security: Small, and Large!](https://www.wearedevelopers.com/videos/259-cyber-security-small-and-large) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) ## Related Articles - [How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again](https://www.wearedevelopers.com/magazine/751-how-we-built-a-worry-free-system-that-runs-for-10-years-and-what-we-d-do-again) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [Résumé-Driven Development: How IT trends affect the job market for software developers](https://www.wearedevelopers.com/magazine/59-resume-driven-development-how-it-trends-affect-the-job-market-for-software-developers)