> Markdown version of [/jobs/ext/206429-senior-staff-product-security-engineer](https://www.wearedevelopers.com/jobs/ext/206429-senior-staff-product-security-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Senior Staff Product Security Engineer - **Company:** Draeger Medical Systems, Inc. - **Location:** Andover, MA, United States - **Experience:** Expert - **Salary:** $140,400.0 - $168,500.0 - **Contract:** Permanent contract - **Skills:** CompTIA Security+, Cyber Security, Computer Engineering, Software Vulnerability Management, System Availability, Software Security, Information Technology - **Published:** May 29, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=e8203059e1f161bd ## About the Role Do you have experience in Vuls?, Do you have a Bachelor's degree?, * Bachelor of Science in Computer Science, Cybersecurity, Computer Engineering, or related discipline. Master preferred. * 10 or more years of experience in cybersecurity engineering within regulated medical device or similar industries. * Demonstrated enterprise level influence in cybersecurity strategy and regulatory alignment. * Cybersecurity Certifications: CISSP ISSMP Information Systems Security Management Professional, Offensive Security Certified Professional OSCP, GIAC Enterprise Defender GCED, Equivalent advanced enterprise level cybersecurity certifications will be considered. * Ability to define enterprise product cybersecurity strategy aligned with evolving global regulatory expectations. * Experience adjudicating complex cybersecurity risk decisions balancing patient safety and system availability. * Representation of the organization in regulatory discussions and industry cybersecurity forums. * Required Tools: + Enterprise vulnerability management platforms + Security architecture modeling tools + Metrics and governance reporting platforms ## Description We are hiring a Senior Staff Product Security Engineer to work hybrid in our Andover, MA office. The Senior Staff Product Security Engineer defines and drives product cybersecurity strategy across business units. The role establishes enterprise cybersecurity architecture standards, leads complex risk adjudication decisions, and ensures alignment with global regulatory expectations. Main Responsibilities: * Define long term product cybersecurity strategy and enterprise security architecture direction. * Establish global cybersecurity design standards and governance frameworks across product portfolios. * Lead enterprise level vulnerability management strategy and risk prioritization decisions. * Represent the organization in regulatory engagements and industry cybersecurity initiatives. * Drive alignment with evolving global cybersecurity regulations and standards. * Define cybersecurity metrics and continuous improvement initiatives. * Develop senior engineering capability and provide technical mentorship. * Performs other duties as needed and assigned. ## Related Videos - [Software Security 101: Secure Coding Basics](https://www.wearedevelopers.com/videos/220-software-security-101-secure-coding-basics) - [Reporting Active Exploits in 24 Hours: Are You Ready for the CRA?](https://www.wearedevelopers.com/videos/100248-reporting-active-exploits-in-24-hours-are-you-ready-for-the-cra) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [Cyber Security: Small, and Large!](https://www.wearedevelopers.com/videos/259-cyber-security-small-and-large) - [What makes Cybersecurity different for critical infrastructure?](https://www.wearedevelopers.com/videos/571-what-makes-cybersecurity-different-for-critical-infrastructure) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Dev Digest 191: Malware interviews, EU ❤️ Open Source and Skilled Agents](https://www.wearedevelopers.com/magazine/645-dev-digest-191-malware-interviews-eu-open-source-and-skilled-agents) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [Top-Paying Tech Jobs (with Salaries)](https://www.wearedevelopers.com/magazine/372-top-paying-tech-jobs-with-salaries) - [The 12 Best Jobs for Software Engineers](https://www.wearedevelopers.com/magazine/401-the-12-best-jobs-for-software-engineers)