Senior Product Cybersecurity Specialist

Propertyvalue Global Dosimetry Solutions
United States
8 days ago
Apply on www.dice.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
4 years minimum
Working hours
Regular working hours
Job source

Tech stack

Amazon Web Services Software Applications Software System Penetration Testing Microsoft Azure Cyber Security Secure Coding Software Engineering Software Vulnerability Management Software Security Information Technology Static Application Security Testing Dynamic Application Security Testing

Job description

Mirion is seeking a motivated and enthusiastic Senior Product Cybersecurity Specialist to support Mirion’s medical and technologies product lines. The specialist will play a crucial role providing cybersecurity advisory services and HIPPA guidance to product owners, sales teams, and developers in the form of providing security guidance, reviews, and compliance information. Additionally, this role will build out processes and technical capabilities as assigned to support the Product Cybersecurity mission., * Support cybersecurity risk assessments for connected medical devices and software per US HHS and FDA guidance.

  • Provide cybersecurity recommendations and guidance to product development teams on secure design, coding, and development.
  • Assist with gathering evidence and providing information for external audits and customer security inquiries for HIPPA and ePHI related security controls and for frameworks such as ISO 27001 and SOC 2.
  • Document and write product risk assessment and security control reports.
  • Review and aid with writing cybersecurity related information for product documentation.
  • Participate in product project meetings as the cybersecurity representative.
  • Collaborate with cross-functional teams to ensure cybersecurity best practices are integrated into product development and support.
  • Stay informed about the latest cybersecurity threats, vulnerabilities, and industry’s best practices.

Potential Additional Responsibilities

  • Participate in routine code vulnerability scans and triage activities.
  • Assist in implementation and creating procedures around the use of developer code security technologies including SAST, SCA, and DAST tools.
  • Coordinating penetration testing and other application security testing.

  • Other general tasks as assigned.

Requirements

  • Bachelor’s degree in information technology, information security, or related field or equivalent practical experience.
  • Experience: 4+ years in a cybersecurity-focused role, with exposure to cybersecurity governance, risk, and compliance.
  • Working knowledge of the HIPAA Security Rule (45 CFP Part 160/164) and Privacy/Breach Notification Rules.
  • Familiarity with FDA’s “Cybersecurity in Medical Devices” premarket/postmarket guidance.
  • Familiarity with cybersecurity frameworks such as ISO 27001, IEC 62443, NIST 800-171, SOC 2, and Cyber Essentials.
  • Experience with HIPPA regulations and the HITRUST security framework.
  • Experience with software application architecture and secure software development practices.
  • Experience with embedded systems and associated security considerations.
  • Good understanding of cybersecurity concepts and best practices to secure hardware and software components.
  • Strong communication skills and a collaborative working style.
  • Desire to work and learn., * Familiarity with international cyber industry regulations such as EU GDPR, and EU Cyber Resilience Act.
  • Understanding of SBOM concepts and code/application vulnerability management tools.
  • Experience with secure coding practices.
  • Experience with Azure and AWS cloud security.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.dice.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

4:01 min

Finding personal fulfillment in the cybersecurity industry

LIVE

1:06 min

Outline of free tools for Microsoft Azure

Radu Vunvulea Radu Vunvulea · World Congress 2022

4:11 min

Introduction to cloud-native application developer security

Micah Silverman · World Congress 2022

2:59 min

Applying secure coding practices and proactive system monitoring

Mihaela-Roxana Ghidersa · LIVE

10:35 min

Teaching and coaching security concepts for lasting impact

Tanya Janca · World Congress 2021

1:45 min

Transitioning from software development to security roles

Stefania Chaplin · World Congress 2022

Videos

See all

Related articles

See all