Principal Cybersecurity Assurance Engineer (Remote - United States)

Solventum Corporation
Maplewood, MN, United States
7 days ago
Apply on www.jofdav.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
8 years minimum
Compensation
$116,480.0 - $128,960.0
Working hours
Regular working hours
Job source

Tech stack

C (Programming Language) Software System Penetration Testing Bluetooth Cyber Security Fuzz Testing Wi-Fi Technology Software Security Static Application Security Testing Vulnerability Analysis Dynamic Application Security Testing

Job description

  • Ensuring compliance with applicable regulatory requirements and industry standards, while immediately elevating to management any major problem that could affect patient safety, cybersecurity, customer usability, or system adherence to process requirements.
  • Acting as a cybersecurity champion within product development teams by analyzing system designs for vulnerabilities, determining cyber risk profiles, estimating security risks, defining security controls, interacting with hardware and software engineers, Design Assurance, Quality, and Regulatory teams to ensure compliance with cybersecurity regulations and ATO readiness, and collaborating with other security teams to monitor and respond to cyber signals.
  • Supporting continuous process improvement, external audits and submissions, the CAPA process, supplier audit processes, and other quality-related processes regarding cybersecurity risk management and software assurance.
  • Supervising, mentoring, guiding, and coaching other cybersecurity assurance engineers.

Requirements

  • Bachelor’s degree or higher (completed and verified prior to start) AND eight (8) years of cybersecurity and/or cybersecurity risk management experience supporting medical devices

In addition to the above requirements, the following are also required:

  • Experience working with embedded systems, Internet of Things (IoT) devices, Bluetooth, Wi-Fi, and/or cellular technologies

Additional qualifications that could help you succeed even further in this role include:

  • Ten (10) years of cybersecurity and/or cybersecurity risk management experience supporting medical devices
  • Experience applying premarket and postmarket medical device regulations and standards, such as FDA requirements, EU regulations, IEC 81001-5-1, ISO 13485, ISO 14971, IEC 62304, or similar standards.
  • Experience leading and documenting threat modeling and vulnerability assessments for embedded systems, connected devices, and/or IoT ecosystems.
  • Experience applying threat modeling and vulnerability assessment frameworks, such as STRIDE and CVSS.
  • Experience conducting penetration testing, malformed input testing (fuzz testing), static application security testing (SAST), and/or dynamic application security testing (DAST) for embedded systems.
  • Experience performing software composition analysis (SCA), software bill of materials (SBOM) generation, SBOM monitoring, and related software security activities.
  • Experience applying C programming language concepts and/or cryptographic principles to support product cybersecurity activities.
  • Experience communicating cybersecurity risks, technical findings, and recommendations through verbal discussions, presentations, and written communications.
  • Experience managing multiple projects, priorities, and deliverables across cross-functional teams in a dynamic product development environment.
  • Experience working with internal stakeholders and external business partners to support cybersecurity, compliance, and product development initiatives.

Benefits & conditions

Applicable to US Applicants Only:The expected compensation range for this position is $124,000 - $170,500, which includes base pay plus variable incentive pay, if eligible. This range represents a good faith estimate for this position. The specific compensation offered to a candidate may vary based on factors including, but not limited to, the candidate’s relevant knowledge, training, skills, work location, and/or experience. In addition, this position may be eligible for a range of benefits (e.g., Medical, Dental & Vision, Health Savings Accounts, Health Care & Dependent Care Flexible Spending Accounts, Disability Benefits, Life Insurance, Voluntary Benefits, Paid Absences and Retirement Benefits, etc.). Additional information is available at: https://www.solventum.com/en-us/home/our-company/careers/#Total-Rewards

Responsibilities of this position include that corporate policies, procedures and security standards are complied with while performing assigned duties.

Solventum is committed to maintaining the highest standards of integrity and professionalism in our recruitment process. Applicants must remain alert to fraudulent job postings and recruitment schemes that falsely claim to represent Solventum and seek to exploit job seekers.

Please note that all email communications from Solventum regarding job opportunities with the company will be from an email with a domain of @solventum.com. Be wary of unsolicited emails or messages regarding Solventum job opportunities from emails with other email domains.

Please note, Solventum does not expect candidates in this position to perform work in the unincorporated areas of Los Angeles County.

Solventum is an equal opportunity employer. Solventum will not discriminate against any applicant for employment on the basis of race, color, religion, sex, sexual orientation, gender identity, national origin, age, disability, or veteran status., $56.00 - $62.00 per hour

About the company

Thank you for your interest in joining Solventum. Solventum is a new healthcare company with a long legacy of solving big challenges that improve lives and help healthcare professionals perform at their best. At Solventum, people are at the heart of every innovation we pursue. Guided by empathy, insight, and clinical intelligence, we collaborate with the best minds in healthcare to address our customers’ toughest challenges. While we continue updating the Solventum Careers Page and applicant materials, some documents may still reflect legacy branding. Please note that all listed roles are Solventum positions, and our Privacy Policy: https://www.solventum.com/en-us/home/legal/website-privacy-statement/applicant-privacy/ applies to any personal information you submit. As it was with 3M, at Solventum all qualified applicants will receive consideration for employment without regard to their race, color, religion, sex, sexual orientation, gender identity, national origin, disability, or status, At Solventum, we enable better, smarter, safer healthcare to improve lives. As a new company with a long legacy of creating breakthrough solutions for our customers’ toughest challenges, we pioneer game-changing innovations at the intersection of health, material and data science that change patients’ lives for the better while enabling healthcare professionals to perform at their best. Because people, and their wellbeing, are at the heart of every scientific advancement we pursue.

We partner closely with the brightest minds in healthcare to ensure that every solution we create melds the latest technology with compassion and empathy. Because at Solventum, we never stop solving for you.

The Impact You’ll Make in this Role

As a Principal Cybersecurity Assurance Engineer you will have the opportunity to tap into your curiosity and collaborate with some of the most innovative and diverse people around the world. Here, you will make an impact by:

  • Leading cybersecurity assurance activities throughout the product life cycle, including creating cybersecurity risk management plans, threat modeling, performing vulnerability assessments, defining security architecture, creating SBOMs, managing vulnerabilities and cybersecurity risks, planning and monitoring security testing, including penetration testing, writing cybersecurity risk management reports, and ensuring traceability between security controls, security requirements, and security testing.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.jofdav.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

4:01 min

Finding personal fulfillment in the cybersecurity industry

LIVE

3:04 min

Replacing complex wireless networking with web bluetooth connections

George Cave · World Congress 2023

4:11 min

Introduction to cloud-native application developer security

Micah Silverman · World Congress 2022

3:40 min

Integrating mutation testing and fuzzing into software workflows

Michael Contento · World Congress 2023

1:45 min

Transitioning from software development to security roles

Stefania Chaplin · World Congress 2022

4:15 min

Modulating music tempo with Web Bluetooth API

Rowdy Rabouw Rowdy Rabouw · LIVE

Videos

See all

Related articles

See all