Security Engineer (Med Device)
Role details
Job location
Tech stack
Job description
We are seeking a Product Security Engineer to own and lead the cybersecurity governance process for Software as a Medical Device (SaMD) products within a strategic Design History File (DHF) workspace. This individual will be responsible for maintaining and improving cybersecurity documentation, vulnerability management processes, risk management activities, and compliance artifacts required under evolving FDA cybersecurity regulations. The role is highly strategic and process-oriented, serving as the security lead embedded within one or two high-visibility SaMD teams. Responsibilities include defining security requirements, reviewing threat analyses, assessing the effectiveness of security controls, overseeing cybersecurity testing outputs, and ensuring documentation remains current as product designs evolve. The ideal candidate will drive continuous improvement of cybersecurity and risk management processes, maintain ownership of all required regulatory documentation, and partner closely with cross-functional engineering and quality teams to ensure ongoing compliance and product security. This is a leadership role without direct people management responsibilities and is focused on governance, oversight, and strategic decision-making rather than hands-on technical implementation.
Requirements
- 5+ years of experience in Product Security, Application Security, Medical Device Security, or Cybersecurity Engineering
- Experience working within recognized security frameworks and secure development practices
- Experience authoring and reviewing cybersecurity requirements
- Strong understanding of secure coding principles and common software vulnerabilities
- Experience conducting Threat Modeling using STRIDE methodology
- Experience performing Secure Architecture Reviews
- Experience with Software Vulnerability Management processes - 3rd party management
- Experience conducting Threat Assessments and Vulnerability Assessments
- Experience utilizing CVSS scoring methodologies
- Experience reviewing SBOMs (Software Bill of Materials)
- Experience evaluating CVEs and CWEs
- Strong understanding of SDLC and software engineering practices
- Cloud security and configuration experience
- Familiarity with FDA Cybersecurity Guidance
- Experience with IEC 62304 and ISO 14971
Nice to Have Skills & Experience
- ISO 27001 experience
- HIPAA experience
- GDPR/privacy experience
- SaMD experience
- FDA submission support
- Cybersecurity risk management files
- Penetration testing knowledge
- Connected device/IoT security
- CISSP, CSSLP, Security+ or similar certifications
Benefits & conditions
Benefit packages for this role will start on the 1st day of employment and include medical, dental, and vision insurance, as well as HSA, FSA, and DCFSA account options, and 401k retirement account access with employer matching. Employees in this role are also entitled to paid sick leave and/or other paid time off as provided by applicable law.