Staff Product Security Engineer
Core
Represent Security/Privacy needs for Patient Care Solutions product design and development, ensuring compliance and secure delivery to customers.
Role type
Staff Product Security Engineer (clinical/medical devices)
Builds
Patient Care Solutions products and solutions for clinical use at the point of care
Domain
Healthcare / Medical Devices / Cybersecurity
Deliverable
production ML models | product features | dashboards & analysis | research | client delivery | infrastructure | physical/clinical work
Required skills
secure product development, system design, post-market security assessments, threat modeling, SBOM management, vulnerability assessment, regulatory compliance (HIPAA, GDPR, NIST, ISO27001), secure coding principles
Preferred skills
application security tools (Threat Modelling Tool, Black Duck, Burpsuite), penetration testing, ethical hacking, identity management (SAML, OAuth, SCIM), FDA-regulated environment experience, network protocols, API security
Technologies
Microsoft Threat Modelling Tool, Black Duck, Syft, Burpsuite, Grype, SAML, OAuth, SCIM, XACML
Responsibilities
Capture security/privacy requirements and consult development teams; Lead threat modeling sessions; Own Cybersecurity Management Plan and vulnerability mitigation; Generate and maintain Software Bill of Materials (SBOM); Scope and participate in penetration tests and risk assessments; Create Design Engineering Privacy and Security (DEPS) artifacts; Maintain QMS compliance
Seniority
Staff, hands-on IC with leadership responsibilities