Product Security Engineer II
Core
Securing Class I-III medical devices, connected care platforms, and cloud-connected healthcare systems throughout the product development lifecycle.
Role type
Product Security Engineer
Builds
Secure medical devices, connected care platforms, and cloud-connected healthcare systems
Domain
Healthcare technology / Medical Device Security
Deliverable
production ML models | product features | dashboards & analysis | research | client delivery | infrastructure | physical/clinical work
Required skills
Security risk assessment, Threat modeling (STRIDE, Attack Trees, MITRE ATT&CK), Security testing (Penetration testing, Vulnerability assessment, Secure code review), Network security testing, Web and API security testing, Python programming, Automation scripting, SBOM & Dependency analysis, CI/CD security integration
Preferred skills
Medical device security experience, Embedded systems security, IoT platforms security, PowerShell or Bash scripting
Technologies
Burp Suite, OWASP ZAP, Checkmarx, Fortify, Veracode, SonarQube, Nessus, Nmap, Wireshark, Metasploit, rivy, Snyk, Prisma Cloud, Microsoft Defender for Cloud, AWS Security Services, Dependency-Track, CycloneDX Tools
Responsibilities
Perform security risk assessments, Conduct threat modeling exercises, Review system/software/cloud/network architectures, Plan and execute security testing activities, Integrate cybersecurity activities into product development processes, Develop automation scripts and tools
Seniority
Mid-Senior, hands-on IC