Role: Cybersecurity / Product Security Engineer
Location: Remote
Job Summary
We're seeking a Cybersecurity / Product Security Engineer to design, implement, and maintain security controls across medical products and enterprise systems. This role ensures products are developed following secure-by-design principles and comply with healthcare and regulatory requirements.
Key Responsibilities
• Security Engineering & Risk Management.
• Perform threat modeling and risk assessments for products and systems.
• Identify vulnerabilities and recommend mitigation strategies.
Secure Development (DevSecOps).
• Integrate security into the Software Development Lifecycle (SDLC).
• Conduct secure code reviews and vulnerability scanning (SAST/DAST).
• Collaborate with DevOps teams to automate security controls.
Security Architecture
• Define and implement security requirements and design controls.
• Develop and review secure system architectures.
• Ensure adherence to “Secure by Design” principles.
• Monitor systems for security threats and vulnerabilities.
• Participate in incident response and remediation efforts.
• Conduct root cause analysis and improve defensive measures.
Cross-functional Collaboration
• Partner with engineering, QA, regulatory, and IT teams.
• Translate security requirements into technical implementations.
• Provide security guidance across product development teams.
Required Qualifications
• Bachelor’s degree in Computer Science, Cybersecurity, or related field.
• 3–8+ years of experience in cybersecurity, application security, or product security.
Strong understanding of:
• Network security & protocols
• Secure coding practices
• Vulnerability management
• Experience with Windows, Linux, and cloud platforms (e.g., Azure)
• Knowledge of scripting/programming (Python, PowerShell, or C#)
Preferred Qualifications
• Experience with medical device or healthcare cybersecurity
• Familiarity with standards/frameworks:
• OWASP Top 10
• NIST, ISO 27001
• HIPAA / FDA cybersecurity guidance
• Experience with DevSecOps pipelines and automation tools