Client Summary:
Our client is a global medical device manufacturer and our mission is Helping Surgeons Treat Their Patients Better™. The right candidate for this role will have some experience securing and pen-testing embedded or IoT devices along with a background in electrical engineering or software system design.
Salary: $75 – $100k
Client is located out of Naples, FL but will consider remote candidates
Job Summary:
- Seeking Pen Testers and Cybersecurity Experts who want a career that positively impacts patient health, safety, and privacy!
- As our Embedded Product Security Engineer II, your day-to-day would be assisting our product design and development teams in securing connected and IoT medical devices.
- You would take part in architecture reviews, grooming product security requirements, testing for vulnerabilities, and documenting the steps of our Secure Product Development Framework for use in regulatory submissions around the globe.
- You will have the opportunity to attend training for security certifications and go to events like H-ISAC Conferences, DEF CON, and Black Hat. And of course, you would get to help secure cutting-edge technology that has a positive impact in society!
- We are open to this role sitting in our office in Boston or Work form home remote.
Essential Duties and Responsibilities:
- Provide feedback to development teams for the secure design of electronic medical devices.
- Conduct security testing and analysis on devices to find vulnerabilities.
- Champion security findings by ensuring they are reproducible, documented, prioritized, and addressed.
- Help to ensure standards are met during the design, development, and maintenance of a medical device using a Secure Product Development Framework.
- Support teams in a fast-paced Agile/Scrum environment.
- You will monitor global regulatory changes and emerging technologies related to Medical Device Software.
- You will provide consultative guidance, as necessary, with new product development and be a point of contact with teams during the implementation or updates of security controls, configurations or software features.
- You will prepare, publish, and train internal resources on key technologies, technical security requirements, and risks.
- You will guide software technology and architecture documentation related to Product Security (Software requirements specifications, Architecture and Data Flow Diagrams, Risk mitigation traceability).
Education and Experience:
- 2 + years of relevant work experience required
- Bachelor’s degree required preferably in Engineering (Mechanical, Biomedical, Electrical or Software Engineering) or Computer Science
Preferred Qualifications:
- Knowledgeable of System and Software Development Processes and Lifecycles required (Agile SDLC).
- Knowledgeable of application security best practices required
- Excellent communication skills and customer service oriented.
- Knowledgeable of System and Software Development Processes and Lifecycles required (Agile SDLC).
- Knowledgeable of application security best practices required.
- Experience in embedded system development, IoT lifecycle, real-time operating systems, firmware, RFID, CANbus, WiFi, or Bluetooth LE preferred.
- Experience in web application security and controls concepts preferred (OWASP).
- Knowledge of ISO/IEC, NIST, EU MDR/MDCG, and FDA standards and requirements a plus.
- Experience with GDPR, PIPEDA, CCPA and other global privacy regulations a plus
- Experience with risk management methodologies, threat modeling, and vulnerability ranking a plus.
- Cybersecurity related certifications a plus (OSCP, OSWE, CSSLP, CISSP, Security+).
- Cybersecurity related coursework, papers, or presentations a plEducation and Experience:
- 2 + years of relevant work experience required
- Bachelor’s degree required preferably in Engineering (Mechanical, Biomedical, Electrical or Software Engineering) or Computer Science
Education and Experience:
- 2 + years of relevant work experience required
- Bachelor’s degree required preferably in Engineering (Mechanical, Biomedical, Electrical or Software Engineering) or Computer Science