Remote Medical Device Product Security Engineer
Posted 2026-05-06
Remote, USA
Full-time
Immediate Start
Role: Cybersecurity / Product Security Engineer
Location: Remote
Job Summary
We're seeking a Cybersecurity / Product Security Engineer to design, implement, and maintain security controls across medical products and enterprise systems. This role ensures products are developed following secure-by-design principles and comply with healthcare and regulatory requirements.
- Key Responsibilities
- Security Engineering & Risk Management.
- Perform threat modeling and risk assessments for products and systems.
- Identify vulnerabilities and recommend mitigation strategies.
- Secure Development (DevSecOps).
- Integrate security into the Software Development Lifecycle (SDLC).
- Conduct secure code reviews and vulnerability scanning (SAST/DAST).
- Collaborate with DevOps teams to automate security controls.
- Security Architecture
- Define and implement security requirements and design controls.
- Develop and review secure system architectures.
- Ensure adherence to “Secure by Design” principles.
- Monitor systems for security threats and vulnerabilities.
- Participate in incident response and remediation efforts.
- Conduct root cause analysis and improve defensive measures.
- Cross-functional Collaboration
- Partner with engineering, QA, regulatory, and IT teams.
- Translate security requirements into technical implementations.
- Provide security guidance across product development teams.
- Required Qualifications
- Bachelor’s degree in Computer Science, Cybersecurity, or related field.
- 3–8+ years of experience in cybersecurity, application security, or product security.
- Strong understanding of:
- Network security & protocols
- Secure coding practices
- Vulnerability management
- Experience with Windows, Linux, and cloud platforms (e.g., Azure)
- Knowledge of scripting/programming (Python, PowerShell, or C#)
- Preferred Qualifications
- Experience with medical device or healthcare cybersecurity
- Familiarity with standards/frameworks:
- OWASP Top 10
- NIST, ISO 27001
- HIPAA / FDA cybersecurity guidance
- Experience with DevSecOps pipelines and automation tools