Mindlance is seeking an experienced Product Security Engineer to join their client in securing innovative healthcare technologies. The role focuses on securing Medical Devices and Software as a Medical Device (SaMD) platforms, while collaborating with various teams to ensure compliance and best practices in cybersecurity.
Responsibilities:
- Perform product security risk assessments and threat modeling
- Conduct security architecture and design reviews
- Support FDA cybersecurity documentation, including 510(k) submissions
- Develop Product Security Risk Management, Vulnerability Management, and Incident Response Plans
- Participate in Secure Software Development Lifecycle (SSDLC) activities
- Analyze SAST, DAST, and vulnerability scan results
- Support SBOM generation and third-party software risk analysis
- Partner with Engineering and DevOps teams to implement secure configurations and security best practices
- Support post-market cybersecurity activities and security audits
Requirements:
- 5+ years of experience in Product Security, Cybersecurity, or Cloud Security
- Experience with Medical Devices or Software as a Medical Device (SaMD)
- Strong background in Threat Modeling and Security Risk Assessments
- Experience supporting FDA cybersecurity documentation and 510(k) submissions
- Knowledge of SSDLC, NIST Cybersecurity Framework, NIST 800 Series, and OWASP Top 10
- Experience with vulnerability management, security architecture reviews, and SBOM
- Medical Device or Healthcare Software experience
- Familiarity with ISO 13485, ISO 27001, and AAMI TIR57
- Cloud Security and DevSecOps experience