CybersecurityJobs.io
← Back to all jobs

Job Description

Myriad Genetics Inc. is seeking a Product Cybersecurity and Compliance Lead based in Salt Lake City, UT (onsite). In this role, you will act as a technical subject matter expert for product cybersecurity and regulatory cybersecurity compliance, helping ensure secure product development practices and providing the technical foundation needed for regulatory submissions across multiple regulated environments.

What you’ll do

  • Serve as a technical SME for product cybersecurity activities across regulated products, translating regulations and standards into actionable technical requirements.
  • Provide cybersecurity guidance for FDA, PMDA, IVDR, and related regulatory cybersecurity expectations.
  • Lead threat modeling, security architecture reviews, and Secure Product Development Framework (SPDF) activities.
  • Promote security-by-design practices across the product lifecycle, including input for new products, enhancements, and regulatory submissions.
  • Partner with the Director of Information Security to mature product cybersecurity capabilities and coordinate cybersecurity workstreams across Product, Engineering, QA, Regulatory Affairs, IT, and Information Security.
  • Support development of cybersecurity evidence and documentation for regulatory submissions, including cybersecurity risk management evidence generation.
  • Conduct product cybersecurity risk assessments and threat analyses, and review application, cloud, infrastructure, and system designs for cybersecurity risks.
  • Review software supply chain security controls and contribute to SBOM processes.
  • Coordinate vulnerability assessments, penetration testing, and remediation efforts, including participation in audits, assessments, and remediation activities.
  • Maintain cybersecurity compliance documentation and supporting artifacts, track deliverables and dependencies, and align efforts with regulatory milestones.
  • Facilitate technical reviews, threat modeling sessions, and cybersecurity working meetings; identify risks, blockers, and resource constraints impacting deliverables.
  • Recommend cybersecurity controls aligned with regulatory and business requirements, and help establish repeatable cybersecurity practices across product development teams.

What you bring

  • 7+ years of cybersecurity, application security, or product security experience.
  • Experience supporting software development or product engineering organizations.
  • Experience with threat modeling, architecture reviews, and secure SDLC practices.
  • Experience conducting product cybersecurity risk assessments.
  • Experience supporting regulated products or regulated software development environments.
  • Strong communication and stakeholder management skills.
  • Ability to lead cross-functional initiatives without direct authority.
  • U.S. citizen or national, Green Card holder, and living full time in the USA.

Tools and standards you may work with

  • Secure Product Development Framework (SPDF)
  • SBOM
  • FDA, PMDA, IVDR
  • HITRUST, ISO 27001
  • NIST CSF
  • CISSP, CCSP, CSSLP, CISM, CISM
  • AWS Security Specialty
  • GIAC
  • Secure SDLC

Preferred qualifications

  • Experience with medical device, diagnostics, biotechnology, healthcare, or other regulated products.
  • Experience supporting cybersecurity components of regulatory submissions.
  • Experience with SBOM management and software supply chain security.
  • Experience with HITRUST, ISO 27001, NIST CSF, or similar security frameworks.
  • Certifications such as CISSP, CCSP, CSSLP, CISM, AWS Security Specialty, GIAC, or equivalent cybersecurity certifications.

Other details

Physical requirements: Use of equipment and tools necessary to perform essential job functions.

Similar Jobs