CybersecurityJobs.io
← Back to all jobs

Job Description

The Senior Product Security Engineer role focuses on embedding Secure by Design across product teams, conducting security assessments and risk management, and supporting DevSecOps for healthcare solutions. The position may be remote or based in Newark, DE; Santa Clara, CA; Marlborough, MA, or other locations.

Responsibilities

  • Drive a Secure by Design culture across product teams, ensuring alignment with security standards and best practices.
  • Contribute to the ongoing enhancement of Secure by Design policies and procedures, aligning products with current security requirements and regulatory standards.
  • Assist in creating and maintaining security design documentation and architecture diagrams.
  • Perform and document continuous security assessments, including Threat Modeling, for Hologic products and remote connectivity solutions, providing guidance to product teams as needed.
  • Carry out Security Risk Management activities to address identified vulnerabilities and security design issues.
  • Develop and maintain security controls and requirements while actively participating in design discussions and activities.
  • Support product development efforts, including Security Code Reviews, to ensure adherence to Secure by Design principles and appropriate security controls.
  • Assist in automating security testing and reporting, manage security tooling, and secure cloud environments as part of DevSecOps.
  • Oversee ongoing security monitoring of in-market products and connected health solutions, and participate in incident response investigations as necessary.
  • Educate sales and service teams on securing our products, connected health solutions, and their operating environments.

Requirements

  • Master’s or Bachelor’s degree in Computer Science, Management Information Science, Engineering, or a related technical field.
  • 4+ years of relevant experience in:
    • Computer and network security
    • Cloud based platform experience
    • Computer networking administration
    • Microsoft Windows and Linux operating systems
    • Software application testing and maintenance
    • Cybersecurity Risk Assessment
  • Knowledge of the secure development lifecycle and experience in a development environment.
  • Expertise in application secure design and code reviews, with an understanding of Secure Coding standards and common vulnerabilities (OWASP Top 10, CWEs).
  • Proficiency in scripting and simple application development (PowerShell, Python, C#, C++).
  • Experience with industry standard security tools (SAST, SCA, DAST, vulnerability scanning).
  • Leadership in Threat Modeling, with STRIDE method preferred.
  • Penetration testing experience (direct or supportive).
  • Ability to secure development and cloud environments (Azure preferred) and the DevSecOps (CI/CD) pipeline.
  • Strong verbal and written communication skills.

Technologies

PowerShell, Python, C#, C++, Windows, Linux, SAST, SCA, DAST, vulnerability scanning, Azure, STRIDE, Threat Modeling, OWASP Top 10, CWEs, CI/CD

Benefits

  • Competitive salary and annual bonus scheme
  • Comprehensive training and continued development
  • Equal Opportunity Employer

Ideal Candidate Profile

  • Industry Awareness: Maintains vigilance on security threats affecting healthcare products and manages risk in line with quality procedures.
  • Troubleshooting Expertise: Effectively diagnoses and resolves issues in networked, computer-based products.
  • Travel Flexibility: Availability for travel to Hologic offices, training sessions, and customer sites.
  • Autonomous Alignment: Works with some supervision while aligning with strategic priorities and corporate goals.
  • Cloud Knowledge: Strong grasp of cloud design concepts and familiarity with security analysis and protection tools.

Preferred Qualifications

  • Medical Systems Knowledge: Experience with medical information system administration and familiarity with medical device security standards and regulations, including FDA Premarket Cybersecurity Guidance, IEC 81001-5-1, AAMI TIR57, AAMI SW96.
  • Regulated Industry Experience: Background in software development and verification within a regulated sector.
  • Technical Support Experience: Experience providing technical support to field service teams and end users.
  • Certifications: Security-related credentials (for example CISSP) are strongly preferred, along with Windows, Linux, and Cisco networking certifications.

Similar Jobs