Medical Device Cybersecurity Engineer.
Cleveland, OH, US • Posted 19 hours ago • Updated 9 hours ago

Apolis
Dice Job Match Score™
🔗 Matching skills to job...
Job Details
Skills
- MEDICAL DEVICE
- MEDICAL DEVICE SECURITY
- MEDICAL
- EMBEDDED
- FIRMWARE
- MEDICAL EMBEDDED DEVICES
- VAPT
- PENETRATION TESTING
- VULNERABILITY ASSESSMENT
- SAST
- DAST
- SCA
- SBOM
- SOUP
- THREAT
- RISK
Summary
Job Title: Medical Device Cybersecurity Engineer.
Location: Cleveland, OH
Contract: 6+ Months
Must have : Medical Embedded Devices, VAPT (Hardware, Firmware), Design History File (DHF), Risk Management File (RMF) Documentation, Threat Modeling, SAST, DAST, SBOM and SOUP Analysis, SCA, FDA Regulations, 510K, ISO 13485 and ISO 14971
Job Summary:
The Medical Device Cybersecurity Engineer is responsible for ensuring that medical device software, connected systems, and supporting infrastructure are designed, developed, and maintained in compliance with FDA cybersecurity requirements and applicable international standards. This role supports cybersecurity risk management activities across the medical device lifecycle, from design and development through post-market surveillance, and contributes to regulatory submissions and FDA inspections.
Key Responsibilities:
FDA & Regulatory Compliance
- Ensure compliance with FDA medical device cybersecurity requirements, including FDA Premarket Cybersecurity Guidance and FDA Post-market Cybersecurity Guidance
- Support cybersecurity content for 510(k) including:
- Cybersecurity risk assessments
- Threat model
- Security architecture descriptions
- Software Bill of Materials (SBOM)
- Threat & Vulnerability Assessment
- Maintain cybersecurity documentation within the Design History File (DHF) and Risk Management File (RMF).
- Support FDA inspections, audits, and responses related to cybersecurity.
Design Controls & Risk Management
- Perform cybersecurity risk management activities in accordance with ISO 14971.
- Identify cybersecurity hazards that could lead to patient harm or device malfunction.
- Define and implement cybersecurity risk controls and verify their effectiveness.
- Ensure cybersecurity requirements are incorporated into design inputs, design outputs, and design verification and validation activities.
- Support secure design reviews and change control processes.
Vulnerability Management & Post-market Surveillance
- Monitor and assess cybersecurity vulnerabilities affecting medical devices, including third-party and open-source software.
- Support coordinated vulnerability disclosure processes in alignment with FDA expectations.
- Participate in post-market surveillance, complaint handling, and CAPA activities related to cybersecurity.
- Support incident response activities and field corrective actions as needed.
Technical Security Responsibilities
- Evaluate and implement security controls, including:
- Authentication and authorization
- Encryption and key management
- Secure boot and firmware integrity
- Logging and audit trails
- Conduct or support penetration testing, threat modeling, and security testing.
- Assess cybersecurity risks associated with cloud services, mobile applications, and networked medical devices.
- Review supplier documentation related to cybersecurity and SBOMs.
Ensure supplier cybersecurity risks are documented and mitigated per quality system requirements.
Qualifications:
- Bachelor s degree in Cybersecurity, Computer Science, Software Engineering, Electrical Engineering, or related field.
- Minimum 8 years of experience in cybersecurity, with experience in medical devices.
- Demonstrated knowledge of:
- FDA medical device cybersecurity guidance
- ISO 13485 and ISO 14971
- Experience with cybersecurity risk assessments and regulatory documentation.
- Dice Id: 10106862
- Position Id: 26-00186
- Posted 19 hours ago
Company Info
About Apolis
Founded 1996, RJT Compuquest, Inc. is an ERP and IT consulting services provider focused on providing innovative and successful business solutions. We are capable of working across all technology platforms, operating systems and infrastructures. RJT has experience in performing implementations, technical and functional upgrades, optimization projects, and full service staffing.
RJT consultants have real world experience across a broad spectrum of industries and can apply that knowledge to best face your business needs. Our recruiting process selects only the most highly qualified individuals for your project. If we cannot find the best consultant for your project, then we have a large pool of third-party consultants that we recruit from to ensure your business needs are met.
Our consultants have up to twenty years of business experience and an average of more than six years of IT and ERP experience. This means that the project team not only understands how systems work, they also understand how the technology impacts the business processes of organizations. We believe that the success of an engagement is determined by strong project management, as well as clear communication and mutual commitment working collaboratively. Our methodology begins with listening to the customer about their needs, then working with their team to gain a clear understanding of the requirements, while providing a knowledge transfer of best practices for the organization. The RJT team is committed to this goal.
When you leverage our exceptional recruiting and management capabilities and unparalleled client service skills, you take the most important step toward accomplishing your business goals. As a trusted advisor to companies of all sizes, we make it our business to become a specialized, physical extension of your team. We listen to your goals, assess your needs, and then take the steps necessary to achieve your objectives. Built on long-term, trusted client and employee relationships, RJT strives to consistently and efficiently plan, execute and deliver high quality services and results.


Similar Jobs
It looks like there aren't any Similar Jobs for this job yet.
Search all similar jobs