Product Security Engineer

Remote • Posted 7 hours ago • Updated 7 hours ago
Contract W2
12 Months
No Travel Required
Remote
145000 - 275000/yr
Company Branding Image
Fitment

Dice Job Match Score™

🤯 Applying directly to the forehead...

Job Details

Skills

  • Bill Of Materials
  • Firmware
  • Medical Devices
  • Embedded Systems
  • Embedded Linux
  • Regulatory Compliance
  • Product Development
  • Software Development
  • Software Security
  • Computer Networking
  • Security Controls
  • Threat Modeling
  • Vulnerability Management
  • Embedded Development

Summary

Advisory Product Security Engineer

Location: Hybrid | Pittsburgh, PA (or Remote for the Right Candidate)

About eNGINE

eNGINE builds Technical Teams. We are a Solutions and Placement firm shaped by decades of interaction with Technical professionals. Our inspiration is continuous learning and engagement with the markets we serve, the talent we represent, and the teams we build. Our Consulting Workforce is encouraged to enjoy career fulfillment in the form of challenging projects, schedule flexibility, and paid training/certifications. Successful outcomes start and finish with eNGINE.


Role Overview

eNGINE is seeking an Advisory Product Security Engineer to support the development of next-generation network-connected medical devices. This role is ideal for a security engineer who enjoys working directly with embedded software developers to build secure products rather than simply reviewing or auditing them.

You will serve as the cybersecurity subject matter expert for multiple engineering teams, partnering throughout the software development lifecycle to implement secure design principles, address vulnerabilities, and meet evolving medical device cybersecurity regulations. This is a hands-on role where you''ll contribute technical solutions, develop automation, and provide coding assistance to embedded development teams when security-related features or remediation efforts require implementation.


Duties & Responsibilities

  • Partner directly with embedded software engineers to design, develop, and implement security features within medical devices.
  • Provide hands-on technical assistance to development teams, including Python scripting, proof-of-concept development, automation, and security-focused coding support.
  • Collaborate with engineering teams to remediate vulnerabilities and integrate security controls into existing and new products.
  • Lead threat modeling exercises and translate findings into practical engineering solutions.
  • Drive Software Bill of Materials (SBOM) and Vulnerability Exploitability eXchange (VEX) activities using enterprise security tooling.
  • Assist with vulnerability management, security assessments, and coordinated vulnerability disclosure (CVD) efforts.
  • Guide teams on secure coding practices, authentication, encryption, certificate management, secure communications, and access control implementation.
  • Support the creation of cybersecurity documentation required for regulatory submissions, including security risk assessments, testing evidence, and mitigation plans.
  • Work alongside R&D teams to integrate cybersecurity throughout the product development lifecycle.
  • Help establish and improve secure development processes, standards, and engineering best practices.
  • Evaluate emerging cybersecurity threats impacting connected medical devices and help development teams proactively address them.
  • Review and contribute to internal secure development policies and engineering standards.

Qualifications

  • Bachelor''s degree in Computer Science, Computer Engineering, Electrical Engineering, Cybersecurity, or a related technical discipline.
  • 5+ years of experience in Product Security, Application Security, or Embedded Security.
  • Experience supporting cybersecurity initiatives within medical devices, healthcare technology, or other regulated embedded systems.
  • Strong understanding of embedded Linux environments and embedded software development.
  • Hands-on experience writing Python for automation, tooling, scripting, or security workflow improvements.
  • Comfortable contributing code or technical implementations alongside software engineering teams.
  • Knowledge of secure networking concepts including TCP/IP, TLS, certificates, encryption, authentication, and secure communications.
  • Experience performing threat modeling and translating findings into engineering requirements.
  • Familiarity with SBOM management, vulnerability remediation, and software supply chain security.
  • Excellent communication skills with the ability to work effectively with software engineers, architects, quality teams, and regulatory stakeholders.

Preferred Experience

  • Experience developing or securing embedded medical devices.
  • Familiarity with AWS or cloud-connected embedded products.
  • Knowledge of FDA cybersecurity guidance, IEC 62304, AAMI TIR57, NIST Cybersecurity Framework, EU MDR, NMPA, and other medical device cybersecurity standards.
  • Experience with SAST, DAST, IAST, Software Composition Analysis (SCA), fuzz testing, and related application security tools.
  • Experience implementing secure boot, secure firmware updates, cryptographic services, or hardware-based security features.
  • Background working within Agile product development environments.
  • Experience supporting security activities throughout the entire SDLC.

What Makes This Role Unique

This is not a governance or compliance-only security position. The ideal candidate enjoys rolling up their sleeves and working directly with software engineers to solve security challenges. You''ll be expected to architect solutions, write scripts and tooling, assist with implementation, and help development teams build secure products—not simply identify issues for others to fix.


Next Steps

No C2C, relocation, referral, or sponsorship candidates for this role.

For finer details on how eNGINE can impact your career, apply today!

 

Employers have access to artificial intelligence language tools (“AI”) that help generate and enhance job descriptions and AI may have been used to create this description. The position description has been reviewed for accuracy and Dice believes it to correctly reflect the job opportunity.
  • Dice Id: 91101830
  • Position Id: 9031170
  • Posted 7 hours ago

Company Info

About eNGINE LLC

eNGINE is a Pittsburgh-based Solutions firm specializing in building Technical and Cyber Security teams. We are a trusted business partner to our clients, and provide resources for Project based Consulting, Contract to hire and Direct Hire. We pride ourselves in building lasting relationships with both our consultants as well as our client partners, and aligning the two when the right fit arises. eNGINE applies over 85 years of collective experience representing Consultants, uncovering passive full time hires, and building Technology teams in Pittsburgh. It’s understood that the wrong resource at the right time is worse than no resource at all. You don’t take shortcuts. Neither do we.

Contact the job poster
JM

Justin Morford

Recruiter @ eNGINE LLC
Create job alert
Set job alertNever miss an opportunity! Create an alert based on the job you applied for.

Similar Jobs

It looks like there aren't any Similar Jobs for this job yet.

Search all similar jobs