**NO 3rd Parties or Sponsorship!
Role Title: Product Security Analyst
Employment Type: Contract
Duration: 6 months
Location: Denver, CO 3 days onsite
Role Description:
Consults on the implementation and configuration of cybersecurity capabilities for products, including the application of cybersecurity requirements, mitigation of cybersecurity defects and risks, and delivery of project artifacts such as threat models and project plans.
Partners with Research & Development product teams to execute product security capabilities, including threat intelligence, security scanning (SAST, DAST, SCA, network), coordination of third-party penetration testing, maintenance of the product security test lab, and ongoing research and education on cybersecurity topics.
Facilitates risk management activities, including risk management reports and risk/vulnerability reporting.
Engages appropriate oversight when deviations from program requirements are identified.
Performs product security incident response activities.
Monitors industry threat intelligence feeds for cybersecurity issues impacting the healthcare sector.
Manages and monitors the Coordinated Vulnerability Disclosure process, ensuring closed-loop communication with security researchers and internal product development stakeholders.
Collaborates with product teams to develop MDS2 documentation to streamline responses to future customer inquiries.
Accountable for customer risk and security assessments across all products, including devices and software solutions.
Coordinates customer notification processes when global cybersecurity threats are identified.
Works closely with the product security program leader to advance product security initiatives.
Provides escalation support for commercial teams (sales and technical support) regarding cybersecurity inquiries.
Requirements:
Minimum 5 years' experience
- Experience with FDA cybersecurity guidance for medical devices
- Experience with developing standard operating procedures (SOPs)
- Experience with medical device product cybersecurity regulatory submission requirements (globally)