Overview
Accepts corp to corp applications
Contract - 12+ month
Skills
security
Product
SECURITY ENGINEER
Job Details
Hello
I hope you are doing well. This is Ranjit Singh from Amaze Systems.
We are urgently hiring for a Principal Product Security Engineer position.
Kindly share your resume and connect with me to discuss the next steps.
Role: Principal Product Security Engineer
Location:- Remote
Duration: Long Term
JD:
- The ideal candidate will have deep experience working with engineering teams to integrate cybersecurity into real-time systems, embedded firmware, connected devices, or other product-level security contexts.
- This role focuses on cybersecurity for medical devices and embedded systems. It is not an IT security, compliance, or GRC-focused position.
- This role drives the integration of advanced cybersecurity measures, identifies and mitigates potential vulnerabilities, and supports initiatives that improve cyber-resiliency throughout the product lifecycle. You will serve as a technical subject matter expert and mentor, collaborating across teams and contributing to long-term improvements in our security posture.
Must Have Requirements
- Minimum 5 years of experience integrating security into embedded systems or connected medical devices in a regulated product development environment
- Strong understanding of secure development lifecycle (SDLC), secure boot, cryptography, secure firmware update, secure communication, and hardware/software interface security
- Master's degree in a relevant engineering or cybersecurity field
- Industry-recognized certifications (e.g., CISSP, CSSLP, CISM, CEH)
- Experience mentoring or technically guiding junior security engineers
- Demonstrated ability to implement secure architecture in embedded and connected device ecosystems
- Familiarity with FDA and MDR cybersecurity submission requirements
- Knowledge of secure coding practices and common vulnerabilities (e.g., OWASP, CWE, CVSS)
- Experience supporting cross-functional design reviews or formal design assurance processes
- Working knowledge of secure boot chains, cryptographic controls, and device authentication protocols
Key Responsibilities:
- Product Security Strategy & Continuous Learning - Stay abreast of emerging cybersecurity threats, technologies, and regulations specific to medical devices and health software. Contribute to OU and enterprise-wide product security strategy and roadmap development.
- Secure Product Development Lifecycle - Drive security integration into all stages of the product lifecycle, from concept and design to postmarket. Work closely with system architects, software leads, and hardware engineers to embed secure design patterns in both embedded and cloud-connected environments.
- Threat Modeling & Risk Assessment - Lead threat modeling sessions, conduct security risk assessments, and identify mitigation strategies in accordance with IEC 81001-5-1, ISO 14971, and FDA premarket cybersecurity guidance.
- Security Architecture & Design - Collaborate on the design and implementation of secure architectures, focusing on secure boot, secure communications, data protection, access control, secure software updates, and hardware-software integration.
- Security Testing & Analysis - Support and interpret results from vulnerability scans, penetration tests, and static/dynamic code analysis. Coordinate with internal teams and third-party vendors to ensure timely and appropriate risk mitigation.
- Security Awareness & Mentorship - Promote a culture of security awareness within R&D and provide mentorship to junior engineers. Lead by example through documentation, review participation, and active knowledge sharing.
- Regulatory & Standards Compliance - Ensure alignment with applicable standards (e.g., NIST, IEC 60601-4-5, IEC 81001-5-1) and support security documentation efforts for global regulatory submissions.
- Vendor & Supply Chain Security - Review and assess the cybersecurity posture of third-party suppliers and open-source software components used within product designs.
- Incident Response Support - Provide technical leadership during postmarket security incidents or field issues. Lead root cause investigations, containment strategies, and risk assessments.
- Security Documentation - Maintain comprehensive security documentation, including threat model diagrams, risk assessments, shared service inventories, design patterns, security guidelines, and product security plans/reports.
Ranjit Singh| Senior Talent Acquisition Specialist
Amaze Systems Inc
D: +1
E:
Employers have access to artificial intelligence language tools (“AI”) that help generate and enhance job descriptions and AI may have been used to create this description. The position description has been reviewed for accuracy and Dice believes it to correctly reflect the job opportunity.