





Tier-1 employer plus mid-level metro role increases competition, but niche security specialization limits applicant pool.
Medical-device regulatory knowledge and product security expertise make cross-industry transitions difficult.
Explicit 5–7 years, required security skills, and medical-device regulatory experience make filters strict.
Login to See Your Match Score
Create a free account or log in to unlock your CV match score across:
Perform security risk assessments and threat modeling throughout the medical device product development lifecycle, focusing on Class I, II, and III devices and connected healthcare systems.
Plan and execute security testing including vulnerability assessments, penetration testing, secure code reviews, and track vulnerabilities through remediation.
Support secure development lifecycle integration, regulatory compliance (FDA, IEC, NIST standards), vulnerability management, and develop automation tools for security processes using Python.
Bachelor's or Master's degree in Computer Science, Cybersecurity, Software Engineering, Electronics Engineering, Information Security, or related engineering discipline.
5-7 years of experience in Product Security, Application Security, Cybersecurity Engineering, or Medical Device Security.
Experience with security risk & threat modeling, security testing (penetration testing, vulnerability assessments, secure code reviews), and security tools like Burp Suite, OWASP ZAP, Checkmarx, or similar.
Proficient in Python scripting; experience with PowerShell or Bash preferred. Work Experience Required: 5-7 years.
Experienced in securing regulated medical devices or healthcare connected products, with hands-on skills in threat modeling and vulnerability management.
Demonstrates ability to collaborate cross-functionally with R&D, quality, regulatory, and product teams to embed security across product lifecycle.
Comfortable working in regulated environments with a focus on compliance to FDA, IEC, NIST cybersecurity frameworks and integrating security into CI/CD and DevSecOps pipelines.