Salary Range
$51,000 - $69,000 /year
EstimatedThis salary is estimated based on similar roles. The actual salary may vary.
Primary Function:
The Product Cybersecurity Team is responsible for the security lifecycle of medical devices, software products, infrastructure, cloud services, and IoMT solutions that generate, collect and analyze medical device machine data from thousands of systems deployed world-wide.
The ideal candidate for the position of Product Security Engineer III is an accomplished security engineer, with demonstrated experience in the secure design, development, and management of complex medical device applications and systems. The candidate has solid cybersecurity knowledge, comprising detailed understanding of cybersecurity threats, secure software design principles, secure coding practices and knowledge of cryptographic tools and libraries. The candidate can review product cybersecurity vulnerabilities; can recommend improvements in security design, and can support remediation. The candidate routinely conducts threat modeling, vulnerability management, and product line security management activities.
This position requires a candidate with strong technical and interpersonal skills, the ability to work effectively and collaboratively with the business and peer Engineering teams to deliver high quality solutions that ensure patient safety.
Roles & Responsibilities:
Product Security (20%)
β’ Assist product teams with defining and shaping Product Security strategy.
β’ Provide cybersecurity guidance and recommendation to Program & Product teams.
β’ Provide teams with technical security guidance as part of developing a product marketing strategy.
β’ Perform Product Security resource management in support of Intuitive product programs/projects.
β’ Where necessary, support third-party vendor oversight in support of program/project-related Product Security activities.
β’ Provide Product Cybersecurity support & recommendation to product road-mapping activities.
β’ Support communication of product cybersecurity strategy as an element of overall product strategy.
β’ Assist in Product Security Incident Response Team (PSIRT) analysis & response.Risk Management (20%)
β’ Ensure that product cybersecurity risk meets product risk acceptance objectives.
β’ Provide product cybersecurity risk management guidance and expertise to projects, peers or external inquires.
β’ Design, implement and maintain common product cybersecurity risk registers.
β’ Implement, review, and assess the results of product cybersecurity risk assessments for both internal and third-party systems and components.
β’ Recommend, document, and monitor the implementation of any corrective actions resulting from product cybersecurity risk assessments.
β’ Perform product cybersecurity risk analysis and risk management for compliance-based initiatives.
β’ Research new trends in cybersecurity risk management, standards, technologies and framework revisionsSDLC And Product Delivery (15%)
β’ Assist in leading and overseeing product cybersecurity Secure Product Development Framework (SPDF) and Software Development Lifecycle (SDLC) practices.
β’ Gather and review product cybersecurity compliance requirements as a component of Security by Design initiatives.
β’ Assess product cybersecurity as a component of product designs and architectures.
β’ Prescribe and evaluate secure coding standards as a component of SPDF and SDLC.
β’ Support product cybersecurity testing and remediation as a component of SPDF and SDLC.
β’ Through review of Software Bill of Material (SBOM), Software of Unknown Provenance (SOUP) and security tools environments, assess third-party component security as an element of overall product cybersecurity posture.
β’ Perform hardware, software, and application cybersecurity threat modeling.Vulnerability Assessment & Penetration Testing (10%)
β’ Support development, communication, and execution of vulnerability scanning, secure code review, and penetration testing plans.
β’ Support scoping engagements and contribute to Statements of Work for external assessment activities.
β’ Provide hands-on support and expertise to ongoing vulnerability assessment and penetration testing activities.
β’ Analyze and present findings and/or remediation guidance associated with vulnerability assessment activities.Security Engineering (10%)
β’ Support product teams with guidance and recommendations for infrastructure security design.
β’ Perform vulnerability assessments as required
β’ Support hardening of systems to meet product cybersecurity and cyber resilience requirements.
β’ Provide guidance and recommendations in evaluation of new security products and solutions.Architecture And Design (10%)
β’ Determine applicable security requirements and security controls as a component of security design.
β’ Perform vulnerability analysis and risk assessments of product and system architectures.
β’ Develop product cybersecurity reports, supporting compliance audits and security assessments.
β’ Develop and maintain product cybersecurity architecture diagrams & design documents.
β’ Remain current on the evolving landscape of product cybersecurity frameworks, methodologies, and procedures.