Product Cybersecurity Expert

Sonova Group

Kitchener

Hybrid

CAD 156,000 - 195,000

Full time

15 hours ago
Be an early applicant
Application generator

A complete application in a minute — tailored resume and cover letter, ready to send.

Get past ATS filters

Benefits offered by this job

Hybrid work model
Bonus eligible

Job summary

Sonova is seeking a Product Cybersecurity Expert in R&D to secure the software and hardware ecosystem behind connected hearing care. You will lead threat modeling, risk assessments, and vulnerability management across devices, firmware, apps, and cloud services in a hybrid work setting.

You will drive secure development, integrate security tooling into CI/CD, coordinate audits and regulatory evidence, and advise stakeholders on risk-based decisions while coaching teams to raise cybersecurity

Qualifications

  • 5+ years in software eng, system/software architecture, or DevSecOps with 3+ years in cybersecurity
  • Experience translating security findings to engineering and leadership
  • Understanding of modern dev workflows and security integration into CI/CD processes

Responsibilities

  • Embed cybersecurity across the secure product lifecycle for connected medical devices, embedded platforms, firmware, mobile apps, and cloud-based services
  • Lead threat modeling, product cybersecurity risk assessments, and mitigation planning with global R&D teams
  • Integrate security checks and tooling into development workflows and CI/CD pipelines to find and address issues early
  • Drive product vulnerability management for Sonova products, including intake, triage, remediation tracking, and post-market monitoring
  • Prepare audit-ready cybersecurity evidence for regulatory submissions and quality processes, including FDA, MDR, and IEC 81001-5-1 expectations
  • Plan and coordinate security testing with internal teams and external partners; analyze findings and drive remediation
  • Advise product, engineering, quality, and regulatory stakeholders on practical, risk-based security decisions
  • Strengthen cybersecurity capability through coaching, security champions, and cross-functional collaboration

Skills

Threat modeling
Vulnerability management
CI/CD security
Regulatory evidence
Cryptography basics

Education

Engineering degree

Tools

CI/CD tooling

Job description

Select how often (in days) to receive an alert:

At Sonova, we envision a world where everyone can enjoy the delight of hearing. This vision inspires us and fuels our commitment to developing innovative solutions that improve hearing health and human connection - from personal audio devices and wireless communication systems to hearing aids and cochlear implants. We're dedicated to providing outstanding customer experiences through our global audiological care services, ensuring that everyone has the opportunity to engage fully with the world around them.

Guided by a culture of continuous improvement that fosters resilience and self-motivation, our team is united by a shared commitment to excellence and a deep sense of pride in our work, each of us playing a vital role in creating meaningful change,

Here you’ll find a diverse range of opportunities that span both consumer and medical solutions and the freedom to shape your career while making an impact on the lives of others. Join us in our mission to create a more connected world, where every voice is heard and every story matters.

Product Cybersecurity Expert

Research & Development | Hybrid

Help secure the future of connected hearing care. As our Product Cybersecurity Expertin R&D, you will help protect the products and digital experiences that improve hearing health and human connection worldwide.

In this role, you will combine product cybersecurity expertise with technical leadership responsibilities, supporting secure design, threat modeling, vulnerability management,DevSecOpsintegration, and regulatory evidence for connected medical devices while collaborating across global R&D, quality, regulatory, and product teams.

WHAT YOU’LL DO
  • Embed cybersecurity across the secure product lifecycle for connected medical devices, embedded platforms, firmware, mobile apps, and cloud-based services
  • Lead threat modeling, product cybersecurity risk assessments, and mitigation planning with global R&D teams
  • Integrate security checks and tooling into development workflows and CI/CD pipelines to find and address issues early
  • Drive product vulnerability management for Sonova products, including intake, triage, remediation tracking, and post-market monitoring.
  • Prepare audit-ready cybersecurity evidence for regulatory submissions and quality processes, including FDA, MDR, and IEC 81001-5-1 expectations
  • Plan and coordinate security testing with internal teams and external partners; analyze findings and drive remediation
  • Advise product, engineering, quality, and regulatory stakeholders on practical, risk-based security decisions
  • Strengthen cybersecurity capability through coaching, security champions, and cross-functional collaboration
WHAT YOU BRING
  • 5+ years of experience in software engineering, system/software architecture,productdevelopment, project management, orDevSecOps, including 3+ years in cybersecurity
  • Strong practical knowledge of secure SDLC, threat modeling, security assessments, security testing, and vulnerability management
  • Experience translating security risks and technical findings into clear decisions for engineering, product, quality, and leadership audiences
  • Understanding of modern development workflows, CI/CD, and how to integrate security without slowing innovation
  • Knowledge of cryptography, authentication protocols,cloudandsoftware supply chain security
  • Basic understanding of AI technology and associated threats; hands-on experience using AI technology
  • Higher-level engineering degree or equivalent experience, with further education or specialization in cybersecurity
  • Excellent English communication skills and the ability to influence across distributed, cross-functional teams
NICE TO HAVE
  • Experience in medical devices, healthcare, or another regulated product environment
  • Security certifications such asISC2/CISSP, GIAC, or equivalent accredited programs
  • Working knowledge of Privacy by Design principles

A minimum of 200Mb/sec download and 10Mb/sec upload speed internet connectivity is required to support any remote/hybrid employee functionality at Sonova

This role's pay range is between: $112,000 - $140,000. This role is also bonus eligible.

How we work:

At Sonova, we prioritize the well-being of our employees and foster an inclusive environment that promotes engagement and collaboration. Our team-customized hybrid work model empowers teams to balance individual needs with business goals, offering flexibility and individualized time management. We recognize the importance of life outside of work and strive to create a supportive and motivating workplace where innovation thrives.

Sonova is an equal opportunity employer.

We team up. We grow talent. We collaborate with people of diverse backgrounds to win with the best team in the market place. We guarantee every person equal treatment in regard to employment and opportunity for employment, regardless of a candidate’s ethnic or national origin, religion, sexual orientation or marital status, gender, genetic identity, age, disability or any other legally protected status.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior IT Cyber Security Specialist
Senior IT Cyber Security Specialist

Sonova Group • Kitchener

On-site
CAD 124,000 - 150,000
Wellness benefit
Pension contributions with employer-m
Mentorship program
Software Developer, Manufacturing Data Solutions (Python/SQL)
Software Developer, Manufacturing Data Solutions (Python/SQL)

Sonova Group • Kitchener

On-site
CAD 90,000 - 115,000
Wellness benefit
Paramedical coverage
Employer-matched pension
+1
Hearing Performance Developer
Hearing Performance Developer

Sonova Group • Kitchener

On-site
CAD 91,000 - 114,000
Exciting and challenging work env.
Opportunities for continuous self-im -
Flexible hybrid work environment
+4
Regulatory Systems Analyst Co-op
Regulatory Systems Analyst Co-op

Sonova Group • Kitchener

On-site
CAD 25,000 - 30,000
Campaign Operations Coordinator - Canada
Campaign Operations Coordinator - Canada

Sonova Group • Mississauga

On-site
CAD 61,000 - 75,000
Wellness benefits
Pension contributions
Hybrid work environment in Mississauga
Software Engineer
Software Engineer

Sonus Microsystems • Vancouver

On-site
CAD 110,000 - 170,000
Equity stock options
Autonomy
Flexibility
Cyber Security Engineer
Cyber Security Engineer

Verathon • Burnaby

On-site
CAD 176,000 - 273,000
HCSA (Health Care Spending Account)
Paid holidays and time off
Retirement matching plan
Clinical Program Manager
Clinical Program Manager

Sonus microsystems Inc. • Vancouver

On-site
CAD 90,000 - 130,000
Equity stock options
Flexible work environment
Autonomy & trust
+1
Manufacturing Engineering Quality Assurance Manager
Manufacturing Engineering Quality Assurance Manager

Sonova Group • Kitchener

Hybrid
CAD 76,000 - 95,000
Wellness benefit
Paramedical coverage
Pension matching
+3
Clinical Program Manager
Clinical Program Manager

Sonus Microsystems • Vancouver

Hybrid
CAD 110,000 - 160,000
Equity (stock options)
Flexibility
Autonomy
+1