Product Security Manager
The Product Security Manager plays a critical role in safeguarding the company's reputation, protecting patient data and maintaining trust among customers and stakeholders throughout the product lifecycle.
Responsibilities
- Develop and implement an end-to-end Secure Development Lifecycle that incorporates cybersecurity and privacy by design principles into all products from pre-market to post-market phases.
- Collaborate with cross-functional teams including engineering, product management and regulatory affairs to develop a DevSecOps pipeline and culture.
- Conduct thorough third-party vendor and supply chain risk assessments to identify potential security threats and develop mitigation strategies.
- Ensure compliance with industry standards and regulations such as GDPR, HIPAA, NIST and FDA cybersecurity guidelines.
- Design and deliver training programs to educate employees on product security best practices.
Key Networking / Relationships
- Engage with senior directors for strategic planning and risk management.
- Work closely with Product Security Director and Data Privacy Officers to align security and privacy compliance programs.
- Guarantee harmonization of processes across different business units with Product Security Officers.
- Define product security procedures with Regulatory Affairs.
- Provide support on Secure Development Lifecycle to Engineering departments.
- Support security testing with Quality Assurance department.
Essential Skills & Qualifications
- Possess an engineer, computer science or other technical degree, or equivalent work experience.
- Hold 7+ years of experience in product security with at least 2 years in a leadership or management position.
- Have 3+ years of software development experience.