Lead Cybersecurity Engineer (Biotech) (FDA)

Red Oak Technologies

Pleasanton (CA)

Hybrid

USD 179,000 - 210,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Red Oak Technologies is seeking a Cybersecurity Lead Engineer to own the product cybersecurity program across the portfolio, integrating FDA, NIST, and ISO requirements while guiding cross‑functional teams.

This full‑time hybrid role is based in Pleasanton or Irvine and leads PSIRT, vulnerability management, and regulatory alignment, with opportunities to scale security programs within a collaborative environment.

Qualifications

  • Bachelor’s degree in Computer Science, Information Security, Engineering or a related field.
  • 7+ years of cybersecurity experience in regulated environments (FDA/healthcare/medical devices).
  • Deep expertise in medical device cybersecurity and FDA pre/postmarket requirements.
  • Knowledge of NIST CSF 2.0, ISO 81001 5 1, ISO/IEC TS 27110, ISO/IEC 27032.
  • Proven ability to lead cross-functional programs in matrixed organizations.
  • Strong technical judgment and executive presence.

Responsibilities

  • Own and evolve the Product Cybersecurity Program including PSIRT governance and escalation paths.
  • Align with FDA medical device cybersecurity expectations across premarket and postmarket requirements.
  • Define cybersecurity framework aligned to major standards and integrate with Global IT security practices.
  • Embed cybersecurity requirements into the Global Quality Management System (QMS).
  • Lead the Cross Functional Cybersecurity Core Team and guide product teams for secure design and development.
  • Oversee vulnerability management, incident investigations, and regulatory timelines.
  • Drive regulatory communications and disclosures with regulators and researchers.
  • Track and report program cybersecurity metrics to leadership.

Skills

Cybersecurity leadership
Regulatory compliance
NIST CSF 2.0 knowledge
ISO 81001/ISO/IEC 27032 knowledge
Cross-functional leadership
Executive communication

Education

Bachelor’s degree in Computer Science/Engineering/Info Security
Master’s degree (preferred)

Job description

Since 1995, Red Oak Technologies has been a trusted partner in the tech industry, delivering innovative talent solutions that drive progress. We specialize in quickly acquiring and efficiently matching top-tier professional talent with clients in immediate need of highly skilled contract, permanent or project management based resources.

Position: Cybersecurity Lead Engineer

Role: Full time Hybrid

Location: Pleasanton,, CA or Irvine, CA

Base Salary: $179-210K Depending on experience

The Technical Leader for the Product Cybersecurity Program and Product Security Incident Response Team (PSIRT) provides leadership for medical device cybersecurity across company's portfolio. This role owns the strategy, governance, and execution of the product cybersecurity program, ensuring compliance with FDA cybersecurity requirements and global standards while driving program maturity across the organization and product lifecycle. This position serves as the authoritative technical leader for product cybersecurity, accountable for vulnerability management, incident response, regulatory alignment, and cross functional coordination. The role operates at the program level, enabling and guiding product teams rather than replacing their functional ownership.

How You'll Make An Impact
  • Own and evolve the Product Cybersecurity Program, including PSIRT governance, operating model, decision authority, and escalation paths.
  • Establish and maintain alignment with FDA medical device cybersecurity expectations, including premarket and post-market requirements for vulnerability management, coordinated disclosure, and incident response.
  • Define and maintain the cybersecurity framework aligned to NIST CSF 2.0, ISO 81001 5 1, ISO/IEC TS 27110, and ISO/IEC 27032, and ensure integration with Global IT security practices.
  • Embed product cybersecurity requirements into the Global Quality Management System (QMS), including Design Controls, risk management, and change management.
Cross Functional Enablement
  • Lead the cross functional Cybersecurity Core Team, ensuring sustained engagement and prioritization across R&D, Software, Systems, QA/RA, Global Supply Chain (Manufacturing and Procurement), and Global Information Security.
  • Provide clear expectations, guidance, and oversight to product teams for secure design, development, and maintenance, without assuming direct development ownership.
  • Ensure cybersecurity considerations are integrated throughout the product lifecycle, from concept and design through post market support.
Vulnerability & Incident Management (PSIRT)
  • Serve as the single point of accountability for product cybersecurity intake, triage, and prioritization.
  • Oversee end to end vulnerability management, including risk assessment, remediation planning, regulatory timelines, and customer deployment.
  • Lead technical coordination for cybersecurity incident investigations, containment, and remediation, ensuring timely and effective response to high severity issues.
  • Guide product teams on mitigations, patches, and workarounds to ensure security and regulatory expectations are met.
Regulatory & External Communication
  • Ensure cybersecurity incidents and disclosures comply with FDA, international regulatory, and internal quality requirements.
  • Oversee the development and approval of security advisories, customer notifications, and regulatory communications.
  • Act as the technical authority in engagements with external security researchers, customers, regulators, and industry groups.
  • Drive cybersecurity awareness and training for R&D, Support, and Quality teams to reinforce a security first culture.
  • Define, track, and report program level cybersecurity and PSIRT performance metrics to leadership.
  • Continuously improve program effectiveness based on metrics, lessons learned, and evolving regulatory expectations.
What You Bring
  • Bachelor’s degree in Computer Science, Information Security, Engineering or a related field.
  • 7+ years of experience in cybersecurity, including architecture design in a regulated environment (preferably FDA, healthcare, or medical devices).
  • A system thinker with deep expertise in medical device cybersecurity, including FDA premarket and post market cybersecurity requirements.
  • Expert knowledge of NIST CSF 2.0, ISO 81001 5 1, ISO/IEC TS 27110, and ISO/IEC 27032.
  • Proven ability to lead cross functional programs in complex, matrixed organizations.
  • Strong technical judgment, communication skills, and executive presence.
  • Demonstrated ability to build, mature, and scale cybersecurity programs across organizations.
  • Preferred: Master’s degree in a technical field.
  • Experience with cloud-based systems, IoT security, or medical device security.

Location: This position must be based in Hercules, CA or Irvine, CA and requires the employee to be located within commuting distance of the office.

Red Oak Technologies is made up of people from a wide variety of backgrounds and lifestyles. We embrace diversity and invite applications from people of all walks of life.

Red Oak Five (Core Values): Relationships First | Exceptional Quality and Service | Unwavering Integrity and Trust | Be Easy To Do Business With | Respect Everyone

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Product Cybersecurity Lead | PSIRT & FDA Alignment
Product Cybersecurity Lead | PSIRT & FDA Alignment

Red Oak Technologies • Pleasanton (CA)

Hybrid
USD 179,000 - 210,000
Software Developer V
Software Developer V

Tri-Valley Career Center • Hercules (CA)

On-site
USD 179,000 - 247,000
Medical plans
Employee stock purchase program
Parental leave
+1
Senior Product Cybersecurity Program Lead
Senior Product Cybersecurity Program Lead

Tri-Valley Career Center • Hercules (CA)

On-site
USD 179,000 - 247,000
Medical plans
Employee stock purchase program
Parental leave
+1
Product Security Architect (Medical Device)
Product Security Architect (Medical Device)

Beacon Hill • San Diego (CA)

On-site
USD 120,000 - 160,000
Product Security Engineer - Medical Device
Product Security Engineer - Medical Device

BioTalent • San Diego (CA)

Hybrid
USD 90,000 - 120,000
Senior Product Security Engineer
Senior Product Security Engineer

Intellias • Newton (MA)

On-site
USD 120,000 - 180,000
Cyber Security Engineer
Cyber Security Engineer

Insight Global • Irvine (CA)

On-site
Medical insurance
Vision insurance
401(k)
Cybersecurity Software Engineer
Cybersecurity Software Engineer

Meridian Bioscience Inc. • United States

On-site
USD 110,000 - 160,000
Senior Quality Engineer, Cybersecurity
Senior Quality Engineer, Cybersecurity

Jobtailor • California (MO)

On-site
USD 120,000 - 180,000
Principal Engineer, Product Cybersecurity
Principal Engineer, Product Cybersecurity

Jobtailor • Illinois

On-site
USD 120,000 - 165,000