Product Security Manager

El Camino Health

United States

On-site

USD 127,000 - 165,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

iRhythm Technologies is looking for a Senior Product Security Engineer to ensure the protection of patient data and device integrity. The role involves collaborating with various teams to maintain FDA cybersecurity compliance and perform comprehensive risk assessments. Ideal candidates will have a background in information security specific to medical devices, alongside experience in regulated environments. This position is remote within the United States, offering a salary range of $127,000 to $165,000. Join us to help shape the future of cardiac health solutions.

Qualifications

  • 6+ years of experience in information security, focusing on product security.
  • Strong understanding of security principles and methodologies within the PDLC and SDLC.
  • Experience in a regulated environment like FDA, HIPAA, or GDPR.

Responsibilities

  • Ensure compliance with FDA cybersecurity guidance.
  • Conduct comprehensive cybersecurity risk assessments.
  • Develop and maintain device-specific cyber threat models.

Skills

Product security for medical devices
Information security
Cybersecurity Risk Assessments (CSRAs)
Vulnerability analysis
NIST Cybersecurity Framework

Education

Bachelor’s degree in Computer Science, Information Security, or related field

Tools

Veracode
Snyk
GitLab

Job description

Senior Product Security Engineer page is loaded## Senior Product Security Engineerremote type: Fully Remotelocations: Remote - UStime type: Full timeposted on: Posted 2 Days Agojob requisition id: JR1359**Career-defining. Life-changing.**At iRhythm, you’ll have the opportunity to grow your skills and your career while impacting the lives of people around the world. iRhythm is shaping a future where everyone, everywhere can access the best possible cardiac health solutions. Every day, we collaborate, create, and constantly reimagine what’s possible. We think big and move fast, driven by our commitment to put patients first and improve lives. We need builders like you. Curious and innovative problem solvers looking for the chance to meaningfully shape the future of cardiac health, our company, and your career**About This Role:**We are seeking a Senior Product Security Engineer with medical device experience who will ensure robust protection of patient data, device integrity, and regulatory compliance. In this role, you will partner with engineering, product management, regulatory, quality, and privacy teams to embed security across the product lifecycle, drive continuous improvement in alignment with FDA cybersecurity and product security requirements.**Key Responsibilities*** **FDA Cybersecurity Compliance**: Ensure compliance with FDA cybersecurity guidance and regulations in collaboration with Cybersecurity, Regulatory, Quality, and Systems Development teams.* **Risk Assessments & CSRAs**: Conduct comprehensive security risk assessments, including **Cybersecurity Risk Assessments (CSRAs)**, to identify vulnerabilities and threats across device hardware, firmware, software, and cloud components.* **Threat Modeling**: Develop and maintain device-specific cyber threat models, factoring in patient safety, data privacy, and operational continuity.* **SBOM Management**: Demonstrate familiarity with Software Bill of Materials (SBOM) and effectively communicate technical details.* **Security Documentation**: Create and maintain cybersecurity documentation for pre- and post-market activities, ensuring regulatory alignment.* **Data Flow Diagrams**: Produce detailed data flow diagrams to support the threat modeling process.* **Security Design Reviews**: Participate in design reviews of medical device architectures and implementations, providing actionable recommendations for system security requirements.* **Vulnerability Analysis & Management**: Perform and support **vulnerability analysis** and coordinate the vulnerability management program, including scanning, patching, and remediation for medical devices.* **Threat Detection Tools**: Leverage and maintain **application and threat detection tools** (Veracode, Snyk, GitLab, or equivalent) to identify security flaws early in the SDLC.* **Incident Response**: Support investigation and remediation of device-related security incidents, minimizing impact and preventing recurrence.* **Data Privacy Compliance**: Partner with the Privacy Team to ensure adherence to HIPAA, GDPR, and other data protection regulations.**Required Qualifications*** Bachelor’s degree in Computer Science, Information Security, or related field.* 6+ years of experience in information security, with direct focus on **product security for medical devices**.* Strong understanding of security principles, methodologies, and tools within the PDLC and SDLC.* Demonstrated experience conducting **Cybersecurity Risk Assessments (CSRAs)**, **vulnerability analysis**, and working with modern threat detection tools (Veracode, Snyk, GitLab, or similar).* Familiarity with **NIST Cybersecurity Framework, NIST SP 800-171, and deeper controls/frameworks such as NIST SP 800-53 (Security and Privacy Controls), NIST SP 800-92 (Log Management), and NIST SP 800-63 (Digital Identity Guidelines).*** Hands-on experience with vulnerability identification and threat modeling within healthcare using methodologies such as STRIDE.* **Experience operating in a regulated environment** (FDA, HIPAA, GDPR, international regulatory frameworks).* **Experience with medical device hardware or Software as a Medical Device (SaMD).*** Experience with medical device software development and regulatory processes.* Excellent problem-solving, analytical, and communication skills, able to take a multi-siloed approach.* Ability to understand intro dependencies of teams across; mobile applications, hardware and cloud environments.* Demonstrated experience supporting 510(k) submissions, with a focus on product security documentation, risk assessments, and regulatory compliance.**Preferred Qualifications*** Industry certifications such as CISSP, CISM, CISA, or medical device security–specific certifications.* Experience with international frameworks and standards (EU MDR, JIS T 2304 / IEC 62304).* Understanding penetration testing methodologies and tools, able to work with pen test teams independently with little guidance.* Proficiency with programming languages and technologies commonly used in medical device development.**Location:**Remote - USActual compensation may vary depending on job-related factors including knowledge, skills, experience, and work location.**Estimated Pay Range**$127,000.00 - $165,000.00As a part of our core values, we ensure an inclusive workforce. We welcome and celebrate people of all backgrounds, experiences, skills, and perspectives. iRhythm Technologies, Inc. is an Equal Opportunity Employer. We will consider for employment all qualified applicants with arrest and conviction records in accordance with all applicable laws.iRhythm provides reasonable accommodations for qualified individuals with disabilities in job application procedures, including those who may have any difficulty using our online system. If you need such an accommodation, you may contact us at taops@irhythmtech.com**About iRhythm Technologies** iRhythm is a leading digital healthcare company that creates trusted solutions that detect, predict, and prevent disease. Combining wearable biosensors and cloud-based data analytics with powerful proprietary algorithms, iRhythm distills data from millions of heartbeats into clinically actionable information. Through a relentless focus on patient care, iRhythm’s vision is to deliver better data, better insights, and better health for all.**Make iRhythm your path forward. Zio, the heart monitor that changed the game.**There have been instances where individuals not associated with iRhythm have impersonated iRhythm employees pretending to be involved in the iRhythm recruiting process, or created postings for positions that do not exist. Please note that all open positions will always be shown here on the iRhythm Careers page, and all communications regarding the application, interview and hiring process will come from a @irhythmtech.com email address. Please check any communications to be sure they come directly from @irhythmtech.com email address. If you believe you have been the victim of an imposter or want to confirm that the person you are communicating with is legitimate, please contact taops@irhythmtech.com. Written offers of employment will be extended in a formal offer letter from an @irhythmtech.com email address **ONLY**.For more information, see andAt iRhythm, you'll have the opportunity to grow your skills and your career while impacting the lives of people around the world. Together, we are reimagining the way cardiac arrhythmias are diagnosed. We need curious problem solvers like you. With opportunities remotely, at our office, in manufacturing, and in locations across the globe, this is your chance to meaningfully shape the future of cardiac health, our company, and your career.**Driven By Purpose** - Cardiac health touches the lives of people all around us. Providing life-changing healthcare solutions that impact patients around the world drives
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Cyber Security Analyst, Application & Infrastructure
Senior Cyber Security Analyst, Application & Infrastructure

El Camino Health • San Francisco (CA)

On-site
USD 127,000 - 165,000
Senior Product Security Manager
Senior Product Security Manager

iRhythm Technologies, Inc. • San Francisco (CA)

On-site
USD 173,000 - 225,000
Senior Embedded Software Test Engineer
Senior Embedded Software Test Engineer

El Camino Health • California (MO)

Hybrid
USD 115,000 - 149,000
Manager, Environmental Health and Safety & Sustainability (EHS&S)
Manager, Environmental Health and Safety & Sustainability (EHS&S)

El Camino Health • Cypress (CA)

On-site
USD 115,000 - 149,000
Medical, dental, and vision insurance
401K with company match
Paid parental leave
+1
Remote Senior IoT Mobile Systems Engineer
Remote Senior IoT Mobile Systems Engineer

iRhythm Technologies, Inc. • United States

On-site
Key Account Manager - Greensboro, NC
Key Account Manager - Greensboro, NC

El Camino Health • Greensboro (NC), Northern (KY)

On-site
USD 83,000 - 108,000
Medical, dental, and vision insurance
401(k) with company match
Paid time off and holidays
Territory Manager | Lexington, Kentucky
Territory Manager | Lexington, Kentucky

El Camino Health • Lexington (KY)

On-site
USD 90,000 - 180,000
Key Account Manager - West Virginia
Key Account Manager - West Virginia

El Camino Health • West Virginia

On-site
USD 83,000 - 108,000
Medical, dental, vision insurance
401(k) with company match
Employee Stock Purchase Plan
+1
Territory Manager | North Sound, Washington
Territory Manager | North Sound, Washington

El Camino Health • Seattle (WA)

On-site
USD 90,000 - 180,000
Medical, dental, and vision coverage
Generous PTO and paid holidays
401(k) with company match
+2
Territory Manager | Sacramento, California
Territory Manager | Sacramento, California

El Camino Health • San Francisco (CA)

On-site
USD 90,000 - 180,000
Competitive compensation package
Medical, dental, and vision coverage
Generous PTO and paid holidays
+2