Position Overview :
We are seeking an Engineering Manager focused on Product Security to lead a dynamic team responsible for developing, implementing, and monitoring security solutions for Org’s devices and infrastructure. This role requires a strategic thinker with strong leadership skills to drive product security initiatives, ensure compliance with regulatory standards, and foster collaboration across various teams.
Key Responsibilities :
- Lead and manage a team of engineers and cybersecurity professionals dedicated to product security for medical devices.
- Execute a comprehensive Product Security strategy aligned with Company’s business objectives and regulatory requirements.
- Collaborate with cross-functional global teams (R&D, quality assurance, and regulatory affairs) to integrate security practices throughout the product lifecycle.
- Oversee the identification and remediation of vulnerabilities, ensuring timely and effective incident response.
- Monitor industry trends and emerging technologies to inform security strategies and practices.
- Communicate complex security concepts clearly to diverse stakeholders, including executive leadership, customers, and regulatory bodies.
- Foster a culture of security awareness and continuous improvement within the team and across the organization.
- Manage project timelines, budgets, and resources to ensure successful delivery of product security initiatives.
- Drive best-in-class Product Security design for new product development, and released products, ensuring scalable and risk-mitigated designs.
- Execute risk-based security assessment processes and implement them across product efforts.
- Build and sustain a product security team capable of assessing and testing new and released products that transcend technology (ex. embedded, mobile, web application…)
Must Have Skills :
16+ years of experience in engineering or cybersecurity with at least 5+ years in leadership rolesProven expertise in product and device security (embedded systems, IoT, mobile / web integration)Experience designing or reviewing secure software / hardware architectureProficient in cybersecurity frameworks : NIST, ISO / IEC 27001, 62443, 14971, 13485Solid grasp of threat modeling, secure SDLC, risk assessment, code reviews, fuzz testingFamiliarity with tools : SAST / DAST, vulnerability scanners, SBOM management, PKI