Product Security Engineer Cincinnati, OH
Title: Product Security Engineer
Job Type: Permanent
Primary Location: Cincinnati, OH or any other USA based location
Vignetic is looking for a Product Security Engineer to provide support for implementation of Product Security strategy and framework throughout the R&D portfolio of medical devices. This includes identifying key strategy and goals, collaborating with internal organizations on existing process and policy enhancements, creating and communicating metrics to senior management, identifying communications plans and raising overall awareness of the capability.
Roles & Responsibilities:
- Supporting R&D throughout a new product’s development phases, review product security requirements and recommend security design solutions, help complete Quality documentation, threat modelling, penetration testing, software architecture review and design recommendations, code analysis and other security testing or work as needed.
- Post market responsibilities for marketed devices include monitoring for new vulnerabilities, assisting with patching and remediation plans, as well as responding to all customer security questionnaires and reviewing security language within contractual agreements.
- Support Global Product Security’s framework.
- Help drive Product Security strategy and goals.
- Partner with internal organizations to improve existing processes and policies.
- Create and present Product Security metrics to senior management.
- Help carry out Product Security governance model for pre and post market devices.
- Create remediation plans and assist the Ethicon engineering team with remediation.
- Respond to customer questionnaires and contractual language.
- Perform other work-related duties as assigned.
- A minimum of 6 years of experience in security and/or embedded software engineering functions is required.
- Intimate knowledge of real-time operating system (i.e. QNX, Linux, Windows Embedded) hardening techniques are required.
- Ability to provide secure coding recommendations is required.
- Knowledge in at least one coding language (i.e. C/C++, C#) with code review experience is required.
- Software engineering experience including securely building embedded applications is required.
- Ability to create and deliver Product Security awareness campaigns and other communications is required.
- Must possess understanding of pen testing, vulnerability scanning, CVSS and/or other general security testing principles with the ability to provide specific recommendations on how to fix resulting vulnerabilities.
- Understanding embedded operating system security patching and vulnerability assessment is required.
- Ability to work autonomously and proactively seek out security opportunities will be required.
- Big Picture/Attention to Detail – align strategic and tactical.
- Must be results oriented and ability to drive to timelines.
- Excellent interpersonal skills are required.
- Creative problem-solving skills and strong customer focus (internal & external) is required.
- Excellent communication and collaboration skills, able to network, interact and influence at all levels of the organization, cross sector, cross-functionally and globally is required.
- Must possess consistent record to influence/collaborate to get to desired result, and strong leadership skills are required.
- Knowledge of product or medical device security is preferred.
- Experience working with cloud based IoT management solutions is preferred.
- Understanding of Quality Design Control processes and FDA submission process is preferred.
- CISSP, CEH, MCSD, CSSLP or other certifications are preferred.
- MS and/or advanced degree is preferred.
Required Minimum Education:
- Minimum of a Bachelor’s degree is required.
- This role may require up to 10% travel.