Senior Product Cybersecurity Engineer
Listed on 2026-07-29
-
Security
Cybersecurity
Who We Are
Samsung HME America (Healthcare and Medical Equipment) is Samsung’s U.S. medical imaging organization, delivering advanced diagnostic solutions across Ultrasound, Digital Radiography, and Computed Tomography. We lead nationwide sales, marketing, service, and distribution of Samsung’s imaging technologies, partnering with healthcare providers to strengthen diagnostic capabilities, streamline clinical workflows, and support better patient care. Samsung HME America also serves as the global manufacturing center for Samsung’s mobile Computed Tomography (mCT) business, leading the development of advanced CT systems used by healthcare providers worldwide.
Backed by Samsung Electronics’ global technology leadership, our teams work closely with clinicians to translate real-world challenges into innovative imaging solutions. Our culture combines a sense of urgency, customer focus, and clinical collaboration to advance the future of medical imaging.
On-site in Danvers, MA
Role DescriptionResponsible for ensuring that Samsung Healthcare’s medical imaging devices are designed, developed, and maintained to protect against cybersecurity threats throughout the product lifecycle. Responsible for cybersecurity risk management, secure product development, DoD Risk Management Framework (RMF) compliance, vulnerability management and support of FDA and other global cybersecurity regulatory requirements.
Key Duties And Responsibilities, Other Duties May Be Assigned- Lead product cybersecurity incident response activities and coordinate technical escalations from customers, service teams and internal stakeholders.
- Maintain and support Department of Defense Risk Management Framework (RMF) compliance, including Authorization to Operate (ATO) packages, security documentation, continuous monitoring activities and Plan of Action & Milestones (POAM) management.
- Perform cybersecurity risk assessments, including asset identification, threat modeling, vulnerability analysis, and security control evaluation for medical devices.
- Collaborate with R&D teams to integrate cybersecurity throughout the secure software development lifecycle (SSDLC) and ensure traceability between cybersecurity requirements, risks, mitigations, verification activities and design documentation.
- Complete RFPs, RFQs, and security questionnaires during the sales process, and respond to customer cybersecurity inquiries.
- Support cybersecurity verification and validation activities, including penetration testing, vulnerability assessments, security testing and remediation verification.
- Coordinate vulnerability management activities including security advisories, CVE assessments, software bill of materials (SBOM) review, patch evaluation, remediation planning and security updates for all products.
- Engage customers, government agencies, and other stakeholders to ensure compliance with cybersecurity requirements and define best practices.
- Collaborate with sales and marketing to integrate cybersecurity as part of go‑to‑market strategy.
- Stay current on applicable security laws, regulations and industry standards.
- Maintain technical knowledge of Samsung Healthcare products and associated cybersecurity architecture.
- Work independently with minimal supervision, and collaboratively as part of a cross‑functional team.
- Effectively manage priorities while balancing technical, regulatory and business objectives.
To perform this job successfully, an individual must be able to perform each essential duty satisfactorily. The requirements listed below are representative of the knowledge, skill, and/or ability required. Reasonable accommodation may be made to enable individuals with disabilities to perform the essential functions.
Education & Experience- Bachelor's degree in Computer Science, Cybersecurity, Computer Engineering, Information Systems, or a related technical field.
- 5+ years of experience in a hands‑on security engineering role.
- Experience with ANSI/AAMI TIR
57, UL 2900, ISO 14971, IEC 62304, IEC 81001‑5‑1 and IEC/TR 80001‑2‑2. - Extensive knowledge of FDA medical device cybersecurity guidance, NIST cybersecurity frameworks, FIPS…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).