×
Register Here to Apply for Jobs or Post Jobs. X

Sr Product Security Engineer

Job in Irvine, Orange County, California, 92616, USA
Listing for: Sunrise Systems
Seasonal/Temporary position
Listed on 2026-08-31
Job specializations:
  • IT/Tech
    Cybersecurity, Information Security & Data Protection
Salary/Wage Range or Industry Benchmark: 105 - 115 USD Hourly USD 105.00 115.00 HOUR
Job Description & How to Apply Below

Sr Product Security Engineer

Our client, a leading Medical Device Manufacturing Company is looking for a Sr Product Security Engineer for an initial duration of 12 Months Contract – Remote Role. This role is focused on risk-based security that ensures patient safety, data protection, and regulatory readiness.

Job Description:

  • Temp to Perm possibility but that depends on experience
  • Sr Product Security Engineer to support Client's STS business unit and develop AI powered skills, agents, and services.
  • The Client portfolio includes FDA Class I and Class II medical devices and their associated cloud-connected platforms, on premise deployed software, and hosted applications.
  • The Sr Product Security Engineer owns, leads, and executes the activities and documentation outlined in Client's security lifecycle.
  • In addition, the use and development of AI tools/capabilities require the candidate to have both strategic and tactical experience in building with AI.

Role Focus:

  • Execution of Product Security Engineering Lifecycle activities
  • Building AI based skills, agents, services, and platforms
  • Integration of AI driven capabilities into product development life cycles
  • Generation and Maintenance of Product Security Documentation
  • Apply risk-proportionate security controls
  • Emphasize secure-by-design and secure-by-default
  • Balance usability, workflow, and security

Key Responsibilities:

  • Security Engineering, Architecture & Design
  • Define end-to-end security engineering/design/solutions/controls across devices, apps, and cloud
  • Establish baseline security patterns (auth, encryption, secure updates)
  • Conduct Threat Modeling, Risk Assessments, Requirements/Controls Mapping, Security White Papers
  • Lead and Drive Security Design Reviews & Roadmap Remediations/Mitigations
  • Perform architecture risk analysis on device/cloud boundaries: trust boundary decomposition, data flow diagrams, attack surface enumeration, and abuse/misuse case development
  • Develop AI skills, agents, services

Secure SDLC:

  • Implement lean Secure SDLC aligned to NIST, OWASP, and BSIMM
  • Integrate SAST, SCA, secrets scanning, container/IaC scanning
  • Define minimum viable security gates

Regulatory & Compliance:

  • Support FDA cybersecurity documentation (threat models, SBOMs, risk assessments)
  • Align with IEC 62304, ISO 14971
  • Ensure audit-ready documentation

Cloud Security:

  • Design secure integrations with Client's Cloud Platforms
  • Secure device-to-cloud data flows

SBOM & Vulnerability Management:

  • Establish SBOM processes (SPDX, CycloneDX)
  • Implement continuous vulnerability monitoring
  • Define risk-based remediation SLAs

Cross-Functional Leadership:

  • Collaborate with engineering, quality, regulatory, and product teams
  • Translate security into patient safety and business risk
  • Mentor teams

Required Qualifications:

  • 5+ years cybersecurity experience
  • Software Development, System Engineering background
  • AI (Agentic, Generative, ML) skills and agent development
  • Regulatory/Quality Control product development
  • Demonstrated working experience in the domains of embedded, cloud, and application security

Preferred Qualifications:

  • Experience with FDA Class I/II devices and FDA submissions
  • Experience with IoMT ecosystems
  • Knowledge of FDA Cybersecurity Pre & Post Market Guidance, UL 2900, AAMI TIR
    57/TIR
    97
  • Dev Sec Ops  experience
  • Certifications (CISSP, CCSP, CSSLP)

Key

Competencies:

  • Ability to right-size security controls
  • Strong risk-based decision-making
  • Communication across technical and non-technical teams
  • Ability to perform manual secure code review and triage SAST findings for exploitability, tuning rules to drive false-positive rates down rather than escalating raw tool output
  • Produce and consume VEX (CSAF, OpenVEX) alongside SBOMs; maintain component provenance and transitive dependency accuracy
  • Depth in web/API security beyond OWASP Top 10: OWASP ASVS levels as requirement source, API Top 10, authorization logic flaws (IDOR, broken object-level and function-level authz), SSRF, deserialization, app security in multi-tenant context
  • Design and review authentication/authorization implementations: OAuth 2.0/OIDC flow selection and misuse, token lifetime and revocation, session management, SAML assertion validation
  • Demonstrated ability to read and write production code in at least one systems language

Success Metrics:

  • Comprehensive Threat Modeling and effective Security Risk Management
  • SBOM completeness
  • Reduction in critical vulnerabilities
  • FDA submission success
  • Time-to-remediate vulnerabilities

Compensation:
The hourly rate for this position is between $105.00-$115.00 per hour. Benefits:
Sunrise offers ACA compliant medical coverage/dental insurance/vision insurance to all employees. We also offer Sick time benefits as required per State regulations.

To View & Apply for jobs on this site that accept applications from your location or country, tap the button below to make a Search.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
 
 
 
Search for further Jobs Here:
(Try combinations for better Results! Or enter less keywords for broader Results)
Location
Increase/decrease your Search Radius (miles)
0
200
Filters
Education Level
Experience Level (years)
Posted in last:
Salary