Sr Product Security Engineer
Listed on 2026-08-31
-
IT/Tech
Cybersecurity, Information Security & Data Protection
Sr Product Security Engineer
Our client, a leading Medical Device Manufacturing Company is looking for a Sr Product Security Engineer for an initial duration of 12 Months Contract – Remote Role. This role is focused on risk-based security that ensures patient safety, data protection, and regulatory readiness.
Job Description:
- Temp to Perm possibility but that depends on experience
- Sr Product Security Engineer to support Client's STS business unit and develop AI powered skills, agents, and services.
- The Client portfolio includes FDA Class I and Class II medical devices and their associated cloud-connected platforms, on premise deployed software, and hosted applications.
- The Sr Product Security Engineer owns, leads, and executes the activities and documentation outlined in Client's security lifecycle.
- In addition, the use and development of AI tools/capabilities require the candidate to have both strategic and tactical experience in building with AI.
Role Focus:
- Execution of Product Security Engineering Lifecycle activities
- Building AI based skills, agents, services, and platforms
- Integration of AI driven capabilities into product development life cycles
- Generation and Maintenance of Product Security Documentation
- Apply risk-proportionate security controls
- Emphasize secure-by-design and secure-by-default
- Balance usability, workflow, and security
Key Responsibilities:
- Security Engineering, Architecture & Design
- Define end-to-end security engineering/design/solutions/controls across devices, apps, and cloud
- Establish baseline security patterns (auth, encryption, secure updates)
- Conduct Threat Modeling, Risk Assessments, Requirements/Controls Mapping, Security White Papers
- Lead and Drive Security Design Reviews & Roadmap Remediations/Mitigations
- Perform architecture risk analysis on device/cloud boundaries: trust boundary decomposition, data flow diagrams, attack surface enumeration, and abuse/misuse case development
- Develop AI skills, agents, services
Secure SDLC:
- Implement lean Secure SDLC aligned to NIST, OWASP, and BSIMM
- Integrate SAST, SCA, secrets scanning, container/IaC scanning
- Define minimum viable security gates
Regulatory & Compliance:
- Support FDA cybersecurity documentation (threat models, SBOMs, risk assessments)
- Align with IEC 62304, ISO 14971
- Ensure audit-ready documentation
Cloud Security:
- Design secure integrations with Client's Cloud Platforms
- Secure device-to-cloud data flows
SBOM & Vulnerability Management:
- Establish SBOM processes (SPDX, CycloneDX)
- Implement continuous vulnerability monitoring
- Define risk-based remediation SLAs
Cross-Functional Leadership:
- Collaborate with engineering, quality, regulatory, and product teams
- Translate security into patient safety and business risk
- Mentor teams
Required Qualifications:
- 5+ years cybersecurity experience
- Software Development, System Engineering background
- AI (Agentic, Generative, ML) skills and agent development
- Regulatory/Quality Control product development
- Demonstrated working experience in the domains of embedded, cloud, and application security
Preferred Qualifications:
- Experience with FDA Class I/II devices and FDA submissions
- Experience with IoMT ecosystems
- Knowledge of FDA Cybersecurity Pre & Post Market Guidance, UL 2900, AAMI TIR
57/TIR
97 - Dev Sec Ops experience
- Certifications (CISSP, CCSP, CSSLP)
Key
Competencies:
- Ability to right-size security controls
- Strong risk-based decision-making
- Communication across technical and non-technical teams
- Ability to perform manual secure code review and triage SAST findings for exploitability, tuning rules to drive false-positive rates down rather than escalating raw tool output
- Produce and consume VEX (CSAF, OpenVEX) alongside SBOMs; maintain component provenance and transitive dependency accuracy
- Depth in web/API security beyond OWASP Top 10: OWASP ASVS levels as requirement source, API Top 10, authorization logic flaws (IDOR, broken object-level and function-level authz), SSRF, deserialization, app security in multi-tenant context
- Design and review authentication/authorization implementations: OAuth 2.0/OIDC flow selection and misuse, token lifetime and revocation, session management, SAML assertion validation
- Demonstrated ability to read and write production code in at least one systems language
Success Metrics:
- Comprehensive Threat Modeling and effective Security Risk Management
- SBOM completeness
- Reduction in critical vulnerabilities
- FDA submission success
- Time-to-remediate vulnerabilities
Compensation:
The hourly rate for this position is between $105.00-$115.00 per hour. Benefits:
Sunrise offers ACA compliant medical coverage/dental insurance/vision insurance to all employees. We also offer Sick time benefits as required per State regulations.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).