Staff DevSecOps Engineer– Medical Devices
Listed on 2026-08-21
-
IT/Tech
Cybersecurity, Information Security & Data Protection, Cloud Computing: Infrastructure & Operations, AWS
Staff Dev Sec Ops Engineer– Medical Devices
The Health Solutions Business Unit at Analog Devices is seeking a Dev Sec Ops Engineer to support the development and operation of secure cloud-native platforms for connected medical devices and digital health solutions.
The successful candidate will contribute to the implementation of secure software development practices, cloud security controls, software supply chain security, and regulatory compliance activities throughout the product lifecycle. This role requires strong experience with AWS cloud environments, CI/CD pipelines, application security, and healthcare software platforms, along with deep expertise in HIPAA compliance, healthcare data protection, cloud security, and cybersecurity requirements for FDA-regulated medical devices.
The ideal candidate is a hands-on engineer with experience securing modern cloud applications, automating security processes, and supporting regulated software products from development through deployment and post-market operations.
Key Responsibilities
- Implement and maintain security controls across AWS cloud environments supporting connected medical devices, Software as a Medical Device (SaMD), and digital health solutions.
- Integrate and manage security capabilities within CI/CD pipelines and Secure Software Development Lifecycle (SSDLC) processes, including secure coding practices, SAST, DAST, SCA, secrets scanning, container security scanning, and Infrastructure-as-Code security validation.
- Manage software supply chain security activities, including SBOM generation, dependency management, artifact integrity validation, and vulnerability remediation.
- Configure and maintain identity and access management, authentication, authorization, encryption, key management, and secrets management solutions across cloud and application environments.
- Design and maintain audit logging, monitoring, and security controls supporting HIPAA compliance and healthcare data protection requirements.
- Partner with software engineering teams to identify, prioritize, and remediate security vulnerabilities throughout the product lifecycle.
- Support security risk assessments, penetration testing activities, vulnerability management, incident response, and operational security efforts.
- Build and maintain security automation capabilities to improve platform security, compliance, and operational efficiency.
- Support the reliability, availability, monitoring, and operational readiness of cloud-based production systems.
Requirements
- Bachelor's, Master's, or Ph.D. degree in Cybersecurity, Computer Science, Software Engineering, Computer Engineering, Information Security, or a related technical discipline.
- 7+ years of experience in Dev Sec Ops , Cloud Security, Security Engineering, Application Security, or related technical roles.
- Experience supporting software development for healthcare products, medical devices, or digital health solutions within established quality and compliance frameworks.
- Strong experience securing cloud-native applications and platforms running on AWS.
- Hands-on experience with AWS services such as ECS, EKS, Lambda, RDS, S3, SQS, Cognito, IAM, KMS, Cloud Formation, and related cloud technologies.
- Experience implementing and managing CI/CD pipelines using Git Hub Actions or similar platforms.
- Experience with security tooling including SAST, DAST, SCA, container security scanning, secrets detection, Infrastructure-as-Code security scanning, and vulnerability management solutions.
- Strong understanding of application security principles, secure coding practices, authentication, authorization, encryption, secrets management, and key management.
- Experience with software supply chain security concepts, including SBOM generation, dependency management, artifact signing, and vulnerability remediation.
- Experience with Infrastructure as Code technologies such as Terraform, Cloud Formation, or AWS CDK.
- Strong understanding of OWASP guidance, cloud security best practices, and secure software development methodologies.
- Experience with containerized applications and orchestration platforms such as ECS, EKS, Kubernetes, or similar technologies.
- Experience…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).