SEE ALL VACANCIES

Product Security Engineer – Vulnerability Management (SBOM)

Vacancy details
Information Security
Security Engineer
Senior
United States
Office
APPLY NOW
REFER A FRIEND

What project we have for you

We are seeking a Senior Product Security Engineer to join a growing R&D organization focused on developing next-generation cardiac ablation and connected medical device solutions.

This role is centered around cybersecurity for medical devices, embedded systems, and connected healthcare technologies. It is not a traditional IT security, SOC, infrastructure, compliance, or GRC-focused position. Instead, we are looking for an engineer who understands how to build secure, reliable, and resilient medical products that operate safely in real-world clinical environments.

The ideal candidate brings hands-on experience working closely with engineering teams to integrate cybersecurity into embedded software, firmware, connected devices, and product development processes within regulated industries.

This position offers the opportunity to become one of the first dedicated Product Security Engineers within the team and collaborate globally with cross-functional engineering and cybersecurity organizations.

What you will do

Product Security Engineering

  • Partner with software, systems, firmware, and hardware engineering teams to integrate cybersecurity controls throughout the medical device development lifecycle.
  • Support secure-by-design initiatives across embedded and connected medical device platforms.
  • Help implement and validate security capabilities such as:
    • secure boot
    • secure communications
    • authentication and authorization
    • encryption and data protection
    • software update mechanisms
    • access control and system hardening

Risk Assessment & Threat Modeling

  • Conduct threat modeling and vulnerability assessments for medical devices and connected systems.
  • Identify, prioritize, and help mitigate cybersecurity risks across product architectures and system integrations.
  • Support vulnerability management activities and security remediation efforts.

Security Architecture & Engineering Collaboration

  • Contribute to the design and delivery of secure medical device architectures.
  • Collaborate closely with embedded, firmware, systems, cloud, and platform engineering teams to improve overall product security posture.
  • Provide pragmatic engineering guidance balancing cybersecurity, patient safety, usability, and product performance.

Regulatory & Industry Standards

  • Apply cybersecurity best practices and frameworks including:
    • NIST
    • OWASP
    • IEC 81001-5-1
    • ISO 14971
    • FDA cybersecurity guidance
  • Support security documentation and regulatory activities related to medical device cybersecurity.

Technical Leadership

  • Serve as a subject matter expert for product cybersecurity initiatives.
  • Mentor engineers and promote secure development practices across teams.
  • Stay current on emerging cybersecurity threats, vulnerabilities, and trends impacting medical devices and healthcare technologies.
  • Contribute to long-term product security strategy and cyber resilience initiatives.

What you need for this

Required Qualifications

  • Bachelor’s degree in Computer Science, Computer Engineering, Electrical Engineering, Cybersecurity, or a related technical field.
  • 4+ years of experience in Product Security, Embedded Security, Medical Device Security, or related cybersecurity engineering roles.
  • Experience securing embedded systems or connected devices within regulated industries.
  • Strong understanding of:
    • secure software development lifecycle (SSDLC)
    • threat modeling
    • vulnerability assessment
    • security-by-design principles
  • Familiarity with cybersecurity frameworks and standards such as NIST and OWASP.
  • Experience collaborating directly with engineering teams to identify and mitigate product security risks.
  • Strong communication and cross-functional collaboration skills.

 

Preferred Qualifications

  • Experience with cybersecurity for medical devices or healthcare technologies.
  • Familiarity with:
    • IEC 81001-5-1
    • ISO 14971
    • FDA premarket and post-market cybersecurity guidance
  • Experience supporting cybersecurity activities for FDA submissions or regulated product releases.
  • Exposure to connected healthcare systems or cloud-connected medical devices.
  • Experience with vulnerability management programs for embedded products.
  • Working knowledge of scripting languages such as Python or Bash.
  • Security certifications such as:
    • CISSP
    • CompTIA Security+
    • GIAC
    • CEH
      or similar.

What it’s like to work at Intellias

At Intellias, where technology takes center stage, people always come before processes. By creating a comfortable atmosphere in our team, we empower individuals to unlock their true potential and achieve extraordinary results. That’s why we offer a range of benefits that support your well-being and charge your professional growth.
We are committed to fostering equity, diversity, and inclusion as an equal opportunity employer. All applicants will be considered for employment without discrimination based on race, color, religion, age, gender, nationality, disability, sexual orientation, gender identity or expression, veteran status, or any other characteristic protected by applicable law.
We welcome and celebrate the uniqueness of every individual. Join Intellias for a career where your perspectives and contributions are vital to our shared success.

Have not found the most
suitable position yet?
Leave your resume and we will select a cool option for you.
Find me a job
Good news!
Link copied
Good news!
You did it.
Bad news!
Something went wrong. Please try again.