Salary
💰 $170,000 - $241,000 per year
About the role
- Establish and maintain a corporate-wide security management program to protect information assets, technology, products, IP, and patient data
- Oversee, lead, and provide briefings of key security functional areas (e.g., incident response, threat intelligence)
- Manage and lead the Product Security team (lead a small team of 1-2 people)
- Develop talent development and succession planning aligned with functional growth
- Collaborate with stakeholders to translate business requirements into security practices and influence implementation
- Oversee AWS Security practices to protect cloud-based infrastructure
- Collaborate with security professionals to design and implement robust security measures
- Conduct regular security assessments and audits to identify and mitigate risks
- Stay updated with security trends and threats and act on external/internal threat information
- Define global communications plan for employee security awareness and best practices
- Identify corporate-wide requirements to integrate security into information and product lifecycle; assess needs and implement solutions
- Provide strategic direction and leadership in all aspects of product security
- Act upon threat information and advise stakeholders on appropriate actions
Requirements
- Bachelor's Degree in a related field required (or Master's Degree with fewer years of experience)
- 12 years of previous related experience with Bachelor's degree OR 10 years with Master's degree (alternate wording in posting)
- Posting also references Bachelor's Degree + 8 years of related experience in IT/Computer Science/networking engineering/R&D
- AWS Security Certification or hands-on expertise
- Product Security hands-on expertise
- Strong AWS, DevOps, and Cloud experience
- Experience in Product Security in the Medical Device industry (preferred)
- Expertise in DevSecOps/DevCloudSecOps, integrating security into CI/CD pipelines and cloud environments
- Certifications such as CISSP, CISM, CSSLP, GIAC, MCSE, or CCSP (preferred)
- Experience advising startups in med tech and pharma (preferred)
- Secure Software Development Life Cycle (SSDLC) experience
- Knowledge of FDA guidelines
- Risk management lifecycle experience
- Strong project management and leadership skills
- Excellent written and verbal communication, negotiating and relationship management skills
- Knowledge of information security and privacy standards, laws, and frameworks (e.g., ISO/IEC 27001, ITIL, COBIT, NIST)
- Ability to manage teams, provide coaching and feedback, and partner with HR on employee relations
- Attention to detail and ability to interact professionally at all organizational levels
- Ability to work in a fast-paced, dynamic environment and lead technical meetings
- Experience in applications, software, and data protection; cyber threat management; incident response; vulnerability testing; risk management
- Intermediate knowledge of privacy regulations and appropriate safeguards
- Demonstrated track record in people management
- Frequently interacts with internal and external senior-level representatives
- May require COVID-19 vaccination if hired into a patient-facing or in-hospital covered role (unless legally exempt)