We use cookies. Find out more about it here. By continuing to browse this site you are agreeing to our use of cookies.
#alert
Back to search results

Product Security Engineer

Ampcus, Inc
United States, Massachusetts, Raynham
Jan 27, 2025
Ampcus Inc. is a certified global provider of a broad range of Technology and Business consulting services. We are in search of a highly motivated candidate tjoin our talented Team.

Job Title: Product Security Engineer

Location(s): Raynham, MA (Remote)

Summary:


  • The Product Security Engineer will be responsible for the implementation of clinet enterprise Product Security strategy and framework throughout the orthopedics portfolio. This includes identifying key strategy and goals, collaborating with internal organizations tenhance existing processes and policies, creating and communicating metrics tsenior management, and driving overall awareness of the capability. Specific responsibilities include supporting Client and R&D teams throughout new product development phases, reviewing product security requirements, and recommending security design solutions. The role alsinvolves assisting with the completion of Quality documentation, performing threat modeling, penetration testing, software architecture review, and providing design recommendations. The engineer will conduct code analysis and other security testing as needed. Additionally, post-market responsibilities for Client marketed devices include monitoring for new vulnerabilities, assisting with patching and remediation plans, and responding tcustomer security questionnaires and reviewing security language within contractual agreements.


Key Responsibilities:


  • Support Global Product Security Framework: Contribute tand enhance the global security strategy, frameworks, and initiatives tensure embedded medical devices are developed with the highest security standards.
  • Collaboration & Process Improvement: Partner with internal organizations (engineering, product management, compliance) timprove existing security processes and policies related tmedical device development and post-market support.
  • Metrics & Reporting: Create, track, and present Product Security metrics tsenior management, providing insights intsecurity posture and progress towards goals.
  • Governance & Compliance: Help carry out the Product Security governance model for both pre-market and post-market devices, ensuring compliance with regulatory standards (FDA, 510k, etc.) and industry best practices.
  • Vulnerability Management & Remediation: Manage and prioritize vulnerabilities across the product portfolio, assisting engineering teams in developing and executing effective remediation plans.
  • Due Diligence & Threat Modeling: Conduct due diligence activities, threat modeling, and risk assessments for new and existing products tidentify potential security gaps.
  • Secure Software Development: Provide recommendations on secure coding practices, review code, and advise engineering teams on securing embedded applications (e.g., C/C++, C#).
  • Customer & Vendor Interactions: Respond tcustomer security questionnaires, contractual language requirements, and ensure compliance with relevant security standards.
  • Security Awareness & Communication: Lead and deliver Product Security awareness campaigns, training, and communications across the organization.
  • Post-Market Security Activities: Monitor and respond tnew vulnerabilities in Client marketed devices, assist with patching and remediation efforts, and collaborate on customer security questionnaires and contractual obligations.
  • Other Duties: Perform additional security-related tasks as assigned.


Qualifications:


  • Education: Minimum of a Bachelor's degree in Computer Science, Engineering, or a related field is required; MS or advanced degree is preferred.
  • Experience: A minimum of 6 years in security and/or embedded software engineering functions, with a focus on product security in regulated environments (medical devices is a plus).


Technical Skills:


  • In-depth knowledge of real-time operating systems (e.g., QNX, Linux, Windows Embedded) and hardening techniques.
  • Strong understanding of embedded systems security, including secure software development, secure coding practices, and vulnerability management.
  • Experience with vulnerability scanning, penetration testing, and risk assessment tools (CVSS, OWASP, etc.).
  • Proficiency in at least one programming language (e.g., C, C++, C#) and experience with secure code reviews.
  • Knowledge of Software Bill of Materials (SBOM) and how it relates tsecurity and compliance.


Security & Regulatory Expertise:


  • Understanding of medical device security requirements, including FDA regulations, 510k submissions, and Quality Design Control processes.
  • Familiarity with threat modeling, risk management frameworks, and vulnerability management for medical devices.


Communication & Leadership Skills:


  • Strong interpersonal and collaboration skills with the ability tcommunicate complex technical concepts tnon-technical stakeholders.
  • Proven ability tinfluence cross-functional teams tdrive security improvements and achieve desired outcomes.
  • Experience creating and presenting security metrics and reports tsenior management.
  • Certifications (preferred, not required):
  • CISSP, CEH, MCSD, CSSLP, or similar security certifications.


Additional Skills:


  • Familiarity with cloud-based IoT solutions is preferred.
  • Creative problem-solving skills with a customer-focused mindset (both internal and external).
  • A strategic thinker with strong attention tdetail and the ability talign tactical initiatives with broader organizational goals.


Ampcus is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard trace, color, religion, sex, sexual orientation, gender identity, national origin, age, protected veterans or individuals with disabilities.
Applied = 0

(web-6f6965f9bf-j5kl7)