Aller au contenu principal

Lead Product Security Engineer

00068697581

Job Title - Lead Product Security Engineer
Location - 2/3 days a week from - Raritan, NJ
Skill matrix:


Mandatory Skills
(Top 5 Keywords or skills)
Skill Proficiency
Years of Experience
Basic Knowledge
Medium
Expert
Product Security
5+
Y
Penetration Testing
5+
Y
C/C++, C#, Python
5+
Y
Job Description:
We are searching for top talent for Lead Product Security Engineer. The preferred locations for this role are San Jose, California; Cincinnati, Ohio; and Raritan, New Jersey. Remote opportunities in the US are available on a case by case basis and if approved by the company. This role may require up to 10 - 20% travel.
The Lead Medical Device Cybersecurity Engineer will be responsible for implementation of the customer's enterprise Product Security strategy and framework for the customer's MedTech Surgery Ottava Robotic Platform. This includes identifying key strategy and goals, collaborating with internal organizations on existing process and policy enhancements, creating and communicating metrics to Ottava management, identifying communications plans and raising overall awareness of the capability.
Specific responsibilities include supporting Ottava’s R&D throughout a new product’s development phases, review product security requirements and recommend security design solutions, ensure the team completes Quality documentation, threat modelling, security risk assessment, penetration testing, software architecture review and design recommendations, code analysis and other security testing or work as needed.
Additionally, post market responsibilities for Ottava’s surgical robotic platform marketed devices include monitoring for new vulnerabilities, leading the product security teams with patching and remediation plans, as well as responding to all customer security questionnaires and reviewing security language within contractual agreements.
Key Responsibilities:
  • Help drive adherence to the customer's Product Security’s overarching framework
  • Partner with internal organizations to enhance existing processes and policies
  • Create and present Product Security metrics to management within Ottava and ISRM
  • Champion Product Security strategy and objectives across the Ottava Robotic Platform
  • Engaged as a subject matter expert to support completion of product security activities, tasks, deliverables, documentation, approvals, and product security controls.
  • Responsible for defining security requirements for the product and associated applications
  • Responsible for reviewing the Threat Model and Security Risk Assessment in collaboration with Systems Engineering.
  • Responsible for supporting the FDA pre-market cybersecurity documents (as needed) and collaborating with regulatory compliance stakeholders and activities.
  • Responsible for the facilitation and assessing any third parties’ penetration testing and/or validation services.
  • Perform regular reviews and analysis of security reports and issues, propose solutions where appropriate and lead their remediation.
  • Respond to alerts, security incidents, and assist in remediation as needed.
  • Respond to customer cybersecurity questionnaires for all post-market medical devices.
  • Other MedTech cybersecurity related duties as needed
Qualifications:
Required:
  • At least 5 years IT or cybersecurity experience and at least 2 years of product security experience
  • Bachelor’s degree or equivalent experience
  • Understanding of penetration testing, vulnerability scanning, CVSS and/or other general security testing principles
  • Ability to provide secure coding recommendations
  • Knowledge in at least one coding language (i.e. C/C++, C#, Python) with code review experience highly preferred
  • Ability to work autonomously and proactively seek out security opportunities within the different surgical robotics teams
  • Knowledge of traditional and real-time operating systems (i.e. QNX, Windows Embedded, Ubuntu, Yocto) hardening techniques
  • Ability to translate technical security requirements into solutions
  • Creative problem-solving skills
  • Customer focus (internal & external)
  • Excellent communication and collaboration skills
Preferred Skills:
  • Understanding of Quality Design Control processes and FDA submission processes.
  • Hands-on experience with software security tools and platforms like Checkmarx, Black Duck, Jfrog Xray, etc.
  • Hands-on experience with vulnerability assessment tools.
  • Knowledge of product or medical device security or MDDS platforms.
  • Working knowledge of microservices architecture and API security.
  • Experience working within Agile methodology.
  • Software development experience
  • Experience leading or participating in formal security audits (i.e. HITRUST, SOC2, FedRAMP)
  • Security certification like CISSP/ AWS Security Specialist/ CEH or CSSLP a strong plus.

Salary and Other Compensation:

The annual salary for this position is between $110-134Kdepending on experience and other qualifications of the successful candidate.

This position is also eligible for Cognizant’s discretionary annual incentive program, based on performance and subject to the terms of Cognizant’s applicable plans.

Benefits: Cognizant offers the following benefits for this position, subject to applicable eligibility requirements:

· Medical/Dental/Vision/Life Insurance

· Paid holidays plus Paid Time Off

· 401(k) plan and contributions

· Long-term/Short-term Disability

· Paid Parental Leave

· Employee Stock Purchase Plan

Disclaimer: The salary, other compensation, and benefits information is accurate as of the date of this posting. Cognizant reserves the right to modify this information at any time, subject to applicable law.


La communauté Cognizant : 

Nous sommes une équipe de professionnels dont les membres s'apprécient et se soutiennent mutuellement. Nos collaborateurs sont les garants d'un lieu de travail dynamique, collaboratif et inclusif où chacun peut s'épanouir.

  • Cognizant est une communauté mondiale qui compte plus de 300 000+ collaborateurs dans le monde entier.
  • Nous ne nous contentons pas de rêver de façons idéales, nous apportons des améliorations concrêtes
  • Nous prenons soin de nos collaborateurs, de nos clients, de notre entreprise, de nos communautés et du climat, en faisant ce qui est juste.
  • Nous favorisons un environnement innovant où vous pouvez construire le plan de carrière qui vous convient.

À propos de nous : 
Cognizant (NASDAQ : CTSH) est un concepteur d’IA et un fournisseur de services technologiques. Avec notre gamme de solutions IA full-stack, nous accompagnons nos clients au carrefour de l’investissement dans l’IA et de la valeur ajoutée. Notre grande expertise sectorielle, des processus et de l’ingénierie nous permet de convertir le contexte propre à chaque entreprise en systèmes technologiques amplificateurs du potentiel humain, générateurs de résultats tangibles et garants de l’avantage des acteurs internationaux dans un monde en constante évolution. Découvrez notre méthode sur www.cognizant.com ou suivez @cognizant.

Cognizant est un employeur soucieux de l'égalité des chances entre candidats. Votre candidature sera étudiée indépendamment de votre race, couleur, sexe, religion, croyances, orientation sexuelle, identité de genre, origine, handicap, informations génétiques, grossesse, statut d'ancien militaire ou de toute autre critère jugé discriminant par les lois européennes ou françaises.

Vous êtes porteur d'un handicap, vous pouvez-nous contacter par courriel [email protected] si vous souhaitez préciser les aménagements nécessaires pour le poste ou les entretiens à venir.

Mentions légales : 
Les informations relatives à la rémunération du poste à pourvoir dépendent de la date de publication de l’offre de poste. Cognizant se réserve le droit de modifier ces informations à tout moment, sous réserve des lois applicables.

Les candidats peuvent être invités à participer à des entretiens en face à face ou par vidéoconférence. En outre, les candidats peuvent être amenés à présenter une carte d'identité valide lors de chaque entretien.

Rejoignez notre communauté de talents

Vous n'avez pas encore trouvé la bonne opportunité ? Recevez les dernières offres d'emploi, les événements de recrutement et les actualités de l'entreprise qui vous concernent particulièrement.

S'inscrire