Product Cybersecurity Engineer (Medical Devices)
Analog Devices · Wilmington, MA · 2 wk ago
Information Technology$135k–$202k/yrFull-time
About the role
The Health Solutions Business Unit at Analog Devices is seeking a Product Cybersecurity Engineer to ensure the security, privacy, and regulatory compliance of connected medical devices and Software as a Medical Device (SaMD) solutions.
Responsibilities
- Perform product security risk assessments and threat modeling for medical devices and SaMD platforms.
- Lead cybersecurity risk management activities throughout the product lifecycle in alignment with FDA guidance and industry best practices.
- Support cybersecurity documentation for FDA regulatory submissions, including cybersecurity risk management files, SBOM requirements, and other regulatory deliverables.
- Conduct security architecture reviews and evaluate system designs against secure architecture principles, cybersecurity frameworks, and regulatory expectations.
- Develop and maintain cybersecurity risk management documentation, vulnerability management processes, and incident response procedures.
- Partner with internal and external teams to integrate secure-by-design principles into product development and lifecycle management activities.
- Participate in secure development lifecycle (SDL/SSDLC) activities, including security requirements definition, design reviews, and cybersecurity verification activities.
- Analyze results from vulnerability assessments, static analysis, dynamic analysis, penetration testing, and security scanning activities.
- Support SBOM generation, third-party software assessments, and supply chain cybersecurity risk evaluations.
- Investigate and support remediation of cybersecurity vulnerabilities affecting medical devices, software platforms, and connected product ecosystems.
- Participate in vulnerability management, coordinated vulnerability disclosure, product security incident response, and post-market cybersecurity monitoring activities.
- Serve as a cybersecurity subject matter expert (SME) for cross-functional teams and product cybersecurity initiatives.
Requirements
- Master’s or Ph.D. degree in Cybersecurity, Computer Science, Computer Engineering, Software Engineering, or a related technical discipline. Ph.D. preferred.
- 7+ years of experience in cybersecurity, product security, software security, or related engineering roles.
- Experience supporting cybersecurity activities for medical devices, connected healthcare products, or Software as a Medical Device (SaMD).
- Demonstrated experience supporting FDA-regulated medical devices, including 510(k) submissions.
- Demonstrated experience performing threat modeling for complex systems using methodologies such as STRIDE, attack trees, misuse cases, or equivalent frameworks.
- Familiarity with cybersecurity standards and frameworks such as NIST Cybersecurity Framework, ISO 14971, IEC 62304, AAMI TIR57, and OWASP guidance.
- Experience with vulnerability management, security testing, penetration testing, and remediation processes.
- Familiarity with Software Bill of Materials (SBOM), third-party software risk management, and supply chain cybersecurity concepts.
- Experience integrating cybersecurity requirements into Secure Development Lifecycle (SDL/SSDLC) processes.
- Strong analytical, technical writing, communication, and cross-functional collaboration skills.
Additional Desired Skills and Qualifications
- Experience with connected medical devices, SaMD, cloud-connected platforms, or AI/ML-enabled medical products.
- Experience with post-market cybersecurity monitoring, vulnerability disclosure, and incident response processes.
- Experience with connected medical devices, cloud-connected platforms, IoMT, or digital health solutions.
- Professional certifications such as CISSP, CSSLP, HCISPP, GICSP, Security+, or equivalent.
Benefits
- Medical, vision, and dental coverage
- 401k
- Paid vacation, holidays, and sick time