Staff Product Security Analyst

February 16

Apply Now
Logo of iRhythm Technologies, Inc.

iRhythm Technologies, Inc.

iRhythm Technologies, Inc. is a medical technology company that specializes in digital healthcare solutions for the management of cardiac arrhythmias. The company is best known for its ZioSuite, a comprehensive platform designed to deliver a streamlined solution for assessing heart health through advanced analytics and patient-centered data collection. iRhythm focuses on improving patient outcomes and optimizing the efficiency of healthcare providers through innovative technology in the cardiac monitoring space.

mHealth • Wearables • Digital Health • Medical Devices • technology

1001 - 5000 employees

Founded 2006

⚕️ Healthcare Insurance

🧬 Biotechnology

📋 Description

• As a Staff Product Security Analyst, you will play a critical role in safeguarding our medical devices by identifying, assessing, and mitigating security risks specific to the healthcare industry and medical devices. • You will be embedded with the software engineering and work closely with cyber security, development teams, product managers, and regulatory affairs to ensure that security is integrated into the product development lifecycle from the earliest stages, in compliance with Regulatory Agencies’ Cybersecurity requirements (e.g., FDA, BSI and PMDA). • Lead and own the end-to-end device product security management process with the following responsibilities: • FDA Cybersecurity Compliance: Ensure compliance with FDA Cybersecurity guidance and regulations through collaboration with the Cyber Security, Regulatory and Quality, and Systems Development teams. • Risk Assessments: Conduct comprehensive risk assessments of medical devices, identifying potential vulnerabilities and threats specific to the device hardware, firmware, and associated software. • Threat Modeling: Develop and maintain cyber threat models for medical devices, considering factors such as patient safety, cyber security data privacy, and operational continuity. • Software Bill of Materials (SBOM): Familiarity with SBOMs and the ability to communicate technical details effectively • Product Security Policy documentation: Develop and maintain required medical device cyber security documentation as part of the device DHF including pre and post market cyber security activities and filings. • Data Flow Diagrams: Ability to detail data flow diagrams at sufficient detail that can be leveraged throughout the threat modeling process. • Security Design Reviews: Participate in security design reviews of medical device architectures and implementations, cybersecurity impact assessment from device design changes and providing recommendations for system security requirements that meet Regulatory and QMS requirements. • Secure Coding Practices: Promote and guide secure coding practices within development teams, providing guidance and training specific to medical devices. • Incident Response: Assist in the investigation and resolution of security incidents related to medical devices, coordinating with relevant teams to minimize impact and prevent future occurrences. • Vulnerability Management: Assist the Cybersecurity team in execution and maintenance of the vulnerability identification program for medical devices, including vulnerability scanning, patching, and remediation. • Data Privacy: Collaborate with the Privacy Team to ensure compliance with data privacy regulations, such as HIPAA, GDPR, and other applicable laws.

🎯 Requirements

• Bachelor's degree in computer science, information security, or a related field. • 12+ years of experience in information security, with a focus on product security for medical devices. • Strong understanding of security principles, methodologies, and tools specific to medical devices. • Exceptional writing, editing, and proofreading abilities. • Familiarity with content management systems (CMS) and/or document repository systems. • Experience with vulnerability scanning, penetration testing, and threat modeling in the healthcare context. • Expertise with FDA Cybersecurity guidance, regulations, and industry best practices. • Familiarity with other Cybersecurity frameworks such as the NIST Cyber Security Framework and NIST SP 800-171. • Knowledge of secure coding practices and development methodologies (e.g., Agile, DevOps) for medical devices. • Experience with medical device design control requirements for software development and regulatory processes. • Excellent problem-solving, analytical, and communication skills. • Demonstrated ability to work on significant and unique issues where analysis of situations or data requires an evaluation of intangibles. Exercise independent judgment in methods, techniques, and evaluation criteria for obtaining results. As well as creates formal networks involving coordination among groups within and outside of their assigned function.

Apply Now

Discover 100,000+ Remote Jobs!

Join now to unlock all jobs

Discover hidden jobs

We scan the internet everyday and find jobs not posted on LinkedIn or other job boards.

Head start against the competition

We find jobs within 24 hours of being posted, so you can apply before everyone else.

Be the first to know

Daily emails with new job openings straight to your inbox.

Choose your membership

Cancel anytime

Loved by 10,000+ remote workers

Wall of Love

Frequently asked questions

We use powerful scraping tech to scan the internet for thousands of remote jobs daily. It operates 24/7 and costs us to operate, so we charge for access to keep the site running.

Of course! You can cancel your subscription at any time with no hidden fees or penalties. Once canceled, you’ll still have access until the end of your current billing period.

Other job boards only have jobs from companies that pay to post. This means that you miss out on jobs from companies that don't want to pay. On the other hand, Remote Rocketship scrapes the internet for jobs and doesn't accept payments from companies. This means we have thousands more jobs!

New jobs are constantly being posted. We check each company website every day to ensure we have the most up-to-date job listings.

Yes! We’re always looking to expand our listings and appreciate any suggestions from our community. Just send an email to Lior@remoterocketship.com. I read every request.

Remote Rocketship is a solo project by me, Lior Neu-ner. I built this website for my wife when she was looking for a job! She was having a hard time finding remote jobs, so I decided to build her a tool that would search the internet for her.

Why I created Remote Rocketship

Choose your membership

Cancel anytime

Loved by 10,000+ remote workers
Built by Lior Neu-ner. I'd love to hear your feedback — Get in touch via DM or lior@remoterocketship.com