EI
Sr. Cybersecurity Specialist in MedTech
Expert In Recruitment Solutions
πΊπΈ United States
Remote
Senior
2 months ago
- IEC
- Risk Management
- Vulnerability Management
- Threat Modeling
- Penetration Testing
2 months ago
This is a remote part-time opportunity (20 hour/week)
Key Qualifications
- Medical Device Experience (5+ Years):
- A minimum 5 years of direct, hands-on experience in medical device cybersecurity, preferably a Class III devices.
- Have demonstrated experience in creating documentation for at last one FDA 510K, PMA submission, or EU MDR technical documentation submission.
- Hands-on experience with standards like ISO 14971, IEC 62304 and ISO 13485 and experience in aligning these with regulatory requirements.
- Proven track record of working on devices with Bluetooth communication, mobile apps, and cloud integration.
- Regulatory Documentation Expertise:
- In-depth knowledge of FDA submission requirements, including:
- Cybersecurity documentation for 510(k) and PMA submissions.
- Creation of threat models, risk management files, and security testing reports tailored to FDA guidance.
- Familiarity with CE marking requirements for the EU, including:
- Cybersecurity sections for Technical Documentation under MDR.
- Ensuring compliance with ISO 14971, IEC 62304, and IEC/TR 60601-4-5.
- Demonstrated ability to produce submission-ready documentation in formats acceptable to both the FDA and Notified Bodies.
- In-depth knowledge of FDA submission requirements, including:
- SDLC Integration:
- Expertise in integrating threat and vulnerability management across the Software Development Lifecycle (SDLC).
- Ability to trace threats, risks, and mitigations through design, development, and testing stages, ensuring that all necessary artifacts are prepared and submission-ready for the specific Notified Body.
- Cybersecurity Risk Management:
- Experience in conducting and documenting:
- Threat modeling (e.g., STRIDE).
- Risk assessments and alignments with AAMI TIR57 and ISO 14971.
- Security testing results, including penetration testing and vulnerability assessments, documented in submission-ready formats.
- Experience in conducting and documenting:
- Standards and Compliance:
- Familiarity with relevant standards for medical device cybersecurity:
- FDA Premarket Guidance for cybersecurity risk management.
- ISO 13485 for quality system integration.
- IEC 62304 for secure software lifecycle processes.
- Familiarity with relevant standards for medical device cybersecurity:
- Communication and Collaboration:
- Strong ability to work cross-functionally with engineering, regulatory, and quality teams to ensure submission documentation meets all regulatory requirements.
- Experience presenting and defending cybersecurity strategies and documentation during audits or regulatory reviews.
Additional Information:
ββββββNo of position - 1 (50% capacity which is 86 hours a month)
ββββββDuration - 5 to 6 months (Aug - Dec 2026) with possibility to extend further
ββββββWork location: Remote (may have to occasionally travel to Houston customer office for meetings/workshops)
Sr. Cybersecurity Specialist in MedTech Β· Expert In Recruitment Solutions