Director of Product Security
Bedford, MA, United States
Overview
Job Summary This position will lead the Product Cyber Security Organization. Director of Product Security will set overall strategy for the product cyber security program, align security initiatives within business goals, and ensure integration of key product security initiatives into other business support functions across IL. Together with other team members, Director of Product Security will be responsible for the cyber security matters of all IL on-market and pre-market products, processes (governance and compliance) and managing consistent communication to Werfen locations and the field. This position will be within the Cybersecurity Organization reporting to the CISO. The Director of Product Security will have frequent interaction with the Senior Management Team as well as a cross functional team including, but not limited to, product development teams, marketing teams, and regulatory and quality assurance teams to define, align and drive security initiatives.Responsibilities
Key Accountabilities- Responsible for leading cross functional team members to complete all aspects of product cyber security and privacy initiatives.
- Responsible for secure software development for all Werfen on-market and pre-market products.
- Represent cyber security within product development teams to ensure cyber security is being designed into products.
- Responsible for cyber security threat management. Complete continuous technical analysis and monitoring for cyber security signals.
- Responsible for customer assurance. Manage key interface contacts with customers. May include completion of security inquiries, intake of vulnerability reports, provide consistent guidance to staff and customers.
- Responsible for governance, risk and compliance of Werfen processes. Establish product security policy and governance, documentation of process for all domains. Conform compliance to existing industry policies and guidelines.
- Responsible for leading cross functional team members to complete all aspects of product cyber security and privacy initiatives.
- Responsible for secure software development for all Werfen on-market and pre-market products.
- Represent cyber security within product development teams to ensure cyber security is being designed into products.
- Responsible for cyber security threat management. Complete continuous technical analysis and monitoring for cyber security signals.
- Responsible for customer assurance. Manage key interface contacts with customers. May include completion of security inquiries, intake of vulnerability reports, provide consistent guidance to staff and customers.
- Responsible for governance, risk and compliance of Werfen processes. Establish product security policy and governance, documentation of process for all domains. Conform compliance to existing industry policies and guidelines.
- Supervises and coordinates technical aspects with the different team technical leads.
- Other internal interfaces TBD based on departmental needs.
Qualifications
Minimum Knowledge & Experience for the position:- Education: Requires Bachelor’s degree in Computer Science, Computer Engineering or the equivalent combination of related training, proficiency and experience. MBA or Master’s degree preferred.
- Experience:
- Minimum of 8 years of experience leading product cyber security teams and projects and risk management activities - in medical device or healthcare domain.
- Cyber security training and certification such as CISSP/CISM.
- Experience in cross-functional cyber security activities including intrusion detection, security tools and technology, regulation compliance, audit/control processes and customer assurance.
- Experience in incident handling and response.
- Experience in writing policy and managing compliance.
- Experience in designing software development products using SDLC (e.g.: Agile, DevOps)
- Familiar with laws and regulations on cyber security, privacy, data protection and breach notification (e.g.: FDA cyber security guidelines, 95/46/ED, HIPPA, GDPR, ISO/TS 14265, 21CFR820, SB1386, etc.)
- Understanding of Windows and Linux operating systems and networking preferred.
- Domain specific standards and approaches on privacy and product security (e.g.: HL7, ASTM, POCT-1A) preferred.
- Language: English
- Leadership, Managing Vision and Purpose, Developing Direct Reports and others (e.g.: holds people accountable, teamwork, delegation, communication, impact and influencing, etc.), Time Management, Project Management, Oral and Written Communications.
* Salary range is an estimate based on our InfoSec / Cybersecurity Salary Index 💰
Job stats:
0
0
0
Categories:
Architecture Jobs
Leadership Jobs
Tags: Agile CISM CISO CISSP Compliance Computer Science DevOps GDPR Governance HL7 Intrusion detection Linux Monitoring Privacy Product security Risk management SDLC Strategy Windows
Region:
North America
Country:
United States
More jobs like this
Explore more career opportunities
Find even more open roles below ordered by popularity of job title or skills/products/technologies used.
Information Security Officer jobsSenior Cybersecurity Engineer jobsInformation System Security Officer jobsSenior Cloud Security Engineer jobsInformation Security Manager jobsInformation Security Specialist jobsCyber Security Specialist jobsSecurity Consultant jobsSenior Network Security Engineer jobsIT Security Engineer jobsSystems Engineer jobsSecurity Specialist jobsSenior Information Security Analyst jobsIT Security Analyst jobsSenior Cyber Security Engineer jobsChief Information Security Officer jobsSystems Administrator jobsSenior Penetration Tester jobsInformation System Security Officer (ISSO) jobsStaff Security Engineer jobsThreat Intelligence Analyst jobsSenior Product Security Engineer jobsInformation Systems Security Engineer jobsSecurity Operations Analyst jobsCloud Security Architect jobs
Encryption jobsForensics jobsJava jobsTop Secret jobsEDR jobsRMF jobsSaaS jobsGDPR jobsIDS jobsSplunk jobsDoDD 8570 jobsIPS jobsSQL jobsSDLC jobsIntrusion detection jobsBash jobsActive Directory jobsThreat detection jobsCompTIA jobsITIL jobsDocker jobsGIAC jobsFinance jobsCRISC jobsOWASP jobs
SANS jobsUNIX jobsIndustrial jobsTerraform jobsTCP/IP jobsClearance Required jobsHIPAA jobsJavaScript jobsOSCP jobsIT infrastructure jobsCCSP jobsBanking jobsSOC 2 jobsVPN jobsDNS jobsCISO jobsPolygraph jobsData Analytics jobsSOX jobsSAP jobsNIST 800-53 jobsJira jobsGCIH jobsMITRE ATT&CK jobsGSEC jobs