Senior Product Security Engineer
Job Description
The Senior Product Security Engineer at Hologic drives Secure by Design across product teams, performs security assessments and risk management, and supports DevSecOps for healthcare solutions. The role may be remote or based in Newark, DE; Santa Clara, CA; Marlborough, MA, or other locations, with a annual salary range of USD 106,600 to 171,800.
Responsibilities
- Promote a Secure by Design culture across product teams, ensuring adherence to security standards and best practices.
- Help refine and extend Secure by Design policies and procedures to align products with current security requirements and regulatory standards.
- Assist in creating and maintaining security design documentation and architecture diagrams.
- Perform and document ongoing security assessments, including threat modeling, for Hologic products and remote connectivity solutions; provide guidance to product teams as needed.
- Lead Security Risk Management activities to address identified vulnerabilities and security design issues.
- Define and maintain security controls and requirements while actively participating in design discussions and activities.
- Support product development with Security Code Reviews to ensure alignment with Secure by Design principles and appropriate security controls.
- Help automate security testing and reporting, manage security tooling, and secure cloud environments.
- Oversee ongoing security monitoring of in-market products and connected health solutions; participate in incident response investigations as necessary.
- Educate sales and service teams on securing our products, connected health solutions, and operating environments.
Requirements
- Master’s or Bachelor’s degree in Computer Science, Management Information Science, Engineering, or a related technical field.
- 4+ years of relevant experience in computer and network security, cloud-based platforms, computer networking administration, Windows and Linux operating systems, software application testing and maintenance, and cybersecurity risk assessment.
- Knowledge of secure development lifecycle and experience within a development environment.
- Expertise in secure application design and code reviews, with understanding of Secure Coding standards and common vulnerabilities (OWASP Top 10, CWEs).
- Proficiency in scripting and basic application development (PowerShell, Python, C#, C++).
- Experience with industry-standard security tools (SAST, SCA, DAST, vulnerability scanning).
- Leadership in Threat Modeling, with STRIDE method preferred.
- Penetration testing experience (direct or supportive).
- Experience securing development and cloud environments (Azure preferred) and in DevSecOps pipelines (CI/CD).
- Strong verbal and written communication skills.
Technologies
- PowerShell, Python, C#, C++
- Windows, Linux
- SAST, SCA, DAST, vulnerability scanning
- Azure, STRIDE, Threat Modeling
- OWASP Top 10, CWEs
- CI/CD
Benefits
- Competitive salary and annual bonus scheme
- Comprehensive training and continued development
- Equal Opportunity Employer
Ideal Candidate Profile
- Industry Awareness: Maintains vigilance on industry security threats, assesses risks to Hologic products, and manages these risks per quality procedures.
- Troubleshooting Expertise: Diagnoses and resolves issues related to networked, computer-based products.
- Travel Flexibility: Available for travel to Hologic offices, training, and customer sites.
- Autonomous Alignment: Works with some supervision while aligning with strategic intentions and corporate priorities.
- Cloud Knowledge: Strong understanding of cloud design concepts and familiarity with security analysis and protection tools.
Preferred Qualifications
- Medical Systems Knowledge: Experience with medical information system administration and familiarity with medical device security standards and regulations (FDA Premarket Cybersecurity Guidance, IEC 81001-5-1, AAMI TIR57, AAMI SW96).
- Regulated Industry Experience: Experience in software development and verification within a regulated industry.
- Technical Support Experience: Experience providing technical support to field service teams and end-users.
- Certifications: Security-related certifications (eg CISSP), OS (Windows, Linux), and networking (Cisco) certifications are strongly preferred.