Sr. Software Quality Assurance Engineer
Job Description
MicroAire Surgical Instruments LLC is hiring a senior, individual-contributor Sr. Software Quality Assurance Engineer to provide independent quality oversight and advanced technical guidance across the full lifecycle of software-based medical devices. This onsite role in Charlottesville, VA supports product safety, effectiveness, security, and regulatory compliance through cross-functional collaboration, complex quality activities, and continuous improvement.
What you’ll do
- Provide Quality Assurance oversight for software development activities across the product lifecycle.
- Ensure compliance with Design Control and Software Lifecycle requirements, including maintaining alignment to the internal Quality Management System (QMS).
- Author, review, and approve software development documentation within delegated authority, including: User Needs; Design Inputs and Requirements; Software Design Specifications; Verification and Validation Protocols; Test Reports; Traceability Matrices; Release Documentation; and Risk Management Documentation.
- Participate in design reviews, software development reviews, risk reviews, and release reviews.
- Lead product or project-level software verification and validation strategies within established lifecycle and Quality frameworks.
- Ensure appropriate testing execution and review across Unit, Integration, System, Regression, Automated Testing, and User Acceptance Testing (UAT).
- Verify traceability between requirements, risks, design outputs, and testing activities, including evaluation of test coverage, unresolved defects, and release readiness.
- Support investigations of software defects and field issues through technical review and root cause analysis.
- Evaluate software change requests for impact to product Quality, risk, and regulatory compliance.
- Assess software design and technical risk assessments, and support software risk management activities in accordance with applicable standards and regulations.
- Participate in relevant risk activities such as Hazard Analyses and FMEA, as well as Cybersecurity Risk Assessments and Benefit-Risk Evaluations.
- Provide Quality oversight for secure software development lifecycle activities, including review of cybersecurity documentation (Threat Models, Security Requirements, Vulnerability Assessments, Penetration Testing Reports, Security Risk Assessments, and SBOMs).
- Support cybersecurity process implementation and maintenance consistent with IEC 81001-5-1 and collaborate with Cybersecurity and IT teams aligned to organizational information security controls and ISO/IEC 27001 principles.
- Support post-market cybersecurity monitoring, vulnerability management, and security update processes.
- Support audits and inspections, including internal audits, supplier audits, notified body audits, MDSAP audits, and regulatory inspections.
- Review software-related nonconformances, deviations, CAPAs, and complaint investigations; support Management Review activities and software Quality metric reporting.
- Lead and implement continuous improvement initiatives within the software Quality system.
- Support qualification and oversight of software suppliers and development partners, including review of supplier Quality documentation and audit results.
- Assess risks tied to third-party software components, open-source software, and cloud service providers, and support supplier corrective actions as required.
- Verify traceability and evaluate technical evidence, including technical evaluation of source-code or code-review evidence, as applicable.
Qualifications
- Bachelor’s degree in Computer Science, Software Engineering, Electrical Engineering, Biomedical Engineering, Computer Engineering, or a related technical discipline.
- Minimum 5 years of progressive experience in Software Quality Assurance, Software Engineering, Software Validation, or Software Quality Engineering within a regulated industry, including demonstrated experience independently leading complex software Quality activities in a regulated environment.
- Hands-on software development experience with ability to independently evaluate software engineering deliverables.
- Experience with one or more programming languages, including C++, and embedded software development.
- Ability to assess software development best practices and understand software build and release processes.
- Knowledge of APIs, cloud services, and system integrations.
- Experience with Azure DevOps, GitHub, GitLab, Jira, Jama, automated testing frameworks, and CI/CD environments.
- Working knowledge of key medical device and cybersecurity requirements and standards, including: FDA 21 CFR Part 820; FDA Design Controls; FDA Software Validation Guidance; FDA Cybersecurity Guidance; ISO 13485; ISO 14971; IEC 62304; IEC 60601; IEC 81001-5-1; ISO/IEC 27001; EU MDR; MDSAP requirements; and applicable global medical device regulations and standards.
Preferred qualifications
- Medical device industry experience.
- Experience with SaMD, SiMD, embedded software, connected medical devices, mobile applications, cloud-based software platforms, and/or AI-enabled technologies.
- Ability to read and understand source code, including experience participating in code reviews.
- Understanding of software architecture and design patterns.
- Experience participating in regulatory inspections and Quality system audits.
- ASQ Certified Software Quality Engineer (CSQE) or ISTQB Software Testing Certification.
- Certified Secure Software Lifecycle Professional (CSSLP) and/or CISSP.
- ISO/IEC 27001 Internal Auditor or Lead Auditor.
Tools you’ll work with
- C++, Azure DevOps, GitHub, GitLab, Jira, Jama, automated testing frameworks, and CI/CD environments.
Schedule and work setup
- Schedule: 8:00am to 5:00pm, with flexibility between 6:30am and 6:00pm.
- Role type: senior individual-contributor role (may provide technical guidance, mentoring, and work direction; no direct supervisory responsibility unless separately assigned).
- Environment: primarily office-based with regular collaboration across Quality, Engineering, Regulatory Affairs, and Product Management.
- May include: audits, inspections, manufacturing observations, design reviews, and supplier assessments.
- Travel: occasional travel may be required for audits, supplier evaluations, business meetings, training, or regulatory activities.
- Must be able to work effectively in a fast-paced, highly regulated environment and maintain compliance with applicable quality system, cybersecurity, and regulatory requirements.
Compensation
$88,000 to $110,000 USD per year.