About this role
Job Requirements
Role Summary:
- Serve as the Product Security Representative for multiple Imaging 360 products and releases, representing cybersecurity and privacy requirements throughout the product lifecycle.
- Drive execution of the GEHC DEPS process, including security and privacy planning, threat modeling, cybersecurity risk assessment, secure design reviews, vulnerability management, lifecycle security artifacts, and phase-appropriate security deliverables from concept through development and evaluation.
- Own Security Design Reviews across the product lifecycle, including concept definition, architecture and design, development execution, verification / evaluation, and release readiness for Imaging360 capabilities and integrations.
- Partner with Product Security Leaders and product teams to interpret and apply GEHC cybersecurity standards, regulatory expectations, and quality management system requirements.
- Lead threat modeling and security architecture reviews for cloud-hosted enterprise applications, APIs, data flows, scanner connectivity, on-premises integrations, identity services, and third-party product integrations.
- Assess cybersecurity risks associated with hybrid deployments involving cloud services, customer networks, on-premises scanners, edge components, and external vendor systems.
- Define and influence implementation of security controls for authentication, authorization, encryption, audit logging, secrets management, network segmentation, secure communication, data protection, and system hardening.
- Own or support cybersecurity management plans, vulnerability triage, remediation planning, risk acceptance discussions, and closure tracking across multiple product teams.
- Coordinate SAST, SCA, DAST, penetration testing, infrastructure scanning, container security, cloud security reviews, and remediation activities in partnership with engineering and operations teams.
- Generate, maintain, and assess Software Bill of Materials (SBOM) content, including open-source, commercial, and third-party components integrated into the product.
- Evaluate third-party product integrations for cybersecurity, privacy, data protection, interface security, supportability, and operational risk.
- Collaborate with architecture, platform, DevOps, cloud operations, quality, regulatory, privacy, and program teams to ensure secure-by-design and compliant delivery.
- Provide cybersecurity guidance to scrum teams, review design and implementation decisions, and help teams adopt secure SDLC and DevSecOps practices.
- Support fielded product security activities, including vulnerability impact assessments, customer notifications, remediation planning, patch strategy, and lifecycle risk management.
- Champion Imaging 360-level security KPI reporting, governance dashboards, and ongoing monitoring of security health indicators, including vulnerability posture, remediation progress, open risks, security test coverage, SBOM readiness, and DEPS compliance status.
- Prepare clear technical and leadership-level communication on security posture, risks, remediation status, and product security readiness
Work Experience
Qualifications
- Bachelor’s degree in Computer Science, Computer Engineering, Cybersecurity, Information Security, Software Engineering, or a related STEM discipline.
- 12+ years of experience in software engineering, product security, application security, cloud security, or cybersecurity engineering for enterprise products.
- Hands-on experience securing cloud-hosted enterprise applications and distributed systems, preferably in AWS, Azure, or similar cloud environments.
- Experience with enterprise products that integrate with on-premises systems, connected devices, customer networks, or scanner / equipment workflows.
- Strong understanding of secure software development lifecycle practices, threat modeling, cybersecurity risk management, vulnerability management, and security control implementation.
- Working knowledge of application, API, container, infrastructure, network, and cloud security concepts.
- Experience with security assessment tools and practices such as SAST, SCA, DAST, penetration testing, container scanning, cloud posture management, SBOM generation, and dependency vulnerability analysis.
- Knowledge of OWASP Top 10, secure coding principles, identity and access management, encryption, audit logging, secure communications, and privacy-by-design principles.
- Ability to work effectively in a regulated product development environment and maintain compliance with quality, privacy, and cybersecurity processes.
- Demonstrated technical leadership, stakeholder management, and communication skills across engineering, product, quality, regulatory, security, and leadership audiences.
Desired Skills
- Experience serving as a Product Security Representative, security architect, or product security owner for multiple products or releases.
- Experience with healthcare software, medical device software, imaging workflows, DICOM environments, or connected clinical systems.
- Familiarity with GEHC DEPS or equivalent product cybersecurity lifecycle processes in regulated industries.
- Understanding of applicable cybersecurity and privacy frameworks such as FDA cybersecurity guidance, NIST, ISO 27001, IEC 81001-5-1, HIPAA, GDPR, SOC 2, or similar standards.
- Experience assessing third-party products, SaaS services, APIs, vendor integrations, and data exchange workflows for cybersecurity and privacy risk.
- Hands-on experience with tools such as threat modeling tools, Black Duck, Syft, Grype, SonarQube, Burp Suite, Wiz, Twistlock / Prisma Cloud, or equivalent security platforms.
- Experience with DevSecOps practices, CI/CD security gates, automated security testing, infrastructure-as-code security, container security, and cloud-native monitoring.
- Strong understanding of identity federation and access control technologies such as SAML, OAuth, OIDC, SCIM, RBAC, and least-privilege access models.
- Security certifications such as CISSP, CSSLP, CISM, CCSP, CEH, or equivalent credentials are a plus.
- Ability to influence without authority, simplify complex security topics, and drive timely risk-based decisions across global and cross-functional teams.