Location: remote (there will be occasional travel (maybe once a month) to Houston)
This is a remote part-time opportunity (20 hour/week)
Key Qualifications
Medical Device Experience (5+ Years):
A minimum 5 years of direct, hands-on experience in medical device cybersecurity, preferably a Class III devices.
Have demonstrated experience in creating documentation for at last one FDA 510K, PMA submission, or EU MDR technical documentation submission.
Hands-on experience with standards like ISO 14971, IEC 62304 and ISO 13485 and experience in aligning these with regulatory requirements.
Proven track record of working on devices with Bluetooth communication, mobile apps, and cloud integration.
Regulatory Documentation Expertise:
In-depth knowledge of FDA submission requirements, including:
Cybersecurity documentation for 510(k) and PMA submissions.
Creation of threat models, risk management files, and security testing reports tailored to FDA guidance.
Familiarity with CE marking requirements for the EU, including:
Cybersecurity sections for Technical Documentation under MDR.
Ensuring compliance with ISO 14971, IEC 62304, and IEC/TR 60601-4-5.
Demonstrated ability to produce submission-ready documentation in formats acceptable to both the FDA and Notified Bodies.
SDLC Integration:
Expertise in integrating threat and vulnerability management across the Software Development Lifecycle (SDLC).
Ability to trace threats, risks, and mitigations through design, development, and testing stages, ensuring that all necessary artifacts are prepared and submission-ready for the specific Notified Body.
Cybersecurity Risk Management:
Experience in conducting and documenting:
Threat modeling (e.g., STRIDE).
Risk assessments and alignments with AAMI TIR57 and ISO 14971.
Security testing results, including penetration testing and vulnerability assessments, documented in submission-ready formats.
Standards and Compliance:
Familiarity with relevant standards for medical device cybersecurity:
FDA Premarket Guidance for cybersecurity risk management.
ISO 13485 for quality system integration.
IEC 62304 for secure software lifecycle processes.
Communication and Collaboration:
Strong ability to work cross-functionally with engineering, regulatory, and quality teams to ensure submission documentation meets all regulatory requirements.
Experience presenting and defending cybersecurity strategies and documentation during audits or regulatory reviews.
Additional Information: No of position - 1 (50% capacity which is 86 hours a month) Duration - 5 to 6 months (Aug - Dec 2026) with possibility to extend further Work location: Remote (may have to occasionally travel to Houston customer office for meetings/workshops)
Numbers & Facts
Location
Remote, FL (Remote)
Skills
Application Integrationunmatched
Association for the Advancement of Medical Instrumentation (AAMI)unmatched
Bluetoothunmatched
Cloud Applicationsunmatched
Computer Securityunmatched
Cross-Functionalunmatched
Documentationunmatched
FDA (Food and Drug Administration)unmatched
ISO (International Organization for Standardization)unmatched
International Electro-Technical Commission (IEC)unmatched
Internet Securityunmatched
Maintain Complianceunmatched
Medical Equipmentunmatched
Medical Protocolsunmatched
Mobile Applicationsunmatched
Penetration Testingunmatched
Regulationsunmatched
Regulatory Complianceunmatched
Regulatory Requirementsunmatched
Risk Analysisunmatched
Risk Managementunmatched
Software Development Lifecycle (SDLC)unmatched
System Integration (SI)unmatched
Technical Writingunmatched
Test Plan/Scheduleunmatched
Testingunmatched
Threat Modelingunmatched
Willing to Travelunmatched
🎯
Be found by employers
5,500+ employers search our resume database daily. Add yours to get found by recruiters looking for candidates like you.
Level up your application
Professional resume templates
Browse dozens of recruiter approved resume templates, layouts and formats. Choose your favorite and make it your own in minutes.