Staff Engr, Software

Saviance Technologies
  • San Diego, CA
  • Quick Apply
6 days ago

Job Description


Bill rate is *** Temp to Perm possibility but that depends on experience !



We are seeking a Product Security Engineer to support Client s MMS Dispensing business unit. The Dispensing portfolio includes FDA Class I and Class II medical devices and their associated cloud-connected platforms. The product security engineer owns, leads, and executes the activities and documentation outlined in Client s security lifecycle. These activities and documents include Security Requirements, Threat Modeling, Risk Assessments and Analysis, Vulnerability & Risk Management Plans, Security Testing, and White Papers.







This role focuses on risk-based security that ensures patient safety, data protection, and regulatory readiness.







Role Focus




- Execution of Product Security Engineering Lifecycle activities




- Generation and Maintenance of Product Security Documentation




- Apply risk-proportionate security controls




- Emphasize secure-by-design and secure-by-default




- Enable efficient FDA submissions (510(k), De Novo)




- Balance usability, workflow, and security







Key Responsibilities







- Security Architecture & Design




- Define end-to-end security architecture across devices, apps, and cloud




- Establish baseline security patterns (auth, encryption, secure updates)




- Conduct Threat Modeling, Risk Assessments, Requirements/Controls Mapping, Security White Papers
- Lead and Drive Security Design Reviews & Roadmap Remediations/Mitigations







Secure SDLC




- Implement lean Secure SDLC aligned to NIST, OWASP, and BSIMM




- Integrate SAST, SCA, secrets scanning, container/IaC scanning




- Define minimum viable security gates







Regulatory & Compliance




- Support FDA cybersecurity documentation (threat models, SBOMs, risk assessments)




- Align with IEC 62304, ISO 14971




- Ensure audit-ready documentation







Cloud Security




- Architect secure integrations with Client s Cloud Platforms




- Secure device-to-cloud data flows







SBOM & Vulnerability Management




- Establish SBOM processes (SPDX, CycloneDX)




- Implement continuous vulnerability monitoring




- Define risk-based remediation SLAs







Cross-Functional Leadership




- Collaborate with engineering, quality, regulatory, and product teams




- Translate security into patient safety and business risk




- Mentor teams







Required Qualifications




- 5 + years cybersecurity experience




- Experience with FDA Class I/II devices




- Regulatory/Quality Control product development




- Demonstrated working experience in the domains of embedded, cloud, and application security




- FDA submissions







Preferred Qualifications




- Software Development, System Engineering background




- AI (Agentic, Generative, ML) skills and agent development




- Experience with IoMT ecosystems




- Knowledge of FDA Cybersecurity Pre & Post Market Guidance, UL 2900, AAMI TIR57/TIR97




- DevSecOps experience




- Certifications (CISSP, CCSP, CSSLP)




- Experience working in cross-functional product development environments




- Experience presenting technical security concepts to leadership and business stakeholders




- Proven track record of driving security initiatives from concept through implementation










Key Competencies




- Ability to right-size security controls




- Strong risk-based decision-making




- Communication across technical and non-technical teams




-Strong stakeholder management skills




-Ability to build credibility and trust across cross-functional teams




-Excellent verbal, written, and presentation communication skills




-Ability to navigate ambiguity and drive consensus




-Ability to balance competing priorities in a fast-paced environment










Success Metrics




- Comprehensive Threat Modeling and effective Security Risk Management




- SBOM completeness




- Reduction in critical vulnerabilities




- FDA submission success




- Time-to-remediate vulnerabilities




- Timely completion of security lifecycle deliverables




- On-time support of product release and submission milestones






Applications must be located in the Orange County / San Diego metro area.








Bill rate is *** Temp to Perm possibility but that depends on experience !



We are seeking a Product Security Engineer to support Client s MMS Dispensing business unit. The Dispensing portfolio includes FDA Class I and Class II medical devices and their associated cloud-connected platforms. The product security engineer owns, leads, and executes the activities and documentation outlined in Client s security lifecycle. These activities and documents include Security Requirements, Threat Modeling, Risk Assessments and Analysis, Vulnerability & Risk Management Plans, Security Testing, and White Papers.







This role focuses on risk-based security that ensures patient safety, data protection, and regulatory readiness.







Role Focus




- Execution of Product Security Engineering Lifecycle activities




- Generation and Maintenance of Product Security Documentation




- Apply risk-proportionate security controls




- Emphasize secure-by-design and secure-by-default




- Enable efficient FDA submissions (510(k), De Novo)




- Balance usability, workflow, and security







Key Responsibilities







- Security Architecture & Design




- Define end-to-end security architecture across devices, apps, and cloud




- Establish baseline security patterns (auth, encryption, secure updates)




- Conduct Threat Modeling, Risk Assessments, Requirements/Controls Mapping, Security White Papers
- Lead and Drive Security Design Reviews & Roadmap Remediations/Mitigations







Secure SDLC




- Implement lean Secure SDLC aligned to NIST, OWASP, and BSIMM




- Integrate SAST, SCA, secrets scanning, container/IaC scanning




- Define minimum viable security gates







Regulatory & Compliance




- Support FDA cybersecurity documentation (threat models, SBOMs, risk assessments)




- Align with IEC 62304, ISO 14971




- Ensure audit-ready documentation







Cloud Security




- Architect secure integrations with Client s Cloud Platforms




- Secure device-to-cloud data flows







SBOM & Vulnerability Management




- Establish SBOM processes (SPDX, CycloneDX)




- Implement continuous vulnerability monitoring




- Define risk-based remediation SLAs







Cross-Functional Leadership




- Collaborate with engineering, quality, regulatory, and product teams




- Translate security into patient safety and business risk




- Mentor teams







Required Qualifications




- 5 + years cybersecurity experience




- Experience with FDA Class I/II devices




- Regulatory/Quality Control product development




- Demonstrated working experience in the domains of embedded, cloud, and application security




- FDA submissions







Preferred Qualifications




- Software Development, System Engineering background




- AI (Agentic, Generative, ML) skills and agent development




- Experience with IoMT ecosystems




- Knowledge of FDA Cybersecurity Pre & Post Market Guidance, UL 2900, AAMI TIR57/TIR97




- DevSecOps experience




- Certifications (CISSP, CCSP, CSSLP)




- Experience working in cross-functional product development environments




- Experience presenting technical security concepts to leadership and business stakeholders




- Proven track record of driving security initiatives from concept through implementation










Key Competencies




- Ability to right-size security controls




- Strong risk-based decision-making




- Communication across technical and non-technical teams




-Strong stakeholder management skills




-Ability to build credibility and trust across cross-functional teams




-Excellent verbal, written, and presentation communication skills




-Ability to navigate ambiguity and drive consensus




-Ability to balance competing priorities in a fast-paced environment










Success Metrics




- Comprehensive Threat Modeling and effective Security Risk Management




- SBOM completeness




- Reduction in critical vulnerabilities




- FDA submission success




- Time-to-remediate vulnerabilities




- Timely completion of security lifecycle deliverables




- On-time support of product release and submission milestones






Applications must be located in the Orange County / San Diego metro area.







['API Documentation', 'Application Programming Interface (API) Security', 'Application Security Architecture', 'Application Security Testing', 'Artificial Intelligence (AI)', 'Cloud Security', 'Cyber Risks', 'Cybersecurity', 'Cyber Security Assessments', 'Cybersecurity Compliance', 'Cybersecurity Risk Management', 'Cyber Threat Analysis', 'Cyber Threat Modeling', 'Design Documentation', 'Documentation Compliance', 'Security Engineering'] Shift: ['API Documentation', 'Application Programming Interface (API) Security', 'Application Security Architecture', 'Application Security Testing', 'Artificial Intelligence (AI)', 'Cloud Security', 'Cyber Risks', 'Cybersecurity', 'Cyber Security Assessments', 'Cybersecurity Compliance', 'Cybersecurity Risk Management', 'Cyber Threat Analysis', 'Cyber Threat Modeling', 'Design Documentation', 'Documentation Compliance', 'Security Engineering']

Numbers & Facts

LocationSan Diego, CA

Skills

  • Applications Securityunmatched
  • Artificial Intelligence (AI)unmatched
  • Association for the Advancement of Medical Instrumentation (AAMI)unmatched
  • CCSP - Cisco Certified Security Professionalunmatched
  • CISSP - Certified Information Systems Security Professionalunmatched
  • Cloud Applicationsunmatched
  • Cloud Computingunmatched
  • Communication Skillsunmatched
  • Computer Securityunmatched
  • Cross-Functionalunmatched
  • Cryptographyunmatched
  • Customer Relationsunmatched
  • Customer Support/Serviceunmatched
  • Documentationunmatched
  • Documentation Modelsunmatched
  • Ecosystemsunmatched
  • Embedded Systemsunmatched
  • FDA (Food and Drug Administration)unmatched
  • ISO (International Organization for Standardization)unmatched
  • International Electro-Technical Commission (IEC)unmatched
  • Internet Securityunmatched
  • Leadershipunmatched
  • Medical Equipmentunmatched
  • Mentoringunmatched
  • Metricsunmatched
  • Patient Safetyunmatched
  • Presentation/Verbal Skillsunmatched
  • Process Developmentunmatched
  • Product Developmentunmatched
  • Product Documentationunmatched
  • Product Engineeringunmatched
  • Product Lifecycleunmatched
  • Product Supportunmatched
  • Quality Controlunmatched
  • Regulationsunmatched
  • Requirements Managementunmatched
  • Right-Sizingunmatched
  • Riskunmatched
  • Risk Analysisunmatched
  • Risk Managementunmatched
  • Security Architectureunmatched
  • Security Attacksunmatched
  • Security Designunmatched
  • Service Level Agreement (SLA)unmatched
  • Software Developmentunmatched
  • Software Development Lifecycle (SDLC)unmatched
  • Support Documentationunmatched
  • Systems Engineeringunmatched
  • Technical Presentationunmatched
  • Threat Modelingunmatched
  • Threat and risk analysis (TRA)unmatched
  • Time Managementunmatched
  • U.S. National Institute of Standards and Technology (NIST)unmatched
  • Usability Engineeringunmatched
  • White Papersunmatched
  • Wireless Multimedia Messaging Serviceunmatched
  • Writing Skillsunmatched

Be found by employers

5,500+ employers search our resume database daily. Add yours to get found by recruiters looking for candidates like you.

Level up your application

Professional resume templates

Browse dozens of recruiter approved resume templates, layouts and formats. Choose your favorite and make it your own in minutes.

Free resume templates

Free resume builder

Improve your existing resume or start from scratch and create a standout, ATS-friendly resume. Add job-specific content, download and apply.

Free resume builder