iRhythm

Senior Product Security Manager

iRhythm
Apply
2 hours ago
Remote, United StatesStaff+

Base Salary

$151k - $196k/yr

Responsibilities

  • Provide senior-level cybersecurity leadership across product development and influence secure design decisions.
  • Drive adoption and continuous improvement of secure product development framework and secure SDLC practices.
  • Translate cybersecurity risks into actionable guidance for engineering and business stakeholders.
  • Ensure compliance with FDA cybersecurity guidance, Section 524B, HIPAA, GDPR, and related regulatory requirements.
  • Develop cybersecurity documentation supporting pre-market and post-market regulatory requirements.
  • Lead threat modeling, cybersecurity risk assessments, security design reviews, and data flow diagram development.
  • Review secure architectures across embedded systems, applications, cloud, and IoMT platforms.
  • Oversee vulnerability detection, scanning, remediation, coordinated disclosure, incident response, and post-market monitoring.
  • Oversee SBOM management, third-party risk, and software supply chain security.
  • Partner with Product, R&D, Quality, Regulatory, Privacy, Cloud, and Cybersecurity teams to embed security throughout the product lifecycle.

Requirements

  • Bachelor’s degree in Computer Science, Information Security, or a related field.
  • 12+ years of experience in product security or related cybersecurity roles.
  • Deep expertise securing complex, software-driven, safety-critical systems.
  • Strong knowledge of secure design, threat modeling, vulnerability management, and SDLC practices.
  • Experience operating in regulated environments involving FDA, HIPAA, and GDPR.
  • Familiarity with NIST, ISO 14971, IEC 62304, and related standards.
  • Proven ability to influence cross-functional teams and drive security outcomes.
  • Experience with medical devices, healthcare technology, or IoMT systems.
  • Professional certifications such as CISSP, CISM, or CRISC are preferred.
  • Experience with CI/CD security tooling, including SAST, DAST, SCA, and shift-left practices, is preferred.
  • Familiarity with EU MDR, GDPR, and ISO/IEC 81001-5-1 is preferred.
  • Experience supporting SBOM programs and PSIRT operations is preferred.
  • Understanding of penetration testing methodologies is preferred.

Benefits

  • Remote position in the US.
  • Estimated base pay range of $151,000.00 to $196,000.00.
  • Inclusive workplace and reasonable accommodations for qualified individuals with disabilities.

Categories

Contact me