Verathon, Inc.

Cybersecurity Engineer

Verathon, Inc.
Apply
1 month ago
Bothell, WA, USASenior

Base Salary

$148k - $182k/yr

Responsibilities

  • Define product security architecture covering assets, trust boundaries, control objectives, interfaces, authentication, authorization, cryptography, secure updates, logging, data integrity, and system hardening.
  • Lead system-level threat modeling and allocate mitigations across hardware, firmware, and software.
  • Derive cybersecurity requirements from FDA guidance and applicable medical-device standards, and define verification strategies and evidence ownership.
  • Maintain security architecture documentation, requirements traceability matrices, interface records, the Product Security Management Plan, and the Product Security Management File.
  • Lead third-party penetration-testing engagements, including scope clarification, environment setup, findings assessment, remediation planning, and retest readiness.
  • Define and coordinate post-release remediation scope, verification, deployment, and documentation closure.
  • Conduct interoperability security assessments and evaluate security and safety risks across device interfaces and operating modes.
  • Perform CVE impact analysis, vulnerability triage, CVSS-based assessment, and remediation scoping for fielded products.
  • Support security-driven release readiness, quality-system activities, design reviews, ECO procedures, and regulatory-submission artifacts.
  • Collaborate across Systems, Software, Quality, and Regulatory teams and monitor evolving FDA, EU, NIST, and medical-device security guidance.

Requirements

  • Bachelor’s degree in Systems Engineering, Electrical Engineering, Computer Engineering, or a related technical discipline.
  • At least 5 years of cybersecurity engineering, product security engineering, or related experience, including at least 3 years focused on connected or regulated products.
  • Demonstrated experience with system-level threat modeling methods such as STRIDE, PASTA, or TARA.
  • Working knowledge of FDA premarket and postmarket cybersecurity guidance, IEC 81001-5-1, AAMI SW96, and IEC 62443.
  • Experience defining security requirements and producing verification evidence in a regulated product-development environment; FDA QSR and ISO 13485 QMS experience is preferred.
  • Experience with CVE/NVD triage, system-level vulnerability impact assessment, CVSS scoring, and cybersecurity risk assessment methodologies.
  • Working knowledge of networking fundamentals, Linux and/or Windows security concepts, and connected medical-device environments.
  • Working knowledge of architecture and modeling tools such as Visio, PlantUML, or basic SysML.
  • Strong written communication skills and the ability to produce clear, audit-ready technical documentation.
  • Relevant security certification such as CISSP, CISM, CEH, or CompTIA Security+ is preferred; equivalent demonstrated experience may be considered.
  • Experience supporting or managing third-party penetration testing is strongly preferred.
  • Familiarity with SBOM concepts and supply-chain security for medical devices is an asset.

Benefits

  • Competitive benefits package including medical, dental, vision, basic life insurance, paid holidays, paid time off, and a 401(k) matching plan.
  • Eligible full-time employees not on a commission plan may participate in the annual bonus plan based on company and individual performance.
  • Position is located on the R&D team in Bothell, Washington.

Tech Stack

LinuxWindows

Categories

Verathon, Inc.

About Verathon, Inc.

501-1,000 employees
Contact me