
Senior Cloud Security Engineer, Healthcare Platform
Analog Devices4 days ago
Istanbul, TurkeySenior
Responsibilities
- Implement and maintain security controls across AWS cloud environments supporting connected medical devices, Software as a Medical Device, and digital health solutions.
- Integrate and manage security capabilities within CI/CD pipelines and secure software development lifecycle processes, including SAST, DAST, SCA, secrets scanning, container security scanning, and Infrastructure-as-Code security validation.
- Manage software supply chain security activities including SBOM generation, dependency management, artifact integrity validation, and vulnerability remediation.
- Configure and maintain identity and access management, authentication, authorization, encryption, key management, and secrets management solutions.
- Design and maintain audit logging, monitoring, HIPAA compliance controls, and healthcare data protection controls.
- Partner with software engineering teams to identify, prioritize, and remediate security vulnerabilities throughout the product lifecycle.
- Support security risk assessments, penetration testing, vulnerability management, incident response, and operational security activities.
- Build and maintain security automation to improve platform security, compliance, and operational efficiency.
- Support the reliability, availability, monitoring, and operational readiness of cloud-based production systems.
Requirements
- Bachelor's, Master's, or Ph.D. degree in Cybersecurity, Computer Science, Software Engineering, Computer Engineering, Information Security, or a related technical discipline.
- At least 5 years of experience in DevSecOps, Cloud Security, Security Engineering, Application Security, or related technical roles.
- Experience supporting software development for healthcare products, medical devices, or digital health solutions within established quality and compliance frameworks.
- Strong experience securing cloud-native applications and platforms running on AWS.
- Hands-on experience with AWS services including ECS, EKS, Lambda, RDS, S3, SQS, Cognito, IAM, KMS, and CloudFormation.
- Experience implementing and managing CI/CD pipelines using GitHub Actions or similar platforms.
- Experience with SAST, DAST, SCA, container security scanning, secrets detection, Infrastructure-as-Code security scanning, and vulnerability management solutions.
- Strong understanding of application security, secure coding, authentication, authorization, encryption, secrets management, and key management.
- Experience with software supply chain security, SBOM generation, dependency management, artifact signing, and vulnerability remediation.
- Experience with Infrastructure as Code technologies such as Terraform, CloudFormation, or AWS CDK.
- Understanding of OWASP guidance, cloud security best practices, and secure software development methodologies.
- Experience with containerized applications and orchestration platforms such as ECS, EKS, or Kubernetes.
- Experience implementing and supporting HIPAA-compliant cloud environments and healthcare data protection controls.
- Experience supporting security and compliance programs aligned with ISO 27001, SOC 2, or similar standards.
- Strong analytical, problem-solving, communication, and collaboration skills.
- Desired qualifications include experience with FDA-regulated products and IEC 62304, ISO 14971, FDA Cybersecurity Guidance, AI-powered or AI-assisted healthcare solutions, and security automation or DevSecOps improvement programs.
- Professional certifications such as CISSP, CSSLP, AWS Security Specialty, Security+, or Certified Kubernetes Security Specialist are desirable.
Benefits
- The role requires approximately 10% travel.
- The position is a 1st Shift/Days role.
- Applicants may be subject to export licensing review for access to technical data, except U.S. citizens, U.S. permanent residents, and protected individuals as defined by 8 U.S.C. 1324b(a)(3).
Tech Stack
Categories
About Analog Devices
Analog Devices, Inc. designs and sells analog, mixed-signal, RF, power, sensor, and digital signal processing ICs to OEMs across industrial, automotive, communications, consumer, and healthcare markets. Founded in 1965 and headquartered in Wilmington, Massachusetts, the NASDAQ-listed company earns revenue from catalog and application-specific semiconductors and supporting software used in applications from factory automation and vehicles to data centers and medical devices.