
Product Security Specialist for Medical Devices (Cyber Security)
PA Consulting8 months ago
London, United KingdomSenior
Responsibilities
- Determine objectives, scope, timelines, and delivery methodologies for product security initiatives with client product and functional teams.
- Assess security risks across medical-device and product portfolios and recommend remediation strategies while balancing business and technical requirements.
- Advise on coding practices, threat modeling, and security testing for embedded systems and IoT devices while supporting regulatory compliance.
- Lead secure code reviews, threat modeling, security risk assessments, vulnerability assessments, and validation and verification of controls with client R&D teams.
- Monitor emerging cybersecurity threats in the IoT and medical-device landscape and produce thought leadership.
- Build stakeholder relationships, foster team growth and training, manage projects, solve problems through a consulting approach, and support business development.
Requirements
- At least 5 years of relevant experience in the medical-device industry or through consulting or service-provider work.
- Proficiency with NIST, OWASP, MITRE ATT&CK, PASTA, and STRIDE, as well as standards and regulations including FDA cybersecurity guidance.
- Experience assessing security risks using penetration-test results, threat modeling, and security testing, and determining residual risk after compensating controls are applied.
- Experience implementing and demonstrating compliance with NIST, IEC, HITRUST, HIPAA, GDPR, ISO 27001, and SOC 2 Type 2, with familiarity working with Quality Management Systems.
- Experience working with teams in a structured software development lifecycle process.
- Cybersecurity qualifications such as CISSP, CSSLP, or CISM are expected or valued.
- Strong written and verbal communication, analytical problem-solving, stakeholder collaboration, relationship-building, proposal development, and client business-development skills.
- Applicants for applicable UK roles must meet Baseline Personnel Security Standard and, where required, higher UK security-clearance residency requirements.
Benefits
- Hybrid working with a minimum of two days per week in the office or on a client site, with assignments potentially requiring up to five days per week on a client site.
- Budget for technical and non-technical courses and certifications, plus access to coaching, mentoring, and peer knowledge-sharing.
- Private healthcare for employees and families, 25 days of annual leave plus a bonus half day on Christmas Eve, and the option to buy five additional days.
- Generous company pension scheme, annual performance-based bonus, PA share ownership, and tax-efficient benefits including cycle to work and give as you earn.
- Opportunities to participate in community and charity initiatives and access to physical, emotional, social, and financial wellbeing support.