Technical Product Security Manager
Seeking a Technical Product Security Manager to lead product security across software, cloud, and medical device environments. The role involves driving vulnerability management, security hardening, and audit readiness, while supporting FDA submissions, FedRAMP, and other compliance requirements. The company is a medical device technology firm specializing in home sleep apnea tests, with a global presence and a commitment to improving patient outcomes.
Responsibilities
- Lead product security activities across applications, cloud services, infrastructure, and development processes.
- Support FDA, FedRAMP, customer audits, and other security compliance activities.
- Manage vulnerability review, CVE impact assessment, remediation tracking, and risk acceptance.
- Work with SBOM/BOM data, third-party components, open-source dependencies, and security scan results.
- Drive security hardening initiatives across products, environments, endpoints, and CI/CD pipelines.
- Partner with Engineering, DevOps, CloudOps, QA/RA, IT, and Security to identify gaps and ensure remediation.
- Support threat modeling, risk assessments, secure configuration reviews, and control validation.
- Prepare security evidence, procedures, guidelines, and technical summaries when needed.
- Track security action items, dependencies, timelines, and deliverables across teams.
Requirements
- B.Sc. in Computer Science, Information Systems, Cybersecurity, Engineering, or equivalent practical experience.
- 3-5 years of experience in product security, application security, DevSecOps, cloud security, infrastructure security, or technical security program management.
- Strong understanding of software development, cloud environments, CI/CD, operating systems, networking, and common security controls.
- Experience with vulnerability management, CVE analysis, remediation tracking, and security risk assessment.
- Experience working with engineering, DevOps, cloud, IT, or QA/RA teams on security improvements and remediation.
- Familiarity with security standards or regulatory frameworks such as FDA cybersecurity guidance, FedRAMP, NIST, ISO 27001, SOC 2, HIPAA, GDPR, or similar frameworks.
Nice to have
- Experience with medical device software, healthcare systems, SaaS products, or regulated environments.
- Experience supporting FDA submissions, FedRAMP activities, customer security reviews, or formal audits.
- Experience with SAST, DAST, SCA, container scanning, cloud security tools, endpoint security tools, and ticketing systems.
- Experience with AWS security services, IAM, encryption, logging, monitoring, and network segmentation.
- Experience with Kubernetes, Docker, CI/CD pipelines, and Infrastructure as Code.