About this role
Job Requirements Role Summary:
• Serve as the Product Security Representative for multiple Imaging 360 products and releases, representing cybersecurity and privacy requirements throughout the product lifecycle. • Drive execution of the GEHC DEPS process, including security and privacy planning, threat modeling, cybersecurity risk assessment, secure design reviews, vulnerability management, lifecycle security artifacts, and phase-appropriate security deliverables from concept through development and evaluation. • Own Security Design Reviews across the product lifecycle, including concept definition, architecture and design, development execution, verification / evaluation, and release readiness for Imaging360 capabilities and integrations. • Partner with Product Security Leaders and product teams to interpret and apply GEHC cybersecurity standards, regulatory expectations, and quality management system requirements. • Lead threat modeling and security architecture reviews for cloud-hosted enterprise applications, APIs, data flows, scanner connectivity, on-premises integrations, identity services, and third-party product integrations. • Assess cybersecurity risks associated with hybrid deployments involving cloud services, customer networks, on-premises scanners, edge components, and external vendor systems. • Define and influence implementation of security controls for authentication, authorization, encryption, audit logging, secrets management, network segmentation, secure communication, data protection, and system hardening. • Own or support cybersecurity management plans, vulnerability triage, remediation planning, risk acceptance discussions, and closure tracking across multiple product teams. • Coordinate SAST, SCA, DAST, penetration testing, infrastructure scanning, container security, cloud security reviews, and remediation activities in partnership with engineering and operations teams. • Generate, maintain, and assess Software Bill of Materials (SBOM) content, including open-source, commercial, and third-party components integrated into the product. • Evaluate third-party product integrations for cybersecurity, privacy, data protection, interface security, supportability, and operational risk. • Collaborate with architecture, platform, DevOps, cloud operations, quality, regulatory, privacy, and program teams to ensure secure-by-design and compliant delivery. • Provide cybersecurity guidance to scrum teams, review design and implementation decisions, and help teams adopt secure SDLC and DevSecOps practices. • Support fielded product security activities, including vulnerability impact assessments, customer notifications, remediation planning, patch strategy, and lifecycle risk management. • Champion Imaging 360-level security KPI reporting, governance dashboards, and ongoing monitoring of security health indicators, including vulnerability posture, remediation progress, open risks, security test coverage, SBOM readiness, and DEPS compliance status. • Prepare clear technical and leadership-level communication on security posture, risks, remediation status, and product security readiness
Work Experience Qualifications
• Bachelor’s degree in Computer Science, Computer Engineering, Cybersecurity, Information Security, Software Engineering, or a related STEM discipline. • 12+ years of experience in software engineering, product security, application security, cloud security, or cybersecurity engineering for enterprise products. • Hands-on experience securing cloud-hosted enterprise applications and distributed systems, preferably in AWS, Azure, or similar cloud environments. • Experience with enterprise products that integrate with on-premises systems, connected devices, customer networks, or scanner / equipment workflows. • Strong understanding of secure software development lifecycle practices, threat modeling, cybersecurity risk management, vulnerability management, and security control implementation. • Working knowledge of application, API, container, infrastructure, network, and cloud security concepts. • Experience with security assessment tools and practices such as SAST, SCA, DAST, penetration testing, container scanning, cloud posture management, SBOM generation, and dependency vulnerability analysis. • Knowledge of OWASP Top 10, secure coding principles, identity and access management, encryption, audit logging, secure communications, and privacy-by-design principles. • Ability to work effectively in a regulated product development environment and maintain compliance with quality, privacy, and cybersecurity processes. • Demonstrated technical leadership, stakeholder management, and communication skills across engineering, product, quality, regulatory, security, and leadership audiences. Desired Skills
• Experience serving as a Product Security Representative, security architect, or product security owner for multiple products or releases. • Experience with healthcare software, medical device software, imaging workflows, DICOM environments, or connected clinical systems. • Familiarity with GEHC DEPS or equivalent product cybersecurity lifecycle processes in regulated industries. • Understanding of applicable cybersecurity and privacy frameworks such as FDA cybersecurity guidance, NIST, ISO 27001, IEC 81001-5-1, HIPAA, GDPR, SOC 2, or similar standards. • Experience assessing third-party products, SaaS services, APIs, vendor integrations, and data exchange workflows for cybersecurity and privacy risk. • Hands-on experience with tools such as threat modeling tools, Black Duck, Syft, Grype, SonarQube, Burp Suite, Wiz, Twistlock / Prisma Cloud, or equivalent security platforms. • Experience with DevSecOps practices, CI/CD security gates, automated security testing, infrastructure-as-code security, container security, and cloud-native monitoring. • Strong understanding of identity federation and access control technologies such as SAML, OAuth, OIDC, SCIM, RBAC, and least-privilege access models. • Security certifications such as CISSP, CSSLP, CISM, CCSP, CEH, or equivalent credentials are a plus. • Ability to influence without authority, simplify complex security topics, and drive timely risk-based decisions across global and cross-functional teams.