About this role
Job title: Cybersecurity and Data Protection Software Quality Engineer
About the Role The Software Quality Engineer is an experienced cybersecurity and data protection professional responsible for ensuring FMI software-enabled medical devices and the FMI quality system comply with cybersecurity expectations from patients, physicians, partners, and regulators, preventing breaches and enabling rapid remediation when incidents occur. The role acts as a bridge between FMI Product Owners, Software Owners, Software Engineering, IT, Data Privacy and Regulatory Affairs to embed security by design into the Quality Management System (QMS) and to lead efforts to implement a Secure Product Development Framework (SPDF) and support premarket submissions (De Novo, PMA, 510(k)).
What You'll Do
- Provide regulatory alignment & QMS management: guide QMS procedures to align with cybersecurity protection requirements, integrating SPDF, threat modeling, and SBOM management into Design Controls.
- Premarket Submission Support: review and approve comprehensive cybersecurity documentation for regulatory compliance, including Security Risk Management Reports, Threat Models, and Security Architecture views.
- SBOM Management: ensure development and maintenance of compliant, machine-readable SBOM (e.g., SPDX or CycloneDX) for all software components, tracking vulnerabilities (CVEs) and managing supplier risks.
- Risk Assessment & Verification/Validation Oversight: collaborate with Product Owners, System Owners, Information Security and Data Privacy to conduct cybersecurity risk assessments; review and approve cybersecurity and data protection requirements and verification results (vulnerability analysis, penetration testing).
- Post-market Surveillance & Patching: support development and implementation of post-market software cybersecurity vulnerability monitoring; review and approves SOPs for timely patching and updating of fielded devices.
- Cross-Functional Collaboration: act as SME advising FMI stakeholders on medical device regulations, guidance, conformity and standards, and best practices during the SDLC.
- Audit Preparation: support FDA and Notified Bodies audits regarding software validation and cybersecurity compliance.
- Supplier Management: collaborate with Product Owners, System Owners, Information Security and Data Privacy in supplier identification, onboarding and management to meet cybersecurity and data protection requirements.
- Quality Management System: maintain documentation of security guidelines, procedures, standards, and controls.
What We're Looking For
- Basic Qualifications: Bachelor’s degree in information systems/IT or related field.
- 2+ years of experience in software quality assurance or cybersecurity in a regulated environment (healthcare or similar).
- Deep knowledge of IT including hardware, software, and networks.
- Direct experience with regulatory or notified body cybersecurity submissions.
- Experience with ISO 13485, IEC 62304, ISO 14971.
Nice to Have
- Meticulous attention to detail and multitasking in a fast-paced environment.
- Strong critical thinking, problem-solving, logic, and forensics.
- Excellent verbal and written communication.
- Ability to work independently and in teams.
- Hacker mindset to anticipate threats.
- Understanding of HIPAA and data privacy regulations.
- Commitment to FMI values: Integrity, Courage, and Passion.
Compensation & Benefits
- Salary range: $93,500 – $116,500 per year.
- A discretionary annual bonus may be available based on individual and company performance.
- This position qualifies for Foundation Medicine’s benefits.