About this role
Job title: Product Cybersecurity Expert, Research & Development
About the Role Product Cybersecurity Expert in R&D to help protect the products and digital experiences that improve hearing health and human connection worldwide. You will combine product cybersecurity expertise with technical leadership responsibilities, supporting secure design, threat modeling, vulnerability management, DevSecOps integration, and regulatory evidence for connected medical devices while collaborating across global R&D, quality, regulatory, and product teams.
What You'll Do
- Embed cybersecurity across the secure product lifecycle for connected medical devices, embedded platforms, firmware, mobile apps, and cloud-based services
- Lead threat modeling, product cybersecurity risk assessments, and mitigation planning with global R&D teams
- Integrate security checks and tooling into development workflows and CI/CD pipelines to find and address issues early
- Drive product vulnerability management for Sonova products, including intake, triage, remediation tracking, and post-market monitoring
- Prepare audit-ready cybersecurity evidence for regulatory submissions and quality processes, including FDA, MDR, and IEC 81001-5-1 expectations
- Plan and coordinate security testing with internal teams and external partners; analyze findings and drive remediation
- Advise product, engineering, quality, and regulatory stakeholders on practical, risk-based security decisions
- Strengthen cybersecurity capability through coaching, security champions, and cross-functional collaboration
What We're Looking For
- 5+ years of experience in software engineering, system/software architecture, product development, project management, or DevSecOps, including 3+ years in cybersecurity
- Strong practical knowledge of secure SDLC, threat modeling, security assessments, security testing, and vulnerability management
- Experience translating security risks and technical findings into clear decisions for engineering, product, quality, and leadership audiences
- Understanding of modern development workflows, CI/CD, and how to integrate security without slowing innovation
- Knowledge of cryptography, authentication protocols, cloud and software supply chain security
- Basic understanding of AI technology and associated threats; hands-on experience using AI technology
- Higher-level engineering degree or equivalent experience, with further education or specialization in cybersecurity
- Excellent English communication skills and the ability to influence across distributed, cross-functional teams
Nice to Have
- Experience in medical devices, healthcare, or another regulated product environment
- Security certifications such as ISC2/CISSP, GIAC, or equivalent accredited programs
- Working knowledge of Privacy by Design principles
- A minimum of 200Mb/sec download and 10Mb/sec upload speed internet connectivity is required to support any remote/hybrid employee functionality at Sonova
Compensation & Benefits
- Pay range: $112,000 - $140,000 USD per year; bonus eligible
- Bonus eligibility
- How we work: Our team-customized hybrid work model empowers teams to balance individual needs with business goals, offering flexibility and individualized time management
- We are an equal opportunity employer; Sonova values diversity and inclusion