About this role
Product Security Engineer
Location: Minneapolis, MN
Country: United States
Employment: Contract
Worksite: On-Site
Job Description
Can you please confirm your top 3 skills sets required? Vulnerability Management, Security signal Analytics with automation/AI, Impact/Risk Analysis and report generation
What is your target years of experience? 3-8Years
Product Security Engineer, Consultant – Job Description
Position Overview
- Lead product cybersecurity operations across the product lifecycle, including incident response, continuous surveillance, vulnerability management, risk assessment, and security monitoring.
- Partner cross-functionally with Engineering, Quality, Regulatory, Product Management, PSO, Global-IT, and Operations to identify, prioritize, and mitigate cybersecurity risks.
Cybersecurity Incident Response
- Lead incident triage, investigation, containment, remediation, recovery, and root-cause analysis for product cybersecurity incidents.
- Coordinate cross-functional response teams, escalation, documentation, and regulatory/customer notification assessments.
Continuous Security Surveillance
- Monitor emerging threats, vulnerabilities, exploits, security advisories, and threat intelligence relevant to the product portfolio.
- Assess emerging threats and proactively identify potential product exposure and required security actions.
Vulnerability Management
- Lead end-to-end vulnerability management, from identification and risk assessment through remediation, mitigation, and closure.
- Prioritize vulnerabilities based on severity, exploitability, exposure, product impact, and business/regulatory risk.
Cybersecurity Risk & Impact Assessment
- Conduct cybersecurity risk and impact assessments across the product lifecycle, including threats, vulnerabilities, attack paths, and security controls.
- Translate technical findings into product, patient/customer, business, and regulatory risk and recommend appropriate mitigation or risk acceptance.
SIEM / SOC & Security Monitoring
- Integrate product cybersecurity signals, telemetry, threat intelligence, and vulnerability data into security monitoring.
- Define monitoring requirements, detection use cases, alerting, escalation criteria, and opportunities for automated threat detection.
Leadership Communication
- Provide timely executive communication on significant incidents, emerging vulnerabilities, cybersecurity risk, and remediation status.
- Translate complex technical issues into concise risk assessments, recommendations, decisions, and business impact for senior leadership.
Cross-Functional Collaboration
- Collaborate with Engineering, Software/Firmware, Quality, Regulatory, Product Management, Operations, and IT teams.
- Drive cybersecurity alignment across product development, deployment, monitoring, post-market surveillance, and lifecycle management.
Continuous Improvement
- Develop and mature cybersecurity processes, tools, automation, metrics, and operating models to improve security posture and response effectiveness.
- Establish KPIs/KRIs, dashboards, lessons-learned processes, and continuous improvement initiatives across product cybersecurity operations.
Qualifications
-
Bachelor’s or Master’s degree in Cybersecurity, Computer Science, Engineering, Information Technology, or related field, with significant cybersecurity experience.
-
3Years+ experience in product cybersecurity, incident response, vulnerability management, threat intelligence, security operations, and cybersecurity risk management.
-
Preferred Experience
-
Experience with Product Security, SIEM/SOC, vulnerability/exposure management, threat modeling, security architecture, and post-market cybersecurity.
-
Experience with regulated or safety-critical industries and frameworks such as FDA cybersecurity requirements, IEC 81001-5-1, ISO 14971, IEC 62443, or ISO 27001.
-
Leadership Competencies
-
Strong cybersecurity leadership, risk-based decision making, executive communication, and cross-functional influence.
-
Ability to lead through high-pressure incidents, translate technical complexity into business decisions, and drive measurable security improvements.
-
Equal Opportunity Employer
-
We are proud to be an equal opportunity employer. We welcome and encourage applications from all qualified candidates regardless of race, sex, gender identity or expression, disability, age, religion or belief, sexual orientation, or any other characteristic protected by applicable laws and regulations. It is our policy not to discriminate against any applicant or employee, and we are committed to fostering a diverse, inclusive, and respectful work environment across all locations in which we operate. We believe that diversity, equity, and inclusion are fundamental to our mission and enhance our ability to serve clients globally. If you have a disability or require any reasonable accommodations during the application or interview process, please inform your recruiter or contact us directly so that we can explore the appropriate arrangements.
-
Fraud Alert
-
Candidate safety is a top priority at Planet Pharma. The industry has seen an increase in people falsely representing themselves as recruiters to gather personal information from job seekers. For your safety, do not provide sensitive data to anyone you have not spoken with thoroughly, never provide banking information during the application process and always double check the email address of the Recruiter to ensure it’s from an official Planet Pharma domain and not a domain with an alternative extension like .net, .org or .jobs.
-
Related Jobs
-
Stay up to date with the latest opportunities
-
Location
-
Remote, Massachusetts
Category:
- Medical Affairs
Type:
- Contract
Worksite:
- On-Site