Talent.com
Senior Product Security Analyst
Senior Product Security AnalystiRhythm Technologies, Inc. • San Francisco, CA, United States
Senior Product Security Analyst

Senior Product Security Analyst

iRhythm Technologies, Inc. • San Francisco, CA, United States
7 days ago
Job type
  • Full-time
Job description

Career-defining. Life-changing.

At iRhythm, you'll have the opportunity to grow your skills and your career while impacting the lives of people around the world. iRhythm is shaping a future where everyone, everywhere can access the best possible cardiac health solutions. Every day, we collaborate, create, and constantly reimagine what's possible. We think big and move fast, driven by our commitment to put patients first and improve lives. We need builders like you. Curious and innovative problem solvers looking for the chance to meaningfully shape the future of cardiac health, our company, and your career

About This Role : Key Responsibilities

  • FDA Cybersecurity Compliance : Ensure compliance with FDA cybersecurity guidance and regulations in collaboration with Cybersecurity, Regulatory, Quality, and Systems Development teams.
  • Risk Assessments & CSRAs : Conduct comprehensive security risk assessments, including Cybersecurity Risk Assessments (CSRAs) , to identify vulnerabilities and threats across device hardware, firmware, software, and cloud components.
  • Threat Modeling : Develop and maintain device-specific cyber threat models, factoring in patient safety, data privacy, and operational continuity.
  • SBOM Management : Demonstrate familiarity with Software Bill of Materials (SBOM) and effectively communicate technical details.
  • Security Documentation : Create and maintain cybersecurity documentation for pre- and post-market activities, ensuring regulatory alignment.
  • Data Flow Diagrams : Produce detailed data flow diagrams to support the threat modeling process.
  • Security Design Reviews : Participate in design reviews of medical device architectures and implementations, providing actionable recommendations for system security requirements.
  • Vulnerability Analysis & Management : Perform and support vulnerability analysis and coordinate the vulnerability management program, including scanning, patching, and remediation for medical devices.
  • Threat Detection Tools : Leverage and maintain application and threat detection tools (Veracode, Snyk, GitLab, or equivalent) to identify security flaws early in the SDLC.
  • Incident Response : Support investigation and remediation of device-related security incidents, minimizing impact and preventing recurrence.
  • Data Privacy Compliance : Partner with the Privacy Team to ensure adherence to HIPAA, GDPR, and other data protection regulations.

Required Qualifications

  • Bachelor's degree in Computer Science, Information Security, or related field.
  • 8+ years of experience in information security, with direct focus on product security for medical devices .
  • Strong understanding of security principles, methodologies, and tools within the PDLC and SDLC.
  • Demonstrated experience conducting Cybersecurity Risk Assessments (CSRAs) , vulnerability analysis , and working with modern threat detection tools (Veracode, Snyk, GitLab, or similar).
  • Familiarity with NIST Cybersecurity Framework, NIST SP 800-171, and deeper controls / frameworks such as NIST SP 800-53 (Security and Privacy Controls), NIST SP 800-92 (Log Management), and NIST SP 800-63 (Digital Identity Guidelines).
  • Hands-on experience with vulnerability identification and threat modeling within healthcare using methodologies such as STRIDE.
  • Experience operating in a regulated environment (FDA, HIPAA, GDPR, international regulatory frameworks).
  • Experience with medical device hardware or Software as a Medical Device (SaMD).
  • Experience with medical device software development and regulatory processes.
  • Excellent problem-solving, analytical, and communication skills, able to take a multi-siloed approach.
  • Ability to understand intro dependencies of teams across; mobile applications, hardware and cloud environments.
  • Proven track record of 510k experience and completion.
  • Preferred Qualifications

  • Industry certifications such as CISSP, CISM, CISA, or medical device security-specific certifications.
  • Experience with international frameworks and standards (EU MDR, JIS T 2304 / IEC 62304).
  • Understanding penetration testing methodologies and tools, able to work with pen test teams independently with little guidance.
  • Proficiency with programming languages and technologies commonly used in medical device development.
  • Location : San Francisco

    Actual compensation may vary depending on job-related factors including knowledge, skills, experience, and work location.

    Estimated Pay Range $141,450.00 - $184,000.00

    As a part of our core values, we ensure an inclusive workforce. We welcome and celebrate people of all backgrounds, experiences, skills, and perspectives. iRhythm Technologies, Inc. is an Equal Opportunity Employer. We will consider for employment all qualified applicants with arrest and conviction records in accordance with all applicable laws.

    iRhythm provides reasonable accommodations for qualified individuals with disabilities in job application procedures, including those who may have any difficulty using our online system. If you need such an accommodation, you may contact us at taops@irhythmtech.com

    About iRhythm Technologies iRhythm is a leading digital healthcare company that creates trusted solutions that detect, predict, and prevent disease. Combining wearable biosensors and cloud-based data analytics with powerful proprietary algorithms, iRhythm distills data from millions of heartbeats into clinically actionable information. Through a relentless focus on patient care, iRhythm's vision is to deliver better data, better insights, and better health for all.

    Make iRhythm your path forward. Zio, the heart monitor that changed the game.

    There have been instances where individuals not associated with iRhythm have impersonated iRhythm employees pretending to be involved in the iRhythm recruiting process, or created postings for positions that do not exist. Please check any communications to be sure they come directly from @irhythmtech.com email address. If you believe you have been the victim of an imposter or want to confirm that the person you are communicating with is legitimate, please contact taops@irhythmtech.com. Written offers of employment will be extended in a formal offer letter from an @irhythmtech.com email address ONLY.

    For more information, see https : / / www.ftc.gov / business-guidance / blog / 2023 / 01 / taking-ploy-out-employment-scams and https : / / www.ic3.gov / Media / Y2020 / PSA200121

    #J-18808-Ljbffr

    Create a job alert for this search

    Senior Product Analyst • San Francisco, CA, United States

    Related jobs
    Senior Product Security Engineer

    Senior Product Security Engineer

    VirtualVocations • Oakland, California, United States
    Full-time
    A company is looking for a Senior Product Security Engineer, Server.Key Responsibilities Take ownership and drive improvement for security programs such as fuzzing, threat modeling, and container...Show more
    Last updated: 30+ days ago • Promoted
    Senior IT Security Analyst

    Senior IT Security Analyst

    VirtualVocations • San Francisco, California, United States
    Full-time
    A company is looking for a Senior IT Security Analyst responsible for assessing information risk and facilitating remediation of identified vulnerabilities across the enterprise.Key Responsibilitie...Show more
    Last updated: 30+ days ago • Promoted
    Security Product Manager

    Security Product Manager

    VirtualVocations • Oakland, California, United States
    Full-time
    A company is looking for a Principal Security Product Manager.Key Responsibilities : Partner with domain leadership to set product vision and strategy Develop and execute multi-year domain roadma...Show more
    Last updated: 2 days ago • Promoted
    Senior Product Analyst

    Senior Product Analyst

    GTMnow • San Francisco, CA, United States
    Full-time
    Owner is the all-in-one platform that restaurants use to succeed online.Thousands of restaurant owners use our tools to build their website, drive online orders, create their own branded app, manag...Show more
    Last updated: 30+ days ago • Promoted
    Senior Product Analyst

    Senior Product Analyst

    VirtualVocations • Santa Clara, California, United States
    Full-time
    A company is looking for a Senior Product Analyst - Remote.Key Responsibilities Own and evolve product KPI frameworks and performance monitoring Design and implement experimentation programs and...Show more
    Last updated: 30+ days ago • Promoted
    Senior Analyst, Security Governance, Risk, and Compliance (Remote)

    Senior Analyst, Security Governance, Risk, and Compliance (Remote)

    Jazz Pharmaceuticals • Palo Alto, CA, United States
    Remote
    Full-time
    If you are a current Jazz employee please apply via the Internal Career site.Jazz Pharmaceuticals is a global biopharma company whose purpose is to innovate to transform the lives of patients and ...Show more
    Last updated: 22 days ago • Promoted
    Senior Software Engineer, Product Security

    Senior Software Engineer, Product Security

    ZipHQ, Inc. • San Francisco, CA, United States
    Full-time
    The simple task of buying software, services, or tools at work has become hopelessly complicated at even the most innovative companies in the world. Today, enterprises spend $120T+ per year globally...Show more
    Last updated: 24 days ago • Promoted
    Senior Product Analyst

    Senior Product Analyst

    Owner.com • San Francisco, CA, United States
    Full-time
    We’re building an effective, impactful Product Analytics function at.As a Senior Product Analyst, you will play a pivotal role in shaping the product roadmap through close collaboration with Produc...Show more
    Last updated: 30+ days ago • Promoted
    Senior Product Manager, AI Security

    Senior Product Manager, AI Security

    hackerone • San Francisco, CA, United States
    Full-time
    HackerOne is a global leader in offensive security solutions.Our HackerOne Platform combines AI with the ingenuity of the largest community of security researchers to find and fix security, privacy...Show more
    Last updated: 14 days ago • Promoted
    Senior Product Security Consultant

    Senior Product Security Consultant

    VirtualVocations • Santa Clara, California, United States
    Full-time
    A company is looking for a Senior Product Security Consultant to join their Product Security Services team.Key Responsibilities Own and lead product security consulting engagements end-to-end, in...Show more
    Last updated: 1 day ago • Promoted
    Senior Product Manager - AI Security

    Senior Product Manager - AI Security

    Snowflake • Menlo Park, CA, US
    Full-time
    Senior Product Manager At Snowflake.Snowflake empowers more than 10,000 organizations worldwide to unlock the full potential of AI-driven data, shaping the future of intelligent business.As compani...Show more
    Last updated: 30+ days ago • Promoted
    Senior Product Security Analyst

    Senior Product Security Analyst

    El Camino Health • San Francisco, CA, United States
    Full-time
    Senior Product Security Analyst page is loaded## Senior Product Security Analystlocations : San Francisco, CAtime type : Full timeposted on : Posted Yesterdayjob requisition id : JR704 • •Career-...Show more
    Last updated: 8 days ago • Promoted
    Senior Product Security Engineer

    Senior Product Security Engineer

    Epoch Biodesign • San Francisco, CA, United States
    Full-time
    Crusoe Energy is on a mission to unlock value in stranded energy resources through the power of computation.Take a look at what we do! https : / / www. We aim to align the long term interests of the cli...Show more
    Last updated: 30+ days ago • Promoted
    Senior Manager, Product Security

    Senior Manager, Product Security

    TiVo Corporation • San Jose, CA, United States
    Full-time
    Xperi invents, develops and delivers technologies that create extraordinary experiences at home and on the go for millions of people around the world. Powering billions of consumer electronics, conn...Show more
    Last updated: 30+ days ago • Promoted
    Senior Product Analyst

    Senior Product Analyst

    Neonpay • San Francisco, CA, United States
    Full-time
    Neon is a global payments and e-commerce platform designed to help game publishers earn more money and independence from app stores. We believe commerce should be open and transparent : clear decisio...Show more
    Last updated: 7 days ago • Promoted
    Senior Manager, Product Security

    Senior Manager, Product Security

    Xperi • San Jose, CA, United States
    Full-time
    Xperi invents, develops and delivers technologies that create extraordinary experiences at home and on the go for millions of people around the world. Powering billions of consumer electronics, conn...Show more
    Last updated: 30+ days ago • Promoted
    Senior Product Analyst

    Senior Product Analyst

    Neon • San Francisco, CA, United States
    Full-time
    Neon is a global payments and e-commerce platform designed to help game publishers earn more money and independence from app stores. We believe commerce should be open and transparent : clear decisio...Show more
    Last updated: 6 days ago • Promoted
    Senior Product Engineer - Security and Compliance

    Senior Product Engineer - Security and Compliance

    Rippling • San Francisco, CA, United States
    Full-time
    Senior Product Engineer - Security and Compliance.Rippling gives businesses one place to run HR, IT, and Finance.It brings together all of the workforce systems that are normally scattered across a...Show more
    Last updated: 13 days ago • Promoted