Bachelors degree in computer science, Cybersecurity, Biomedical Engineering, or related field Bachelors degree in Computer Science, Cybersecurity, Biomedical Engineering, or related field
Strong understanding of medical device cybersecurity regulations (FDA pre/post market guidance)
Experience with FDA design controls and software validation processes
Knowledge of IEC 62304, ISO 14971, and other relevant medical device standards
Knowledge of compliance frameworks (SOC 2, ISO 27001, GDPR)
Demonstrated experience with security risk management in medical device development
Experience with security testing tools (e.g., Burp Suite, OWASP ZAP)
Knowledge of common web vulnerabilities, such as:
SQL Injection
Cross-Site Request Forgery
Understand Exploitation Techniques: Privilege escalation, lateral movement and escalation.
Knowledge of secure coding practices, cryptography, and authentication/authorization frameworks
Familiarity with CI/CD pipelines and DevSecOps practices
Knowledge of HIPAA compliance and healthcare data security
Experience with container security and Kubernetes
Strong communication skills and ability to explain security concepts to technical and non-technical stakeholders