About Pramana. Pramana, Inc., enables digital transformation for next-generation pathology at medical centers, pathology labs, and biorepositories. Pramana offers a first-in-class Digital Pathology as a Service (DPaaS) solution by providing a turnkey service with cutting-edge whole slide imaging systems and a scalable software platform for clinical workflows
Pramana is a gateway for pathologists to utilize AI-enabled decision support. The company is headquartered in Cambridge, Mass., and backed by Matrix Capital Management Company, L.P., a global leader in customized investment solutions, and NTTVC, a leading firm backing diverse founders within the technology spectrum
Visit us at https://pramana.ai/ to learn more
About The Role. We are seeking a highly skilled and experienced Cybersecurity Professional to join our team
This role is critical in ensuring that our digital pathology solutions meet regulatory requirements and maintain the highest standards of cybersecurity. The ideal candidate will have a deep understanding of medical device cybersecurity, regulatory compliance, and quality management systems, particularly in the context of FDA, CE Mark, and US Federal Government. requirements
Key Responsibilities. Regulatory Compliance:. Ensure compliance with FDA cybersecurity guidelines for medical devices, including risk management and mitigation strategies
Prepare and maintain technical documentation required for CE marking under the EU MDR
Lead efforts to comply with the stringent cybersecurity requirements of the US Federal. Government, the Joint Pathology Center, and the Defense Health Agency
FDA 510(k) Submission. Ensure all necessary documentation for 510(k) submissions, including a description of the device's security features and risk management approach, is prepared and submitted
Collaborate with regulatory affairs to demonstrate substantial equivalence to legally marketed devices, facilitating market clearance
Risk Management. Conduct comprehensive risk assessments to identify potential cybersecurity threats and vulnerabilities
Develop and implement risk mitigation strategies to protect our digital pathology systems
Authority To Operate (ATO) Process. Navigate the ATO process as outlined in the ISACA Journal, ensuring that our IT security policies, procedures, and controls meet federal standards
Prepare and submit necessary documentation and validation reports for obtaining and. maintaining the ATO
Quality Management System (QMS). Integrate cybersecurity best practices into our ISO 13485 certified QMS
Develop and maintain cybersecurity policies and procedures in line with ISO 13485 standards
Support internal and external audits by providing evidence of cybersecurity measures and their effectiveness
Continuous Monitoring And Incident Response. Implement continuous monitoring processes to detect and respond to cybersecurity incidents promptly
Develop and maintain incident response plans to address and mitigate the impact of cybersecurity breaches
Collaboration And Training. Work closely with cross-functional teams, including product development, IT, and regulatory affairs, to ensure cybersecurity is considered at every stage of the product lifecycle
Provide cybersecurity training and awareness programs for employees to foster a culture of security
Qualifications. Bachelor’s degree in Computer Science, Information Security, or a related field; advanced degree preferred
Minimum of 5 years of experience in cybersecurity, preferably in the medical device or healthcare industry
In-depth knowledge of FDA cybersecurity guidelines, EU MDR requirements, and US Federal Government cybersecurity standards
Experience with ISO 13485 and integrating cybersecurity into QMS
Proven track record of successfully navigating the ATO process
Strong understanding of risk management principles and methodologies
Excellent problem-solving skills and attention to detail
Strong communication and collaboration skills
Certifications (Preferred). Certified Information Systems Security Professional (CISSP). Certified Information Security Manager (CISM). Certified Information Systems Auditor (CISA). Certified in Risk and Information Systems Control (CRISC). Show more Show less