Cybersecurity Engineer III
$125,000–$193,400 year
On-siteBurnaby, British Columbia, Canada
Job Summary
Define product security architecture, including trust boundaries and control objectives, while deriving cybersecurity requirements from FDA guidance and consensus standards like IEC 62443. Lead system-level threat modeling and allocate mitigations across hardware, firmware, and software, ensuring trust-boundary assumptions are explicit and testable. Produce design-level documentation such as architecture views, security requirements traceability matrices, and interface records to satisfy regulatory expectations throughout the product lifecycle. Own engineering interfaces during penetration testing engagements, assess design impacts of findings, and define remediation approaches for post-release updates. Collaborate cross-functionally with Software, Quality, and Regulatory teams to align on security decisions and maintain the Product Security Management Plan. Stay current with evolving FDA cybersecurity guidance and NIST CSF to identify implications for Verathon products.
Required Qualifications
- Bachelor's degree in Systems Engineering, Electrical Engineering, Computer Engineering, or a related technical discipline
- 5+ years of demonstrated experience in systems engineering, product security engineering, or a related field
- at least 3 years focused on cybersecurity for connected or regulated products
- Demonstrated experience with system-level threat modeling methodologies (e.g., STRIDE, PASTA, or TARA as defined in IEC 81001-5-1 / AAMI SW96)
- Working knowledge of medical device cybersecurity regulatory requirements, including FDA premarket and postmarket cybersecurity guidance, IEC 81001-5-1, AAMI SW96, and IEC 62443
- Experience defining security requirements and producing verification evidence in a regulated product development environment (FDA QSR / ISO 13485 QMS)
- Experience with CVE/NVD triage and vulnerability impact assessment at the system level including CVSS-based vulnerability scoring and cybersecurity risk assessment methodologies
- Working knowledge of networking fundamentals (ports, protocols, firewalls) and OS-level security concepts across Linux and/or Windows environments relevant to connected medical devices
Desired Qualifications
- Experience supporting or managing third-party penetration testing engagements, including findings triage and remediation scoping
- Experience defining security requirements and producing verification evidence in a regulated product development environment (FDA QSR / ISO 13485 QMS) preferred
- Relevant security certification (e.g., CISSP, CISM, CEH, CompTIA Security+, or equivalent)
- candidates with equivalent demonstrated experience will be considered
- Familiarity with SBOM concepts and supply chain security considerations for medical devices is an asset
- Strong written communication skills with demonstrated ability to produce clear, audit-ready technical documentation
Hiring someone like this?
Get your role in front of qualified candidates on Sorce.