Product Security Engineer (Hybrid)
Location: Limerick - Must be onsite 2/3 days per week. Duration: Permanent
About the role:
You will be responsible for implementing security requirements and secure coding standards, e.g., NIST SP 800-53, OWASP, and MS Secure Coding Standards.
Evaluate product designs and provide solutions to remediate security vulnerabilities through product security risk assessments, vulnerability scans, and static and dynamic code analysis tools.
In addition to defining security requirements for new product development, the role requires you to support teams in remediating vulnerabilities with existing products.
Main Responsibilities:
1. Support teams in reducing product risk by finding practical solutions on how to increase security in new and existing products.
2. Work in a team supporting R&D in implementing secure software solutions by ensuring architecture is in accordance with industry accepted standards for medical device security including encryption, disaster recovery, authentication, audit logging, hardening measures, patch management, and vulnerability monitoring.
3. Assist in product security risk assessments and provide vulnerability remediation guidance to product development software engineers both on and off-site.
4. Develop and ensure software engineering procedures are aligned with product security requirements.
5. SUPPORT THE PRODUCT SECURITY DOCUMENTATION PROCESS INCLUDING:
1. Providing standardized Product Security documentation.
2. Organize and support the document review and approval process.
3. Ensure that deliverables are delivered punctually and to the required level of quality.
About You:
* BS degree in Computer Science, Computer Engineering, Electrical Engineering, other related engineering field or equivalent work experience required.
* Minimum of 3 years of experience in areas such as IT-Security, secure software development and designs, and risk management.
* Working experience with various encryption algorithms and PKI solutions.
* Understanding of security issues and solutions for embedded devices.
* Good understanding of networking and related security aspects and common attacks.
* Demonstrated understanding of developing in a regulated environment and adhering to a quality management system.
* Excellent written and verbal communication and interpersonal skills are essential.
* Demonstrated positive work ethic with a strong commitment to achieving project goals.
* Good understanding of Microsoft Office products and tools.
Additional desirable skills include:
* Experience with Dynamic and static code analysis tools.
* Knowledge of completing a track Trace and plan using a Security Requirements Traceability Matrix (SRTM) or similar tool with the goal of tracking Security Requirements Source of Requirement Requirement Objective Verification Method.
* Understanding of vulnerability scans and static code analysis results.
* Understanding proper secure coding practices to drive standards within the software engineering organization.
* Experience working in a regulated (FDA, MDR) environment with medical instrumentation.
* Basic understanding of network security fundamentals (IP protocol, firewalls etc.).
* Recognized Security certifications are a plus (CISSP, CASP+, CSSLP etc.).
Candidates should hold appropriate RTWs for Ireland i.e. Stamp1G, Stamp 4, Irish/British/EU passport.