My fantastic Limerick client is looking for a Product Security Engineer. As the Product Security Engineer, you will be responsible for the implementation of security requirements and secure coding standards, e.g., NIST SP 800-53, OWASP, and MS Secure Coding Standards.
Evaluate product designs and provide solutions to remediate security vulnerabilities through product security risk assessments, vulnerability scans, and static and dynamic code analysis tools.
In addition to defining security requirements for new product development, the role requires you to support teams in remediating vulnerabilities with existing products.
Main responsibilities will include: Support teams in reducing product risk, by finding practical solutions on how to increase security in new and existing products.Work in a team supporting R&D in implementing secure software solutions by ensuring architecture is in accordance with industry-accepted standards for medical device security including encryption, disaster recovery, authentication, audit logging, hardening measures, patch management, and vulnerability monitoring.Assist in product security risk assessments and provide vulnerability remediation guidance to product development software engineers both on and off-site.Develop and ensure software engineering procedures are aligned with product security requirements.Support the Product Security Documentation process including:Providing standardized Product Security documentation.Organizing and supporting the document review and approval process.Ensuring that deliverables are delivered punctually and to the required level of quality.Interface and oversee product security aspects of technical departments such as Systems Hardware, Quality, and technical services.Collaborate with other resources to ensure effective design and implementation goals.Assure adherence to our development policies and software quality procedures.About you: BS degree in Computer Science, Computer Engineering, Electrical Engineering, or other related engineering field or equivalent work experience required.Minimum of 3 years of experience in areas such as IT-Security, secure software development and designs, and risk management.Working experience with various encryption algorithms and PKI solutions.Understanding of security issues and solutions for embedded devices.Good understanding of networking and related security aspects and common attacks.Demonstrated understanding of developing in a regulated environment and adhering to a quality management system.Excellent written and verbal communication and interpersonal skills are essential.Demonstrated positive work ethic with a strong commitment to achieving project goals.Good understanding of Microsoft Office products and tools.In addition to the above skills, the following skillset would be advantageous but not essential: Experience with Dynamic and static code analysis tools.Knowledge of completing a track Trace and plan using a Security Requirements Traceability Matrix (SRTM) or similar tool.Understanding of vulnerability scans and static code analysis results.Understanding proper secure coding practices to drive standards within the software engineering organization.Experience working in a regulated (FDA, MDR) environment with medical instrumentation.Basic understanding of network security fundamentals (IP protocol, firewalls etc.
).Recognized Security certifications are a plus (CISSP, CASP+, CSSLP etc.
).
#J-18808-Ljbffr