Overview
In this role you help clients in the medical device space enhance security across product development and lifecycle. You will collaborate with product, design and cross-disciplinary teams to deliver secure software and hardware solutions. You’ll assess risks, guide remediation strategies and advise on threat modeling, secure coding and testing. You contribute to client trust through strong stakeholder engagement and by shaping security strategy in a fast-paced consulting environment.
Pay / Benefits
- private healthcare for you and family
- 25 days annual leave + 5 purchase days
- generous pension
- annual bonus
- PA share ownership
- cycle to work and tax-efficient benefits
Responsibilities
- Assess security risks across client product portfolios and recommend remediation strategies
- Lead secure code reviews, threat modeling, and vulnerability assessments with client R&D teams
- Advise on coding practices, threat modeling, and security testing for embedded systems and IoT devices
- Work with client product teams to define objectives, scope and timelines for security initiatives and delivery methodologies
- Monitor emerging cybersecurity threats in IoT/medical devices and articulate PA’s viewpoint
- Foster strong stakeholder relationships and contribute to business development and project management
- Collaborate across cross-functional teams to deliver secure, compliant solutions
- Support and mentor junior colleagues and drive knowledge sharing and growth
Key requirements
- 5+ years of relevant experience in the medical device space
- Proficiency in security frameworks (NIST, OWASP, MITRE ATT&CK, PASTA, STRIDE)
- Experience with risk assessment methods and residual risk calculation
- Experience with compliance frameworks (NIST, IEC, HITRUST, HIPAA, GDPR, ISO 27001, SOC 2 Type 2) and QMS familiarity
- Experience in SDLC and communicating security to technical and non-technical audiences
- Strong proposals and business development capabilities
- Cyber security accreditations (CISSP, CSSLP, CISM)
- Strong problem-solving and stakeholder collaboration in fast-paced settings
- Excellent interpersonal and written/verbal communication skills
- Strong relationship-building and stakeholder management
- Collaborative and client-centric mindset
- Security frameworks proficiency (NIST, OWASP, MITRE ATT&CK, PASTA, STRIDE)
- Threat modeling and vulnerability assessment
- Secure coding practices for embedded systems and IoT
…
