Cybersecurity Expert - Product (Medical Devices) (f/m/d)
- Work model
- Hybrid
- Experience
- 2-5 years
- Employment
- Contract
- Compensation
- Not disclosed
- Technology signal
- 5 tags
Technology context
5Parsed from the vacancy text; ordered by relevance to this role.
Full listing
Role description
Do you want to help create the future of healthcare? Our name, Siemens Healthineers, was selected to honor our people who dedicate their energy and passion to this cause. It reflects their pioneering spirit combined with our long history of engineering in the ever-evolving healthcare industry.
We offer you a flexible and dynamic environment with opportunities to go beyond your comfort zone in order to grow personally and professionally. Sounds interesting?
Then come and join our global team as Cybersecurity Expert (f/m/d) Product (Medical Devices). In this position, you will help strengthen the cybersecurity posture of advanced medical devices used in demanding clinical environments. You will work at the intersection of cybersecurity, medical device development, systems engineering, product architecture, regulatory compliance, and healthcare innovation.
Choose the best place for your work - Within the scope of this position, it is possible, in consultation with your manager, to work mobile (within Germany) up to an average volume of 60% of the respective working hours.
Even more flexibility? Mobile working from abroad is possible for up to 30 days a year under certain conditions and in selected countries.
Your tasks and responsibilities
- You are part of the cybersecurity team supporting the Artis product family. Together with an experienced internal Cybersecurity Expert and external cybersecurity specialists, you ensure the planning, execution, and continuous improvement of cybersecurity activities throughout the product lifecycle.
- Together with Product Management, Systems Engineering, Architecture, and the Cybersecurity Officer, you contribute to cybersecurity strategies and planning activities for new product developments and product maintenance projects.
- You create threat models, perform Threat and Risk Analyses (TRA), moderate cybersecurity workshops and derive risk mitigation measures using established methodologies and industry best practices.
- You define, specify, and maintain cybersecurity requirements and ensure their traceability from risk identification through implementation and verification.
- You develop and review cybersecurity architectures, data flow diagrams, network flow diagrams, and other security engineering artifacts for complex medical systems in cooperation with architects.
- You provide technical guidance to development teams regarding secure software development, system hardening and security-by-design principles.
- You coordinate and assess cybersecurity testing activities including vulnerability assessments, penetration testing, software composition analysis, SAST, security scanning, and remediation planning.
- You evaluate cybersecurity vulnerabilities, third-party software risks, software bills of materials (SBOMs) and end-of-life risks and support mitigation strategies together with development teams.
- You prepare and maintain cybersecurity documentation required for regulatory submissions and market approvals, including IEC 81001-5-1 evidence, security whitepapers, and cybersecurity assessment reports.
- You contribute to the continuous improvement of cybersecurity processes, methods, and tool chains across Advanced Therapies R&D.
To find out more about the specific business, have a look at Angiography
Your qualifications and experience
- You hold a university degree in Cybersecurity, Computer Science, Software Engineering, Systems Engineering, Information Technology, or a related technical discipline.
- You have several years of professional experience in product cybersecurity, application security, embedded security, system security, or a comparable field.
- You have practical experience in threat modeling, security architecture design, cybersecurity risk assessment, and vulnerability management.
- You have knowledge of cloud security, container security, IOT security, and AI security controls and concepts.
- You are familiar with secure development lifecycles and cybersecurity processes within regulated industries.
- You have experience with cybersecurity standards and regulations such as IEC 81001-5-1, IEC 62304, FDA Cybersecurity Guidance, ISO 27001, IEC 62443, OWASP or the NIST Cybersecurity Framework.
- You understand common security testing techniques such as penetration testing, fuzzing, security scanning, and software composition analysis.
- Experience with requirements in engineering, systems engineering and traceability methods is highly desirable.
- Professional cybersecurity certifications such as CISSP, CSSLP, CISM, GICSP, CEH or comparable certifications are considered a plus.
Your attributes and skills
- You combine strong analytical thinking with a structured and systematic working style.
- You enjoy solving complex technical challenges and communicating cybersecurity concepts to multidisciplinary stakeholders.
- You can balance cybersecurity requirements with patient safety, clinical effectiveness, usability, and regulatory expectations.
- You work effectively in international and cross-functional development environments.
- You are proactive, self-driven and able to take ownership of cybersecurity topics from concept through product release.
- You possess excellent communication and stakeholder management skills.
- You are fluent in English. German language skills are beneficial.
Our global team
Siemens Healthineers is a leading global medical technology company. 74,000 dedicated colleagues in over 70 countries are driven to shape the future of healthcare. An estimated 5 million patients across the globe benefit every day from our innovative technologies and services in the areas of diagnostic and therapeutic imaging, laboratory diagnostics and molecular medicine, as well as digital health and enterprise services.
Our culture
Our culture embraces different perspectives, open debate, and the will to challenge convention. Change is a constant aspect of our work. We aspire to lead the change in our industry rather than just react to it. That's why we invite you to take on new challenges, test your ideas, and celebrate success. Check our Careers Site at https://www.siemens-healthineers.com/de/careers
As an equal opportunity employer, we welcome applications from individuals with disabilities. #myabilityshs
Wish to find out more before applying? Contact us: recruitinggersupport.func@siemens-healthineers.com , if you wish to discuss any initial questions with our recruitment team. The contact person handling this job ad is Simone Morgenstern.
We care about your data privacy and take compliance with GDPR as well as other data protection legislation seriously. For this reason, we ask you not to send us your CV or resume by email. We ask instead that you create a profile in our talent community where you can upload your CV. Setting up a profile lets us know you are interested in career opportunities with us and makes it easy for us to send you an alert when relevant positions become open. Click here to get started.
To all recruitment agencies
Siemens Healthineers' recruitment is internally managed, with external support permitted only when a qualified supplier has established a formal contract with us. Unsolicited candidate submissions and referrals, absent a current supplier contract, do not establish consent and are ineligible for fees. We delete and destroy unsolicited information, thus, would recommend you refrain from any such practices. Your adherence to our policies is appreciated.
Siemens Healthineers Germany was awarded the Great Place to Work® certificate.