Security Operations & Compliance Engineer

VAPOTHERM, INC.Exeter, NH
Remote

About The Position

This role involves working with cross-organizational stakeholders to ensure the understandability and relevance of published security policies and their impact on the business. The engineer will develop cyber resilience strategies, design policies and procedures for risk management, access control, cloud security, patch management, and change management. Key responsibilities include interacting with management to implement security controls, providing supporting guidelines and tools to foster a security culture, completing Gap Analysis of Enterprise Cyber Security and Product Security, and forming an Information Security Steering committee. The role also requires presenting Gap Analysis to committees, designing information security policies, documenting business initiatives and their security implications, assessing risks, conducting security awareness and training, performing BIA and risk assessments, designing Security Management Plans, and training Product teams on security and Privacy by Design. Additionally, the engineer will interact with third-party vendors, respond to cyber insurance questionnaires and customer security assessments, integrate SAST and DAST tools, submit for FDA 510k, perform Threat Modelling, work with Quality Control and Regulators for Safety Risk Assessment, and collaborate with the Department of Defense on Product Security assessments. Experience with various security tools and platforms is essential.

Requirements

  • Bachelor’s Degree (3 or 4 year U.S. or foreign degree) in Computer Science, Computer Applications, or a related field.
  • Five (5) years of experience in the proffered position, or as Quality Assurance Specialist, Information Security Lead, Chief Security Officer, or related occupation.
  • 1 year experience developing cyber resilience strategies.
  • 1 year experience designing policies and procedures regarding risk management, access control, cloud security, patch management, and change management.
  • 1 year experience interacting with management and stakeholders to implement security controls.
  • Experience with GCP, Azure, Active Directory, Security Command Center, Cisco Meraki Firewall, Crowdstrike, Intune, Zoho, Nessus, Burp Suite, Kali Linux Microsoft TMT, Snyk SAST, Helm SBOM, JIRA, Service Desk, Outlook, wizer security.

Nice To Haves

  • Threat Modelling (STRIDE) for Products and training Software Architects in using Threat Model requirements for FDA submissions.
  • Work with Quality control and Regulators for Safety Risk Assessment of the Product.
  • Work with Department of Defense on Product Security assessments.

Responsibilities

  • Work with cross-organizational stakeholders to determine the understandability and relevance of published security policies and their impact on the business.
  • Develop cyber resilience strategies.
  • Design policies and procedures regarding risk management, access control, cloud security, patch management, and change management.
  • Interact with management and stakeholders to implement security controls.
  • Provide supporting guidelines and tools to enable a culture of security.
  • Complete Gap Analysis of Enterprise Cyber Security and Product Security and Forming an Information Security Steering committee and charter.
  • Present Gap Analysis to Security Steering Committee and Audit Committee and obtaining buy-in for Info Sec Initiatives and tasks.
  • Design information security policies and procedures for the organization such as access control policy, risk management policy, cloud security policy and procedures, BCP/DR, Secure Development Policy, Patch management, Third-party vendor risk assessment and Change Management Policy.
  • Document business initiatives and their security implications and assess Risk Management (Identifying, Assessing and Controlling) risks.
  • Conduct security awareness and training across the enterprise and supporting businesses based on the security and operational risks identified.
  • Conduct BIA, risk assessments and providing reports to the leadership team and stakeholders.
  • Design Security Management Plan for the product teams to enable implementation and controls.
  • Design and train Product teams on security and Privacy by Design.
  • Interact with third party vendors in price and service negotiations for onboarding security MSP and tools.
  • Respond to Cyber insurance renewal questionnaires and Product Customer Security Risk Assessments.
  • Integrate different SAST and DAST tools to JIRA and automation.
  • Submit for FDA 510k.
  • Threat Modelling (STRIDE) for Products and training Software Architects in using Threat Model requirements for FDA submissions.
  • Work with Quality control and Regulators for Safety Risk Assessment of the Product.
  • Work with Department of Defense on Product Security assessments.
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service