Leica Microsystems-posted 3 months ago
$140,000 - $160,000/Yr
Full-time • Senior
Vista, CA
Computer and Electronic Product Manufacturing

The Senior Engineer, Product Cybersecurity for Leica Biosystems is responsible for embedding security and resilience into our products' entire lifecycle, from requirements through deployment and support. You will perform threat modeling, attack surface analysis, and risk assessments (aligned with ISO 14971 and AAMI TIR57), as well as hands-on design and implementation of secure software and system architectures. This position is part of the Research and Development Department located in Vista California and will be on-site. At Leica Biosystems, our vision is to advance cancer diagnostics and improve lives. This role reports to the Senior Manager, Software Engineering, and will focus on product lifecycle security, including threat modeling, security architecture, and requirements definition.

  • Manage product security risks, overseeing threat detection and analysis activities, prioritizing identified risks for mitigation, validating the effectiveness of implemented mitigations, and reporting on residual risk to stakeholders.
  • Implement and improve security mitigations, such as encryption, authentication, secure coding practices, and integration of security tools into the development pipeline and product development.
  • Participate in the authoring and execution of test plans for security requirements testing, validation of security controls, and risk mitigations.
  • Collaborate with Product Security representatives across Leica Biosystems and other Danaher Operating Companies to align on security requirements, best practices, and drive consistent implementation of cybersecurity initiatives.
  • Work cross functionally with other disciplines, such as Quality, Regulatory, and Leadership, to instill, educate, and promote cybersecurity throughout their entire lifecycle.
  • Bachelor's or Master's degree in Computer Science, Cybersecurity, Electrical/Computer Engineering, related discipline or equivalent experience.
  • Experience with threat modeling, secure software design, and security risk management.
  • Understanding of industry standards (such as IEC 62304, ISO 14971, IEC 81001-5-1, AAMI TIR57, AAMI SW96, and CLSI AUTO11-Ed3).
  • Experience with cross-functional collaboration (e.g. Engineering, Quality Affairs, Regulatory Affairs, Program Management, and Product Management).
  • Experience with secure development lifecycle (SDL/SDLC) practices, and integrating and using SAST, DAST, and SBOM vulnerability monitoring tooling to ensure software is securely developed and maintained.
  • Certifications such as CISSP, CEH, GIAC, CCSLP.
  • Experience with Atlassian Jira, Atlassian Confluence, Cybellum, Tenable Nessus, CIS-CAT Pro Assessor, Microsoft Threat Modeling Tool, CycloneDX, Sonatype, Veracode.
  • Comprehensive package of benefits including paid time off, medical/dental/vision insurance, and 401(k).
  • Bonus/incentive pay eligibility.
© 2024 Teal Labs, Inc
Privacy PolicyTerms of Service