Manage the penetration testing programme: scoping, vendor coordination, findings review, and remediation follow-up.
Embed security controls into CI/CD pipelines, including SAST, DAST, SCA, secrets detection, and container scanning.
Address software supply chain risks: SBOM processes, open-source dependency management, and secure build and release practices.
Lead threat modelling, secure design reviews, and security risk assessments for new and existing product features.
Support customer security reviews, questionnaires, and technical security discussions.
Define and track product security metrics and report to leadership.
Requirements
Background in product security, application security, cloud security, DevSecOps, or a closely related discipline.
Experience with vulnerability management, including prioritisation, remediation tracking, and communicating risk to technical and non-technical stakeholders.
Hands-on experience with CI/CD security tooling such as SAST, DAST, SCA, secrets scanning, or container scanning.
Understanding of software supply chain risks, SBOMs, and secure build and release practices.
Genuine interest in the product and clinical domain — you want to understand what you are securing, not just run the tooling.
Strong cross-functional collaboration skills; able to influence without formal authority.
Excellent communication skills in English.
Preferred qualifications: Experience in medical device software, regulated software, or AI/ML-enabled products; Familiarity with IEC 62304, ISO 14971, ISO 27001/2, FDA cybersecurity guidance, EU MDR, NIS2, OWASP, or NIST SSDF; Relevant certifications such as CISSP, CSSLP, OSCP, GWAPT, CCSP, or similar.
Tech Stack
Cloud
Cyber Security
Benefits
Providing a Certificate of Conduct (VOG) or background check is part of our application procedure.