Primary Function of PositionThis role is part of the Product Cybersecurity organization and contributes to improving the overall security posture of products. It involves leading and managing individual contributors while contributing broadly to organizational goals and deliverables. The position provides leadership to technical team members and contributes directly to products, tools, internal policies, and procedures. Collaboration across multidisciplinary teams and departments is essential to achieve security objectives within the organization.
Essential Job Duties- Lead and manage a team of 4-5 Product Security Analysts responsible for cybersecurity threat modeling, security risk analysis, and security design assessments across Intuitive medical device platforms.
- Drive development and maintenance of threat models, attack surface analyses, and cybersecurity risk assessments using recognized methodologies such as STRIDE and attack trees.
- Provide oversight for compliance with FDA cybersecurity guidance, Section 524B of the FD&C Act, and applicable global medical device cybersecurity and privacy regulations.
- Improve and establish security policies, departmental processes, and procedures.
- Work with cross-functional teams, organizations, and third-party vendors to coordinate activities that support organizational and departmental objectives.
- Support various departments such as legal, quality assurance, regulatory, human factors, manufacturing, software, test, and reliability in responding to customer concerns, security laws, regulations, and product requirements.
- Interface with teams across multiple disciplines including mechanical, software, systems analysis, manufacturing, test, supply chain, quality, regulatory, service, and technical publications.
- Recognize and attract top talent, mentor and train team members through one-on-one coaching and team-wide initiatives.
QualificationsRequired Education, Experience & Skills- Minimum 8 years as an individual contributor and 1-3 years as a people manager or prior management responsibilities through project management or team leadership efforts in embedded product security or related cybersecurity domains with a University degree
- Deep understanding of cybersecurity attacks, threats, threat analysis, ethical hacking, and system analysis/auditing
- Strong design and development skills
- Ability to multi-task, prioritize, and work effectively in a fast-paced, collaborative environment
- Excellent communication skills (written, oral, presentation, and documentation) with the ability to maintain relationships across organizations
- Proven ability to lead and manage deeply technical individual contributors and set employee goals and objectives
- Passion for creating robust and reliable products with strong problem-solving and learning enthusiasm
- Experience with security analysis of medical devices and products is preferred
- Experience with medical device cybersecurity regulations (FDA, NMPA, EU MDR, MDCG, HIPAA) is preferred
Additional InformationDue to the nature of our business and the role, please note that Intuitive and/or your customer(s) may require that you show current proof of vaccination against certain diseases including COVID-19. Details can vary by role.
This position may be filled at a different job level than listed here depending on
business need and/or on the selected candidate's experience, knowledge and skills.
Compensation will be based primarily on the job level at which the role is filled and the
candidate's qualifications, consistent with applicable law.
We provide market-competitive compensation packages, inclusive of base pay, incentives, benefits, and equity. It would not be typical for someone to be hired at the top end of range for the role, as actual pay will be determined based on several factors, including experience, skills, and qualifications. The target compensation ranges are listed.