iRhythm Technologies, Inc.

Product Security Manager

iRhythm Technologies, Inc.$127K — $165K *
US-AnywhereRemote in United States
Healthcare
8 - 10 years of experience
Job Overview by Ladders

Qualifications

  • Bachelor's degree in Computer Science, Information Security, or related field.
  • 8+ years of experience in information security with a focus on medical devices.
  • Strong understanding of security principles in PDLC and SDLC.
  • Hands-on experience in Cybersecurity Risk Assessments (CSRAs) and vulnerability analysis.
  • Familiarity with NIST Cybersecurity Framework and regulatory compliance standards.
  • Proven expertise with medical device software development and operating in regulated environments.
  • Excellent problem-solving, analytical, and communication skills.

Responsibilities

  • Ensure compliance with FDA cybersecurity regulations and guidance.
  • Conduct comprehensive security risk assessments to identify vulnerabilities.
  • Develop and maintain cyber threat models for specific devices.
  • Create and manage cybersecurity documentation for regulatory alignment.
  • Produce detailed data flow diagrams to support threat modeling.
  • Participate in design reviews and provide recommendations for security requirements.
  • Coordinate vulnerability analysis and management programs for medical devices.

Benefits

  • Remote work flexibility from anywhere in the US.
  • Dynamic work environment within a leading medical technology organization.
  • Opportunities for professional development and certifications.
  • Collaborative team culture with cross-functional involvement.
  • Participation in impactful projects that enhance patient safety and compliance.
Full Job Description
About This Role:

We are seeking a Product Security Manager with proven experience in the medical device industry. In this role, you will safeguard medical devices by identifying, assessing, and mitigating security risks unique to healthcare technology. You will collaborate with cybersecurity, development, product management, and regulatory teams to ensure that security is embedded across the product development lifecycle (PDLC) and the secure software development lifecycle (SDLC), in alignment with FDA cybersecurity requirements.

Key Responsibilities
  • FDA Cybersecurity Compliance: Ensure compliance with FDA cybersecurity guidance and regulations in collaboration with Cybersecurity, Regulatory, Quality, and Systems Development teams.
  • Risk Assessments & CSRAs: Conduct comprehensive security risk assessments, including Cybersecurity Risk Assessments (CSRAs), to identify vulnerabilities and threats across device hardware, firmware, software, and cloud components.
  • Threat Modeling: Develop and maintain device-specific cyber threat models, factoring in patient safety, data privacy, and operational continuity.
  • SBOM Management: Demonstrate familiarity with Software Bill of Materials (SBOM) and effectively communicate technical details.
  • Security Documentation: Create and maintain cybersecurity documentation for pre- and post-market activities, ensuring regulatory alignment.
  • Data Flow Diagrams: Produce detailed data flow diagrams to support the threat modeling process.
  • Security Design Reviews: Participate in design reviews of medical device architectures and implementations, providing actionable recommendations for system security requirements.
  • Vulnerability Analysis & Management: Perform and support vulnerability analysis and coordinate the vulnerability management program, including scanning, patching, and remediation for medical devices.
  • Threat Detection Tools: Leverage and maintain application and threat detection tools (Veracode, Snyk, GitLab, or equivalent) to identify security flaws early in the SDLC.
  • Incident Response: Support investigation and remediation of device-related security incidents, minimizing impact and preventing recurrence.
  • Data Privacy Compliance: Partner with the Privacy Team to ensure adherence to HIPAA, GDPR, and other data protection regulations.


Required Qualifications
  • Bachelor's degree in Computer Science, Information Security, or related field.
  • 8+ years of experience in information security, with direct focus on product security for medical devices.
  • Strong understanding of security principles, methodologies, and tools within the PDLC and SDLC.
  • Demonstrated experience conducting Cybersecurity Risk Assessments (CSRAs), vulnerability analysis, and working with modern threat detection tools (Veracode, Snyk, GitLab, or similar).
  • Familiarity with NIST Cybersecurity Framework, NIST SP 800-171, and deeper controls/frameworks such as NIST SP 800-53 (Security and Privacy Controls), NIST SP 800-92 (Log Management), and NIST SP 800-63 (Digital Identity Guidelines).
  • Hands-on experience with vulnerability identification and threat modeling within healthcare using methodologies such as STRIDE.
  • Experience operating in a regulated environment (FDA, HIPAA, GDPR, international regulatory frameworks).
  • Experience with medical device hardware or Software as a Medical Device (SaMD).
  • Experience with medical device software development and regulatory processes.
  • Excellent problem-solving, analytical, and communication skills, able to take a multi-siloed approach.
  • Ability to understand intro dependencies of teams across; mobile applications, hardware and cloud environments.
  • Proven track record of 510k experience and completion.


Preferred Qualifications
  • Industry certifications such as CISSP, CISM, CISA, or medical device security-specific certifications.
  • Experience with international frameworks and standards (EU MDR, JIS T 2304 / IEC 62304).
  • Understanding penetration testing methodologies and tools, able to work with pen test teams independently with little guidance.
  • Proficiency with programming languages and technologies commonly used in medical device development.


Location:
Remote - US

Actual compensation may vary depending on job-related factors including knowledge, skills, experience, and work location.

Estimated Pay Range
$127,000.00 - $165,000.00

About iRhythm Technologies, Inc.

iRhythm Technologies is a medical device company that develops and commercializes solutions for cardiac arrhythmia detection. The company's flagship product is the Zio XT, a wearable patch that continuously monitors a patient's heart rhythm for up to 14 days. The Zio XT is designed to improve the detection and diagnosis of cardiac arrhythmias, which can be difficult to diagnose due to their intermittent nature. iRhythm Technologies was founded in 2006 and is headquartered in Redwood City, California. The company went public in 2016 and is traded on the NASDAQ stock exchange under the ticker symbol IRTC.
Learn more about iRhythm Technologies, Inc.
Size
1,700 employees
Market Cap
$2.7 billion
Industry
Net Income
-$43.8 million
Founded
2006
5 Year Trend
+38.2%
Revenue
$265.1 million
NASDAQ

Similar Jobs

More Jobs at iRhythm Technologies, Inc.

More Healthcare Jobs

Find similar Product Security Manager jobs: