The specialist will provide cybersecurity advisory services and HIPAA guidance to support medical and technology product lines. They will conduct risk assessments, ensure compliance with FDA and industry standards, and collaborate with development teams on secure design practices.
Mirion is seeking a motivated and enthusiastic Senior Product Cybersecurity Specialist to support Mirion’s medical and technologies product lines. The specialist will play a crucial role providing cybersecurity advisory services and HIPPA guidance to product owners, sales teams, and developers in the form of providing security guidance, reviews, and compliance information. Additionally, this role will build out processes and technical capabilities as assigned to support the Product Cybersecurity mission.
Primary Responsibilities
- Support cybersecurity risk assessments for connected medical devices and software per US HHS and FDA guidance.
- Provide cybersecurity recommendations and guidance to product development teams on secure design, coding, and development.
- Assist with gathering evidence and providing information for external audits and customer security inquiries for HIPPA and ePHI related security controls and for frameworks such as ISO 27001 and SOC 2.
- Document and write product risk assessment and security control reports.
- Review and aid with writing cybersecurity related information for product documentation.
- Participate in product project meetings as the cybersecurity representative.
- Collaborate with cross-functional teams to ensure cybersecurity best practices are integrated into product development and support.
- Stay informed about the latest cybersecurity threats, vulnerabilities, and industry’s best practices.
Potential Additional Responsibilities
- Participate in routine code vulnerability scans and triage activities.
- Assist in implementation and creating procedures around the use of developer code security technologies including SAST, SCA, and DAST tools.
- Coordinating penetration testing and other application security testing.
- Other general tasks as assigned.
Required Qualifications and Experience
- Bachelor’s degree in information technology, information security, or related field or equivalent practical experience.
- Experience: 4+ years in a cybersecurity-focused role, with exposure to cybersecurity governance, risk, and compliance.
- Working knowledge of the HIPAA Security Rule (45 CFP Part 160/164) and Privacy/Breach Notification Rules.
- Familiarity with FDA's "Cybersecurity in Medical Devices" premarket/postmarket guidance.
- Familiarity with cybersecurity frameworks such as ISO 27001, IEC 62443, NIST 800-171, SOC 2, and Cyber Essentials.
- Experience with HIPPA regulations and the HITRUST security framework.
- Experience with software application architecture and secure software development practices.
- Experience with embedded systems and associated security considerations.
- Good understanding of cybersecurity concepts and best practices to secure hardware and software components.
- Strong communication skills and a collaborative working style.
- Desire to work and learn.
Desired Qualifications and Experience
- Familiarity with international cyber industry regulations such as EU GDPR, and EU Cyber Resilience Act.
- Understanding of SBOM concepts and code/application vulnerability management tools.
- Experience with secure coding practices.
- Experience with Azure and AWS cloud security.