-
View all jobs
Location: Remote (Europe preferred)
Team: Product team
Corsmed is redefining quantitative MRI through advanced clinical solutions that deepen diagnostic insight, streamline examination workflows, and reduce the total cost of imaging. We operate at the intersection of advanced physics, high-performance computing and modern software engineering.
We are looking for a Senior Cybersecurity Engineer to embed security throughout our product lifecycle. You will design, build, automate and maintain the secure deployment and monitoring of our products, in a regulated medical device environment.
Requirements
Product & Medical Device Security (FDA-Regulated Environment)
Team: Product team
Corsmed is redefining quantitative MRI through advanced clinical solutions that deepen diagnostic insight, streamline examination workflows, and reduce the total cost of imaging. We operate at the intersection of advanced physics, high-performance computing and modern software engineering.
We are looking for a Senior Cybersecurity Engineer to embed security throughout our product lifecycle. You will design, build, automate and maintain the secure deployment and monitoring of our products, in a regulated medical device environment.
Requirements
- 5+ years of experience in cybersecurity, with at least 3–5 years in a hands- on senior or lead role.
- Experience in a regulated industry, with a strong preference for MedTech (medical devices), HealthTech, or Life Sciences.
- FDA expertise: Hands-on experience with FDA cybersecurity guidance for medical devices, contributing to the cybersecurity sections of regulatory submissions (e.g., 510(k), PMA), and acting as a subject matter expert in direct interactions with regulatory bodies (e.g., responding to submission questions, participating in audits).
- Compliance expertise: Direct experience leading or playing a primary role in achieving and maintaining SOC 2 and/or HIPAA compliance.
- Product security: Strong experience with application security, secure SDLC practices, threat modeling (e.g., STRIDE), and vulnerability management for software products.
- Cloud security: Deep knowledge of securing cloud environments and services (AWS, GCP, or Azure).
- Technical skills: Proficiency with security assessment tools, IAM systems, endpoint protection, and network security concepts.
- Bachelor’s degree in Computer Science, Information Security, or a related field.
- Relevant professional certifications are highly desirable (e.g., CISSP, CISM, HCISPP, CSSLP).
Product & Medical Device Security (FDA-Regulated Environment)
- Secure Software Development Lifecycle (SDLC): Integrate security best practices and tools into every phase of the product development lifecycle, from design and requirements to coding, testing, and deployment.
- Threat Modeling & Risk Analysis: Lead and perform threat modeling and security risk analysis (per ISO 14971) for new and existing medical device software.
- FDA & Regulatory Compliance: Author, review, and own all cybersecurity- related documentation for regulatory submissions (e.g., FDA 510(k) pre- market and post-market management plans). Ensure our products and processes align with the latest FDA guidance, IEC 62304, and other relevant medical device security standards.
- Regulatory Interface: Act as the primary cybersecurity subject matter expert (SME) for regulatory interactions, including responding to questions during FDA submissions and representing the company’s cybersecurity posture during audits.
- Security Requirements Definition: Partner with Product Management, Engineering, and Quality teams to define and document security, controls, and architecture for our medical device platforms.
- Vulnerability Management & Penetration Testing: Manage and coordinate third-party penetration testing and internal vulnerability assessments of our products. Develop and oversee remediation action plans.
- Incident Response: Develop, implement, and maintain an incident response plan for product
- Continuous Security Assessment & Strategy: Continuously assess the company’s security posture against evolving business needs and emerging threats. Identify relevant security standards (e.g., SOC 2, HIPAA, NIST CSF), perform regular gap analyses, and own the strategic roadmap for assessment, implementation, and improvement.
- Compliance Frameworks (SOC 2 / HIPAA): Lead initiatives to achieve and maintain SOC 2 certification for our platform and business operations. Develop and manage the security controls and policies required for SOC 2 and HIPAA Security Rule compliance.
- Corporate Security Governance: Develop, implement, and enforce company-wide information security policies, procedures, and standards.
- IT & Cloud Security: Conduct security architecture reviews and risk assessments of our corporate IT and cloud infrastructure (AWS / GCP / Azure). Implement and manage security controls to protect corporate data and systems.
- Vendor & Third-Party Risk Management: Establish and manage a program to assess and monitor the security posture of third-party vendors and partners.
- Identity & Access Management (IAM): Oversee and improve IAM policies and solutions to ensure the principle of least privilege is maintained.
Key Skills
Ranked by relevance
cybersecurity
hipaa
cloud
penetration testing
aws
gcp
incident response
network security
cloud security
cissp
cism
nist
Related Jobs
3 roles aligned with this opportunity
View Job Details
Related
Senior Python Engineer
2026-06-19
Full-time
Mid-Senior
Turkey
Software Development
Information Technology
View Job Details
Related
Cybersecurity Engineer
2026-06-19
Full-time
Not Applicable
Turkey
Research Services
Information Technology
View Job Details
Related
Full Stack Engineer (Python/React) - Ankara, TR
2026-06-19
Full-time
Not Applicable
Turkey
Software Development
Engineering
Login to Apply
- Posted
- Jan 08, 2026
- Type
- Full-time
- Level
- Mid-Senior
- Location
- Greater Stockholm Metropolitan Area
- Company
- Corsmed
Industries
Software Development
Categories
Information Technology
Related Jobs
3 roles aligned with this opportunity
View Job Details
Related
Senior Python Engineer
2026-06-19
Full-time
Mid-Senior
Turkey
Software Development
Information Technology
View Job Details
Related
Cybersecurity Engineer
2026-06-19
Full-time
Not Applicable
Turkey
Research Services
Information Technology
View Job Details
Related
Full Stack Engineer (Python/React) - Ankara, TR
2026-06-19
Full-time
Not Applicable
Turkey
Software Development
Engineering