Staff Cyber Security Engineer
Core
Serve as the Product Security Representative (PSR) for Imaging360, embedding cybersecurity, privacy, and regulatory compliance into the design, development, and lifecycle of a cloud-enabled enterprise healthcare platform connecting on-premises imaging scanners with third-party services.
Role type
Staff Cyber Security Engineer (Product Security Representative)
Builds
Cloud-hosted enterprise applications, APIs, hybrid cloud/on-premises connectivity, and third-party integrations for healthcare imaging workflows.
Domain
Healthcare / Enterprise Cloud Security
Required skills
Threat modeling, cybersecurity risk assessment, secure design reviews, vulnerability management, secure SDLC practices, API security, identity and access management, encryption, audit logging, secrets management, network segmentation, SBOM generation, third-party integration security assessment, DevSecOps practices, cloud security posture management, container security, regulatory compliance (HIPAA, GDPR, FDA guidance).
Preferred skills
Product Security Representative experience, healthcare software/imaging workflows (DICOM), GEHC DEPS process familiarity, NIST/ISO 27001/IEC 81001-5-1 frameworks, tools (Black Duck, Syft, Grype, SonarQube, Burp Suite, Wiz, Prisma Cloud), identity federation (SAML, OAuth, OIDC, SCIM), security certifications (CISSP, CSSLP, CISM).
Technologies
AWS, Azure, Docker, Kubernetes, SAML, OAuth, OIDC, SCIM, RBAC, SAST, SCA, DAST, SBOM, CI/CD pipelines.
Responsibilities
Drive execution of the GEHC DEPS process including security planning, threat modeling, and risk assessments; Own Security Design Reviews across the product lifecycle from concept to release; Lead threat modeling and security architecture reviews for cloud applications and hybrid integrations; Assess cybersecurity risks for hybrid deployments involving cloud, customer networks, and on-premises scanners; Define and influence implementation of security controls for authentication, authorization, encryption, and network segmentation; Coordinate SAST, SCA, DAST, penetration testing, and cloud security reviews; Generate and assess Software Bill of Materials (SBOM) content; Champion security KPI reporting and governance dashboards; Provide cybersecurity guidance to scrum teams to adopt secure SDLC and DevSecOps practices.
Seniority
Staff, strategic leadership with hands-on technical execution