Senior Product Cyber Security Systems Engineer at Sonova focusing on product security and cyber threats. Collaborating with teams to maintain robust security practices and compliance.
Responsibilities
Support Secure Product Development: Collaborate with product development, quality, and maintenance teams to integrate cyber security into the secure product development lifecycle, including secure design, development, maintenance, and DevSecOps practices.
Cyber Security Strategy & Governance: Assist in developing and implementing Sonova’s cross-divisional product cyber security strategy, roadmap, policies, standards, controls, and processes, ensuring adoption within Advanced Bionics.
Threat & Regulatory Monitoring: Monitor evolving cyber threats, industry trends, and regulatory requirements, conducting assessments against relevant standards and frameworks to maintain an effective security posture.
Security Requirements & Risk Management: Identify security requirements for products and business processes, monitor product cyber risks, and support initiatives to ensure product confidentiality, integrity, and availability.
Security Verification & Vulnerability Management: Conduct and support security verification activities including design and code reviews, vulnerability scanning, penetration testing, and ongoing vulnerability management for products and services.
Security Metrics, Documentation & Incident Response: Maintain required security documentation and quality deliverables, measure effectiveness of security controls through KPIs, and support cyber security incident response and investigations.
Cross-Functional Collaboration & Continuous Improvement: Work with internal teams, external partners, and customers to promote cyber security awareness, support communication on product security matters, contribute to R&D activities in an agile environment, and drive continuous improvement initiatives.
Requirements
Bachelor’s degree (or higher) in engineering or a related field, with further specialization in cybersecurity; professional security certifications preferred.
At least 5 years of experience in software engineering, system design/architecture, SDLC, and project management, including 3+ years in cybersecurity-related roles.
Experience with threat modeling, security assessments, vulnerability management, secure SDLC practices, and familiarity with cybersecurity frameworks, standards, and regulations (e.g., GDPR, MDR, FDA, HIPAA).
Knowledge of application security, cryptography, authentication/authorization protocols (e.g., OAuth2, WebAuthn), OWASP Top 10, SANS CWE-25, CI/CD pipelines, and DevSecOps practices.
Practical experience with programming languages such as C, C++, C#, Java, Swift, Kotlin, TypeScript, Rust, scripting languages such as Python, PowerShell, Bash, and frameworks/platforms including .NET, Angular, and Azure.
Understanding of communication and security protocols such as Bluetooth (Classic/LE), WLAN, TLS, wireless vulnerabilities (RF, Bluetooth, Wi-Fi), and experience with penetration testing, fuzz testing, and embedded or device software environments.
Strong analytical and problem-solving abilities, excellent written communication skills, ability to explain complex security topics to non-technical audiences, work collaboratively across teams, manage competing priorities, and perform effectively under pressure.
A minimum of 200Mb/sec download and 10Mb/sec upload speed internet connectivity is required to support any remote/hybrid employee functionality at Sonova.
Benefits
Medical, dental and vision coverage*
Health Savings, Health Reimbursement, Flexible Spending/Dependent Care Accounts
TeleHealth options
401k plan with company match*
Company paid life/ad&d insurance
Additional supplemental life/ad&d coverage available
Company paid Short/Long-Term Disability coverage (STD/LTD)
Associate Director ICT Security overseeing the cybersecurity strategy and team leadership at PFH Technology in Dublin. Ensuring compliance and security in Ireland’s healthcare infrastructure.
Senior Consultant focused on ISMS, BCM, and cybersecurity compliance at VICCON GmbH. Leading projects and collaborating with clients to enhance their information security and resilience.
GSS Officer at Itad supporting safety, security, and travel policies. Overseeing risk management and collaborating with project teams for operational support.
Install and manage fall protection systems at height, ensuring compliance with safety standards. Leadership required in overseeing teams and project delivery at construction sites.
Security Design Lead in Rabobank's cybersecurity team, designing secure technology solutions for food & agribusiness banking. Collaborating across teams to ensure robust security implementations.
Identity Security Posture Management Specialist enhancing identity security posture at Kemper Insurance. Collaborates across teams to tackle identity risks and compliance challenges in a high - performing culture.
Senior Manager overseeing Security Risk Management at First American. Leading enterprise policies, third - party vendor security, and security strategy execution.
Zscaler Engineer responsible for maintaining cybersecurity tools and developing integrations at HP. Collaborating across teams to enhance data loss prevention strategies and monitor industry threats.
Principal Architect developing cybersecurity strategy for Ensemble's technology - enabled revenue cycle management solutions. Focus on securing cloud architectures and ensuring information assurance in healthcare.
Designer developing comprehensive application solutions for security systems at Johnson Controls. Collaborating on technical sales support and large - scale integrated electronic security systems.