Product Security Manager overseeing cybersecurity architecture and engineering at Smith+Nephew. Ensuring robust cyber security controls throughout product development and collaborating with R&D and Compliance Teams.
Responsibilities
Encourage the development and advancement of personnel on their team
Help develop and mature Global Product Security Strategy and Secure-Software Development Life Cycle (S-SDLC)
Oversee the definition and support the implementation of cybersecurity requirements and controls
Lead the creation and maintenance of Product Cybersecurity Risk Registers and Threat Models
Lead the execution and integration of cybersecurity testing and assessment activities
Support best practice product cyber security incident response (IR) activities
Provide technical leadership and competency in communications with stakeholders outside of Smith + Nephew
Requirements
Bachelor's degree in life science, computer science, information systems and/or equivalent formal training or work experience
5+ years in hands-on cybersecurity experience
2+ years people management experience
Strong ability to influence and think strategically
Clear understanding of mitigating security controls, vulnerability management, penetration testing, and code security
FDA and other medical device regulators
Knowledge of cyber security standard frameworks such as HIPAA, FDA, ISO 27001/2, NIST CSF, and OWASP
Understanding of network infrastructure, including firewalls, web proxy and/or email architecture- particularly as they apply in a mitigating control functionality
Experience with different cloud computing platforms and the cloud security framework
Ability to design, recommend, plan, guide, and support implementation of innovative security solutions
Current CISM, CISSP, CRISC, or equivalent certification preferred.
Application Security Specialist focusing on security in software development lifecycle at Insight Investment in Manchester, driving DevSecOps practices across teams.
Cyber Security Engineer supporting mission - critical DoD contract at CACI. Involves reviewing infrastructure changes and implementing security measures in a cloud - based environment.
Security Incident Management Analyst coordinating information security incidents. Overseeing cyber incident response and providing guidance to senior management within a leading industrial software company.
Customer Security Engineer managing end - to - end pentesting services at Aikido Security. Ensuring customer value and addressing vulnerabilities for a developer - first security product.
Cybersecurity GRC Specialist developing compliance standards across IT environments at Axpo Group. Collaborate with teams to safeguard critical systems and implement cybersecurity policies in energy sector.
Lead Cybersecurity Specialist managing enterprise cybersecurity programs at NexThreat. Overseeing cybersecurity research, engineering, and technical services while ensuring federal compliance.
Manager overseeing Netflix's global physical security technology design and build programs across multiple business verticals. Leading a team to ensure best - in - class security systems and vendor management.
Information System Security Officer liaising between Cybersecurity Group and information owners. Ensuring compliance and security posture for national security IT systems in a hybrid environment.
Information System Security Officers maintaining IT security posture through collaboration with stakeholders. Supporting system security policies and risk management for national cybersecurity objectives.
Technician in workplace health and safety conducting interventions in member companies of CIAMT. Focusing on risk prevention and improving workplace safety conditions.