Senior Cybersecurity Engineer (Hybrid or Remote)

Q Bio
Redwood City, CA

The Role:

At Q Bio, we are transforming healthcare by combining AI, Physics, and Biology to automate the physical exam, making preventive, personalized care accessible to all. We are hiring a Senior Cybersecurity Engineer to join our dynamic team, focusing on embedding security throughout our product lifecycle. You will be instrumental in designing, building, automating, and maintaining the secure deployment and monitoring of our cutting-edge products.

$170,000 - $200,000 a year

What You Will Do:

Product & Medical Device Security (FDA Regulated Environment):

● Secure Software Development Lifecycle (SDLC): Integrate security best practices and tools into every phase of the product development lifecycle, from design and requirements to coding, testing, and deployment.

● Threat Modeling & Risk Analysis: Lead and perform threat modeling and security risk analysis (per ISO 14971) for new and existing medical device software.

● FDA & Regulatory Compliance: Author, review, and own all cybersecurity-related documentation for regulatory submissions (e.g., FDA 510(k) pre-market and post-market management plans). Ensure our products and processes align with the latest FDA guidance, IEC 62304, and other relevant medical device security standards.

● Regulatory Interface: Serve as the primary cybersecurity subject matter expert (SME) for regulatory interactions, including responding to questions during FDA submissions and representing the company's cybersecurity posture during audits.

● Security Requirements Definition: Partner with Product Management, Engineering, and Quality teams to define and document security requirements, controls, and architecture for our medical device platforms.

● Vulnerability Management & Penetration Testing: Manage and coordinate third-party penetration testing and internal vulnerability assessments of our products. Develop and oversee the remediation action plan.

● Incident Response: Develop, implement, and maintain an incident response plan for product-related security events, including vulnerability disclosure policies.

Corporate Security & Compliance:

● Continuous Security Assessment & Strategy: Continuously assess the company's security posture against evolving business needs and emerging threats. Identify relevant security standards (e.g., SOC 2, HIPAA, NIST CSF), perform regular gap analyses, and own the strategic roadmap for assessment, implementation, and improvement.

● Compliance Frameworks (SOC 2 / HIPAA): Lead the initiative to achieve and maintain SOC 2 certification for our platform and business operations. Develop and manage the security controls and policies required for SOC 2 and HIPAA Security Rule compliance.

● Corporate Security Governance: Develop, implement, and enforce company-wide information security policies, procedures, and standards.

● IT & Cloud Security: Conduct security architecture reviews and risk assessments of our corporate IT and cloud infrastructure (AWS/GCP/Azure). Implement and manage security controls to protect corporate data and systems.

● Vendor & Third-Party Risk Management: Establish and manage a program to assess and monitor the security posture of third-party vendors and partners.

● Identity & Access Management (IAM): Oversee and improve the company's IAM policies and solutions to ensure the principle of least privilege is maintained.

What You Will Bring:

● 5+ years of experience in cybersecurity, with at least 3-5 years in a hands-on, senior or lead role.

● Proven experience in a regulated industry, with a strong preference for MedTech (medical devices), HealthTech, or Life Sciences.

● FDA Expertise: Demonstrated, hands-on experience with FDA cybersecurity guidance for medical devices, contributing to the cybersecurity sections of regulatory submissions (e.g., 510(k), PMA), and acting as a subject matter expert in direct interactions with regulatory bodies (e.g., responding to submission questions, participating in audits).

● Compliance Expertise: Direct experience leading or playing a primary role in achieving and maintaining SOC 2 and/or HIPAA compliance.

● Product Security: Strong experience with application security, secure SDLC practices, threat modeling (e.g., STRIDE), and vulnerability management for software products.

● Cloud Security: Deep knowledge of securing cloud environments and services (AWS, GCP, or Azure).

● Technical Skills: Proficiency with security assessment tools, IAM systems, endpoint protection, and network security concepts.

● Bachelor's degree in Computer Science, Information Security, or a related field.

● Relevant professional certifications are highly desirable (e.g., CISSP, CISM, HCISPP, CSSLP).

Posted 2025-09-22

Recommended Jobs

AGS NAMER Sales Planning Lead

Amazon Web Services, Inc.
Mountain View, CA

DESCRIPTION AWS Global Sales (AGS) drives adoption of the AWS cloud worldwide, enabling customers of all sizes to innovate and expand in the cloud. Our team empowers every customer to grow by prov…

View Details
Posted 2025-09-10

(USA) Manager, Marketing

Walmart Inc.
Los Angeles, CA

What you'll do at Position Summary... The VIZIO Platform Content & Partnerships Marketing team is looking for a strategic and creative Manager, Partner Marketing to support VIZIO OSs 300+ ente…

View Details
Posted 2025-08-25

Senior/Staff Forward Deployed AI Engineer

Coders Connect
San Francisco, CA

Coders Connect is partnering with an ambitious, AI-first healthtech startup that’s redefining the revenue cycle in healthcare through generative AI. They build cutting-edge LLM-powered tools …

View Details
Posted 2025-09-22

ASE Certified Master Mechanic (Vehicles & Equipment)

Pioneer Desert Manufacturing
Yuba City, CA

We are hiring an experienced ASE Certified Master Mechanic proficient in diagnosing, maintaining, and repairing both light-duty vehicles and heavy equipment. The role involves technical leadership,…

View Details
Posted 2025-09-11

BA - Media and Entertainment Exp. - Infrastructure preferred - 1099 - 3 to 6 months

Waveseven
Los Angeles, CA

Looking for a BA with media and entertainment experience - preferably Infrastructure experience to assist a client with a project tracking project as part of a PMO office.

View Details
Posted 2025-08-16

Community Health Coordinator (CHC) Program- Independent Contractor

COPE Health Solutions
Los Angeles, CA

Description The Community Health Coordinator (CHC) is responsible for helping members and their families to navigate and access community services, and other resources, to support Social Drivers …

View Details
Posted 2025-08-15

Registered Dental Hygienist

Marin Contemporary Perio and Implant Concepts
San Rafael, CA

Registered Dental Hygienist Join Our Dedicated Team of Dental Professionals! Are you a passionate Dental Hygienist looking to make a meaningful impact in a thriving dental practice? We invite you …

View Details
Posted 2025-07-29

AT&T Sales Representative

Channel Focus
Oakland, CA

Our company is a prominent sales firm that partners with premier telecommunications clients, like AT&T, to deliver customer-centric sales solutions. Our goal is to provide products and services that…

View Details
Posted 2025-09-10

Staff Manufacturing Hardware Test Engineer

Aurora Innovation
Mountain View, CA

Aurora hires talented people with diverse backgrounds who are ready to help build a transportation ecosystem that will make our roads safer, get crucial goods where they need to go, and make mobility…

View Details
Posted 2025-09-22

Senior Research Associate/Associate Scientist, Antibody Screening and Display

CEDENT
Berkeley, CA

Client uses a combination of novel, cutting edge methods in machine learning, biology at scale and next gen antibody discovery that address key bottlenecks in the drug development pipeline. To accompl…

View Details
Posted 2025-07-31