Irhythmtech

Irhythmtech

Senior Product Security Manager

San Francisco, United States of America · Senior

Sponsorship not specified$173k-$225kDetected 11 hours ago
AlgorithmsGitCI/CDData AnalysisCybersecurityPenetration TestingSOC OperationsDetection EngineeringIncident ResponseComplianceProduct ManagementSupply ChainEmbedded SystemsHIPAAPatient CareFDA RegulatoryMedical DevicesLeadershipCommunicationCISSP

About the role

  • We are seeking a Senior Product Security Manager with proven experience in the medical device industry.
  • In this role, you will safeguard medical devices by identifying, assessing, and mitigating security risks unique to healthcare technology.
  • Translate complex cybersecurity risks into clear, actionable guidance for engineering and business stakeholders.

Responsibilities

  • Provide senior-level cybersecurity leadership across product development, influencing secure design decisions at scale.
  • Drive adoption and continuous improvement of the Secure Product Development Framework (SPDF) and secure SDLC practices.
  • Develop and maintain cybersecurity documentation to support pre- and post-market regulatory requirements.
  • Lead and mature cybersecurity risk management practices, including threat modeling, Cybersecurity Risk Assessments (CSRAs), and security design reviews.
  • Develop and maintain threat models and data flow diagrams, incorporating considerations for patient safety, data privacy, and system integrity.
  • Secure Architecture & Design
  • Participate in design reviews, providing actionable recommendations to strengthen system security requirements.
  • Every day, we collaborate, create, and constantly reimagine what's possible.

Requirements

  • Bachelor's degree in Computer Science, Information Security, or related field
  • 12+ years of experience in product security or related cybersecurity roles
  • Deep expertise in securing complex, software-driven and safety-critical systems
  • Experience operating in regulated environments (FDA, HIPAA, GDPR)
  • Familiarity with frameworks such as NIST, ISO 14971, IEC 62304, and related standards

Nice to have

  • Professional certifications such as CISSP, CISM, CRISC
  • Experience with CI/CD security tooling (SAST, DAST, SCA) and shift-left practices
  • Familiarity with global regulatory standards (EU MDR, GDPR, ISO/IEC 81001-5-1)
  • Experience supporting SBOM programs and PSIRT operations
  • Understanding of penetration testing methodologies
  • $173,000.00 - $225,000.00
  • We welcome and celebrate people of all backgrounds, experiences, skills, and perspectives. iRhythm Technologies, Inc. is an Equal Opportunity Employer.
  • We will consider for employment all qualified applicants with arrest and conviction records in accordance with all applicable laws.

Skills

  • Advise on and review secure architectures across embedded systems, applications, cloud, and IoMT platforms.

Compensation

  • Estimated Pay Range

Benefits

  • Curious and innovative problem solvers looking for the chance to meaningfully shape the future of cardiac health, our company, and your career
  • iRhythm is a leading digital healthcare company that creates trusted solutions that detect, predict, and prevent disease.
  • Through a relentless focus on patient care, iRhythm's vision is to deliver better data, better insights, and better health for all.

Company info

  • As a part of our core values, we ensure an inclusive workforce.

Equal opportunity

  • Equal Opportunity Employer.

This listing is sourced directly from Irhythmtech's careers page and normalized into a canonical job model.