Irhythmtech
Senior Product Security Manager
San Francisco, United States of America · Senior
Sponsorship not specified$173k-$225kDetected 11 hours ago
AlgorithmsGitCI/CDData AnalysisCybersecurityPenetration TestingSOC OperationsDetection EngineeringIncident ResponseComplianceProduct ManagementSupply ChainEmbedded SystemsHIPAAPatient CareFDA RegulatoryMedical DevicesLeadershipCommunicationCISSP
About the role
- We are seeking a Senior Product Security Manager with proven experience in the medical device industry.
- In this role, you will safeguard medical devices by identifying, assessing, and mitigating security risks unique to healthcare technology.
- Translate complex cybersecurity risks into clear, actionable guidance for engineering and business stakeholders.
Responsibilities
- Provide senior-level cybersecurity leadership across product development, influencing secure design decisions at scale.
- Drive adoption and continuous improvement of the Secure Product Development Framework (SPDF) and secure SDLC practices.
- Develop and maintain cybersecurity documentation to support pre- and post-market regulatory requirements.
- Lead and mature cybersecurity risk management practices, including threat modeling, Cybersecurity Risk Assessments (CSRAs), and security design reviews.
- Develop and maintain threat models and data flow diagrams, incorporating considerations for patient safety, data privacy, and system integrity.
- Secure Architecture & Design
- Participate in design reviews, providing actionable recommendations to strengthen system security requirements.
- Every day, we collaborate, create, and constantly reimagine what's possible.
Requirements
- Bachelor's degree in Computer Science, Information Security, or related field
- 12+ years of experience in product security or related cybersecurity roles
- Deep expertise in securing complex, software-driven and safety-critical systems
- Experience operating in regulated environments (FDA, HIPAA, GDPR)
- Familiarity with frameworks such as NIST, ISO 14971, IEC 62304, and related standards
Nice to have
- Professional certifications such as CISSP, CISM, CRISC
- Experience with CI/CD security tooling (SAST, DAST, SCA) and shift-left practices
- Familiarity with global regulatory standards (EU MDR, GDPR, ISO/IEC 81001-5-1)
- Experience supporting SBOM programs and PSIRT operations
- Understanding of penetration testing methodologies
- $173,000.00 - $225,000.00
- We welcome and celebrate people of all backgrounds, experiences, skills, and perspectives. iRhythm Technologies, Inc. is an Equal Opportunity Employer.
- We will consider for employment all qualified applicants with arrest and conviction records in accordance with all applicable laws.
Skills
- Advise on and review secure architectures across embedded systems, applications, cloud, and IoMT platforms.
Compensation
- Estimated Pay Range
Benefits
- Curious and innovative problem solvers looking for the chance to meaningfully shape the future of cardiac health, our company, and your career
- iRhythm is a leading digital healthcare company that creates trusted solutions that detect, predict, and prevent disease.
- Through a relentless focus on patient care, iRhythm's vision is to deliver better data, better insights, and better health for all.
Company info
- As a part of our core values, we ensure an inclusive workforce.
Equal opportunity
- Equal Opportunity Employer.
Apply directly at Irhythmtech →Create a free account for alerts like thisView Irhythmtech immigration profile
This listing is sourced directly from Irhythmtech's careers page and normalized into a canonical job model.