Senior Cyber Security Engineer Job at Spacelabs

Spacelabs Snoqualmie, WA 98065

Overview:
At Spacelabs Healthcare, we are on a mission to provide continuous innovation in healthcare technology for better clinical and economic outcomes. Our scalable solutions deliver critical patient data across local and remote systems, enable better-informed decisions, increase efficiencies, and create a safer environment for patients.

Why work at Spacelabs? Because lives depend on you!

We are looking for a highly motivated engineer specializing in product security to work on Spacelabs product portfolio and future R&D projects. You will participate in technical research and development to enable continuing innovation for Spacelabs products and cloud services.
As a Senior Cybersecurity Engineer for Spacelabs, you will be expected to analyze medical devices, system services, operating systems, networks, and applications from a security perspective. You will be expected to be skilled at discovering security risks, issues and recommending remediation and mitigation strategies. You will participate in security audits. Lead risk assessments, vulnerability assessments, secure code testing, SOUP testing and threat models.

Proficiency in security and cloud security engineering and development is desired. Maintaining a current understanding of the latest security threats, trends and technologies is a crucial component of the position. The ideal candidate needs excellent verbal and written communication skills with the ability to understand business requirements.
To succeed in this position, candidate must be able to develop security technology strategies that align with Spacelabs organizational goals and operations and protect the confidentiality, integrity and availability of information systems and our data without impacting patient safety.
Decisions require analytical, interpretative, and creative thinking that may not conform to established patterns to solve security problems. They must effectively communicate highly complex technical issues with confidentiality and sensitivity to diverse audiences as appropriate.

Your role will involve using a degree of independent judgment; working closely with the R&D and other departments; understanding and supporting Spacelabs mission, vision, priorities, and company values.
We are looking for a Senior Cybersecurity Engineer to join our team in our Spacelabs Snoqualmie office and work with our global cybersecurity team.
Responsibilities:
  • Ensure that Spacelabs products are implemented to a high security standard that adheres to regulatory and industry standard requirements.
  • Lead security initiatives and serves as Point of Contact
  • Provide security guidance as Subject Matter Expert on all Spacelabs products and services.
  • Work with teams to implement, identify and advance security at Spacelabs.
  • Manage the security Product Requirement Documents (PRD) for the assigned Spacelabs products and/or services.
  • Implement product and testing solutions in Security lab.
  • Conduct product risk assessments, prioritize threats, and help develop mitigation strategies.
  • Conduct security testing and audit for product software and infrastructure.
  • Collaborate with the engineering team to perform regular product vulnerability assessments, secure code testing, SOUP testing and threat models.
  • Conducting and/or analyzing vulnerability assessments to validate system compliance with Risk Management Framework controls and DISA Security Technical Information Guidelines (STIGS) and/or CIS Benchmarks
  • Participate in and assist with the development of product documentation, security documentations and test protocols.
  • Responsibility for validating and analyzing the security test results, producing summary reports and interpretation.
  • Liaison with the US government for RMF activities and follow-ups
  • Update and maintain Plan of Actions and Milestones (POA&M) documentation for product RMF maintenance.
  • Responsible for overseeing, supporting, and documenting the secure implementation and administration of the Spacelabs AWS and EC2 cloud services.
  • Manage security controls using SecureFrame (security compliance automation)
  • Uphold the company’s core values of Integrity, Innovation, Accountability, and Teamwork.
  • Demonstrate behavior consistent with the company’s Code of Ethics and Conduct.
  • It is the responsibility of every Spacelabs Healthcare employee to report to their manager or a member of senior management any quality problems or defects for corrective action to be implemented and to avoid the recurrence of the problem.
  • Duties may be modified or assigned at any time to meet the needs of the business.
Qualifications:
  • Must be a U.S. citizen or have a Permanent Resident Card (green card)
  • Bachelor's degree in Computer Science, a related technical field or equivalent practical experience
  • In-depth knowledge of IT concepts, strategies, and methodologies. In-depth knowledge of diverse and emerging technologies and new architectural concepts and principles.
  • Knowledgeable in cloud computing environments, security infrastructure, and cloud pipeline deployment; proficient in new and emerging technologies.
  • Able to demonstrate clear understanding of current cybersecurity threats to on-premises products and Cloud infrastructure and/or IT infrastructures at technical and managerial levels.
  • Highly developed negotiation, consensus building & influencing skills, facilitation, and the adaptability to respond to change quickly. Highly developed oral and written communication skills; strong presentation skills.
  • 10+ years of experience in IT and Cybersecurity
  • Experience in web app security, vulnerability research, and security assessments
  • Strong familiarity with OWASP Top 10 vulnerabilities, their discovery, exploitation and remediations
  • Strong foundation in computer and network security, authentication, security protocols and applied cryptography.
  • Strong English communication skills that include the capability to clearly communicate information security concepts and risks both orally and in writing.
  • Adept at reading, writing, and interpreting technical documentation and procedures.
  • Familiarity with networking implementations
  • Skilled at working within a team-oriented, collaborative environment.
  • Ability to be able to work across global time zones when the need arises.
  • Must have AWS Certified Security certification.
  • Strong organizational skills, attention to detail and ability to multi-task
  • Ability to troubleshoot and work under minimal direction.
  • Must have or be willing and able to obtain a security clearance.

PREFERRED QUALIFICATIONS:
  • Must have or be willing and able to obtain a security certification, such as Security+, CISSP, CEH, CCSP, CCNA Security
  • Experience in working in a healthcare delivery organization or a medical device manufacturer is desirable.
  • 3+ years of experience working in the Product Security space, as a builder or breaker
  • Cybersecurity Framework experience such as NIST 800-53, NIST 800-17, and ISO 27001 governance and compliance standards hands-on experience.
  • Familiarity with at least some of the following: C, C++, Java, Python, Go, JavaScript
  • Experience with implementing controls and hardening guidelines such as CIS Benchmarks or Security Technical Implementation Guidelines (STIGs) is a plus.
  • Experience performing software security testing of products using software code analysis tools is a plus.
  • Experience working with cryptography and Anti-Tamper design knowledge.
  • Experience working with US government agencies is a plus.
  • Experience working with government RMF processes such as DoD 8510.01 is a plus.


Please review our benefits here:
Life at OSI
The specific programs and options available to any given employee may vary depending on eligibility factors such as geographic location and date of hire. Please note that the salary information shown above is a general guideline only. Salaries are based upon candidate experience and qualifications, as well as market and business considerations.


NOTICE TO THIRD PARTY AGENCIES

OSI Systems, Inc. and its subsidiaries (collectively “OSI”) does not accept unsolicited resumes from recruiters or employment agencies. If any person or entity, including a recruiter or agency, submits any information, including any resume or information regarding any potential candidate, without a signed agreement in place with OSI, OSI explicitly reserves the right to use such information, and pursue and/or hire such candidates, without any financial obligation to the person, recruiter or agency. Any unsolicited information or resumes, including those submitted directly to hiring managers, are considered and deemed to be the property of OSI.


Equal Opportunity Employer - Disability and Veterans

EEO is the Law


Poster Link: https://www.eeoc.gov/sites/default/files/2022-10/22-088_EEOC_KnowYourRights_10_20.pdf

OSI Systems, Inc. has three operating divisions: (a) Security, providing security and inspection systems, turnkey security screening solutions and related services; (b) Healthcare, providing patient monitoring, diagnostic cardiology and anesthesia systems; and (c) Optoelectronics and Manufacturing, providing specialized electronic components and electronic manufacturing services for original equipment manufacturers with applications in the defense, aerospace, medical and industrial markets, among others.




Please Note :
blog.nvalabs.org is the go-to platform for job seekers looking for the best job postings from around the web. With a focus on quality, the platform guarantees that all job postings are from reliable sources and are up-to-date. It also offers a variety of tools to help users find the perfect job for them, such as searching by location and filtering by industry. Furthermore, blog.nvalabs.org provides helpful resources like resume tips and career advice to give job seekers an edge in their search. With its commitment to quality and user-friendliness, Site.com is the ideal place to find your next job.