SENIOR PRODUCT SECURITY ENGINEER JOB DETAILS | OLYMPUS CORPORATION OF THE AMERICAS
Descripción de la oferta de empleo
MINNESOTA, BROOKLYN PARK; FLORIDA, MIAMI; MASSACHUSETTS, WESTBOROUGH; NATIONWIDE; PENNSYLVANIA, CENTER VALLEY; TENNESSEE, BARTLETT Workplace Flexibility.
Field For more than 100 years, Olympus has focused on making people’s lives healthier, safer and more fulfilling.
Every day, we live by our philosophy, True to Life, by advancing medical technologies and elevating the standard of patient care so people everywhere can fulfill their desires, dreams, and lives.
Our five Core Values empower us to achieve Our Purpose.
Patient Focus, Integrity, Innovation, Impact and Empathy.
Learn more about Life at Olympus.
**Please note.
All correspondence will be sent from our Olympus domain (@Olympus.
om).
If you receive correspondence from an entity other than @Olympus.
om, it is likely not legitimate.
Job Description The Olympus Digital Unit is developing new software-based products that will require the management of security risks.
The Senior Product Security Engineer within the Digital Unit will assist with executing the security risk management process over the lifecycle of cloud-based products including security risk analysis (inclusive of threat modeling), security risk evaluation, and security risk control.
This role will also support the assessment and mitigation of security vulnerabilities in legacy products.
This role requires technical expertise, knowledge of quality management systems for medical devices, experience with a variety of cloud deployment models (SaaS, IaaS, PaaS), and the ability to work with a global team to ensure the security and resilience of Digital Unit products.
Job Duties Performs tasks associated with security risk management for the Olympus Digital Unit.
Develops threat models for medical device systems whose functionality is supported by Google Cloud Platform, Azure, or AWS.
Develops security risk management and threat modeling documentation as required by the Olympus Quality Management System.
Supports the assessment and mitigation of security vulnerabilities in legacy products.
Supports product authorization and certification activities including ISO , SOC 2, HITRUST, and FedRAMP.
Collaborates with teams in quality, regulatory, and legal to enhance processes, procedures, and work instructions associated with security risk management and threat modeling.
Ensures compliance with regulatory requirements, industry standards, and internal policies governing product security.
Stays informed about new tools, regulations, standards, and best practices of the industry.
Job Qualifications Required.
Bachelor's degree in Computer Science, Engineering, information technology, cybersecurity, or related area required, or minimum of 5 years’ experience in a relevant industry.
Minimum of 2 years’ experience working as a Software Security Engineer or Systems Engineering professional.
Experience with embedded technology and software security.
Experience in using a Secure Product Development Framework (SPDF) within an agile environment.
Experience with security techniques and standards for authentication, authorization, and cryptography (symmetric and asymmetric).
Recent experience with threat modelling of cloud-based systems (SaaS, IaaS, or PaaS) using STRIDE or other industry-recognized methods to identify threat events and vulnerabilities.
Extensive experience with the development of data flow diagrams (DFDs) for cloud-based systems including identification of external/internal entities, processes, data stores, data flows, and trust boundaries.
Experienced user of standards, technical reports, and plans for medical device security including AAMI TIR57, AAMI TIR97, ANSI/AAMI SW96, IEC , and the Medical Device and Health IT Joint Security Plan.
Experience with applying CVSS 3.
and CVSS 4.
for vulnerability prioritization.
Experience with supporting coordinated vulnerability disclosure in a regulated industry.
Knowledge of government and sector-agnostic publications for security risk management including NIST SP , NIST SP , NIST SP , and ISO .
Experience of vulnerability handling and disclosure standards such as ISO/IEC and ISO/IEC , respectively.
Knowledge of requirements specified by IEC and ISO for medical device software life-cycle processes and medical device risk management, respectively.
Knowledge of medical device cybersecurity guidance published by the U.
.
Food & Drug Administration, EU Medical Device Coordination Group, Health Canada, Therapeutic Goods Administration (Australia), and the International Medical Device Regulators Forum (IMDRF).
Excellent analytical and troubleshooting skills.
Ability to work both independently and in a team environment.
Excellent communication skills, oral and written.
Able to work in a multi-discipline collaborative environment to include international colleagues and Olympus partners.
Preferred.
Systems engineering background preferred.
Certifications (preferred).
CISSP, CSSP, CRISC, CompTIA Security+ Why join Olympus? We offer a holistic employee experience supporting personal and professional well-being through meaningful work, equitable offerings, and a connected culture.
Equitable Offerings you can count on.
Competitive salaries, annual bonus and 401(k)* with company match Comprehensive medical, dental, vision coverage effective on start date 24/7 Employee Assistance Program Free live and on-demand Wellbeing Programs Generous Paid Vacation and Sick Time Paid Parental Leave and Adoption Assistance* 12 Paid Holidays On-Site Child Daycare, Café, Fitness Center** Connected Culture you can embrace.
Work-life integrated culture that supports an employee centric mindset Offers onsite, hybrid and field work environments Paid volunteering and charitable donation/match programs Diversity Equity & Inclusion Initiatives including Employee Resource Groups Dedicated Training Resources and Learning & Development Programs Paid Educational Assistance *US Only **Center Valley, PA and Westborough, MA Are you ready to be a part of our team? Learn more about our benefit and incentives.
At Olympus, we are committed to Our Purpose of making people’s lives healthier, safer and more fulfilling.
As a global medical technology company, we partner with healthcare professionals to provide best-in-class solutions and services for early detection, diagnosis and minimally invasive treatment, aiming to improve patient outcomes by elevating the standard of care in targeted disease states.
For more than 100 years, Olympus has pursued a goal of contributing to society by producing products designed with the purpose of delivering optimal outcomes for its customers around the world.
Headquartered in Tokyo, Japan, Olympus employs more than employees worldwide in nearly 40 countries and regions.
Olympus Corporation of the Americas, a wholly owned subsidiary of Olympus Corporation, is headquartered in Center Valley, Pennsylvania, USA, and employs more than employees throughout locations in North and South America.
For more information, visit www.
lympusamerica.
om.
Olympus is dedicated to building a diverse, inclusive and authentic workplace We recognize diversity in people, views and lifestyle choices and emphasize the importance of inclusion and mutual respect.
We strive to continue to foster empathy and unity in the workplace so that our employees can fully contribute and thrive.
Let’s realize your potential, together.
It is the policy of Olympus to extend equal employment and advancement opportunity to all applicants and employees without regard to race, color, national origin (including language use restrictions), citizenship status, religious creed (including dress and grooming practices), age, sex (including pregnancy, childbirth, breastfeeding, medical conditions related to pregnancy, childbirth and/or breastfeeding), gender, gender identity and expression, sexual orientation, marital status, disability (physical or mental) and/or a medical condition, genetic information, ancestry, veteran status or service in the uniformed services, and any other characteristic protected by applicable federal, state or local law.
Applicants with Disabilities.
As a Federal Contractor, Olympus is committed to ensuring our hiring process is accessible to everyone.
If you need an accommodation in order to complete the application or hiring process, please contact Olympus via email at .
If your disability impairs your ability to email, you may call our HR Compliance Manager at -Olympus ().
Posting Notes.
|| United States (US) || Minnesota (US-MN) || Brooklyn Park || Research and Development
Detalles de la oferta
- Olympus Corporation of the Americas
- En todo México
- Sin especificar - Sin especificar
- 26/12/2024
- 26/03/2025
Drive the communication with the customer to ensure the customer has confidence on problem resolution define and understand the customer issue by creating adequate reproduction scenarios... key responsibilities: ability to take technical/functional leadership in one specific product or area of business......
Requisitos del puestogood knowledge of the architecture of the tandem platform good knowledge in handling tacl macros, obey files, shell script good knowledge in middleware configuration like pathway, mq good knowledge of tcp/ip and socket management... candidateshould have good communication skills......
Responsibilities spend 90% of your time actively designing and coding in support of the immediate team... understanding of sql and nosql is preferred... a minimum of 5 years experience in... catering to companies of all sizes and industries, including some of the world's largest brands, sonatafy technology......
Ensuring the best performance and user experience of the application... demonstrable portfolio of released applications on the app store or the android market... strong knowledge of architectural patterns—mvp, mvc, mvvm, and clean architecture—and the ability to choose the best solution for the app......
Catering to companies of all sizes and industries, including some of the world's largest brands, sonatafy technology is a trusted provider of nearshore enterprise-level cloud and mobile application software development services... lead the identification, innovation, and implementation of new tools and......
Essential: graduated industrial engineer or related... the position requires constant communication with clients abroad... preferably more than one year experience in the automotive or aviation industry... customer service quotations and follow-ups search for new customers apqp administration constant......
Requisitos del puesto good knowledge of the unisys platform architect good knowledge of cobol and algol programming languages good knowledge of dmsii and socket management programming... we are looking for an enthusiastic and motivated “senior unisys developer” in our development team......
Requisitos del puesto good knowledge of the tandem platform architecture good knowledge of cobol85, c and tal programming languages good knowledge in programming with pathway middleware... candidate should have good communication skills, be a team player and be able to lead a team......
Requisitos del puesto good knowledge of red hat linux platform architecture good knowledge of programming languages such as c, c++, java and python good knowledge of middlewares such as weblogic, was, solace, etc... we are looking for an enthusiastic and motivated “senior software developer” in......
Requisitos del puestogood knowledge in oracle database managementgood knowledge of web servers platform architecturegood knowledge of cobol85, c and tal programming languages... we are looking for an enthusiastic and motivated “senior software developer” in our development team......