Cybersecurity Engineer III

Posted Yesterday
Be an Early Applicant
Burnaby, BC, CAN
In-Office
125K-193K Annually
Senior level
Healthtech • Industrial • Manufacturing
The Role
Leads cybersecurity engineering for connected medical devices across the product lifecycle. Responsibilities include security architecture, system threat modeling, regulatory requirement derivation, verification evidence, penetration testing, vulnerability assessment, remediation planning, interoperability security, and audit-ready documentation. The role coordinates with Systems, Software, Quality, and Regulatory teams while maintaining product security plans and supporting FDA, QMS, and medical device cybersecurity compliance.
Summary Generated by Built In
Company Overview

Verathon is a global medical device company focused on supporting customers by being their trusted partner, delivering high-quality products that endure over time and ensure clinical and economic utility. Two areas where Verathon has significantly impacted patient care, and become the market leader in each, are bladder volume measurement and airway management. The company’s BladderScan portable ultrasound and GlideScope video laryngoscopy & bronchoscopy systems effectively address unmet needs for healthcare providers and meaningfully raise the standard of care for patients. Verathon, a subsidiary of Roper Technologies, is headquartered in Bothell, Washington, USA and has international subsidiaries in Canada, Europe and Asia Pacific. For more information, please visit www.verathon.com.

Overview

The Cybersecurity Engineer is responsible for leading the system-level cybersecurity engineering activities required to design and sustain secure medical devices across Verathon's product portfolio. This role is the primary owner of product security architecture, system threat modeling, and the translation of FDA and consensus standards guidance into actionable security requirements and verification evidence. Working closely with Software Engineering, Quality, and Regulatory teams, the Cybersecurity Systems Engineer ensures that Verathon's products are designed and documented to satisfy regulatory expectations throughout the product lifecycle, from initial design through post-market sustaining activities.

Responsibilities 
  • Define product security architecture, including trust boundaries, control objectives, and interface documentation; specify and review designs for authentication, authorization, cryptography, secure update mechanisms, event logging, data integrity, and system hardening
  • Lead system-level threat modeling (e.g., STRIDE / MITRE ATT&CK for ICS) and allocate mitigations across hardware, firmware, and software; ensure trust-boundary assumptions are explicit, traceable, and testable
  • Derive cybersecurity requirements from FDA guidance and consensus standards (IEC 62443, IEC 81001-5-1, AAMI SW96); define verification strategies specifying required evidence, timing, and ownership
  • Produce and maintain design-level product security documentation including architecture views, control rationale, security requirements traceability matrices, and interface/external connection records
  • Own the engineering interface during penetration testing engagements: lead scope clarification, environment setup, and technical Q&A; assess design impact of findings; define remediation technical approach and support retest readiness
  • When post-release remediation is required, define technical scope and verification approach; coordinate with engineering and release functions to ensure validated deployment and documentation closure
  • Lead interoperability security assessments for device interfaces with external systems, networks, and devices; evaluate security and safety risks across normal and fault operating modes and define appropriate risk controls for interface trust boundaries
  • Conduct CVE impact analysis for fielded products; assess applicability of newly disclosed vulnerabilities to system-level components and architecture; support prioritization and remediation scoping
  • Contribute to release readiness for security-driven sustaining updates, including inputs to patch packaging, documentation updates, and design change records
  • Collaborate with the Software to ensure security requirements are correctly allocated and verification evidence is complete across the system
  • Work cross-functionally across Systems, Software, Quality, and Regulatory disciplines to align on security architecture decisions and ensure consistent implementation
  • Own and maintain the Product Security Management Plan and associated Product Security Management File, ensuring all required cybersecurity activities are planned, traceable, and audit-ready
  • Support Verathon's Quality Management System (QMS), including participation in design reviews, ECO procedures, and DHF/regulatory submission artifact preparation
  • Stay current with evolving FDA cybersecurity guidance, NIST CSF, and relevant medical device security standards; identify implications for Verathon products and processes
Qualifications
  • Bachelor's degree in Systems Engineering, Electrical Engineering, Computer Engineering, or a related technical discipline is required
  • 5+ years of demonstrated experience in systems engineering, product security engineering, or a related field, with at least 3 years focused on cybersecurity for connected or regulated products
  • Demonstrated experience with system-level threat modeling methodologies (e.g., STRIDE, PASTA, or TARA as defined in IEC 81001-5-1 / AAMI SW96)
  • Working knowledge of medical device cybersecurity regulatory requirements, including FDA premarket and postmarket cybersecurity guidance, IEC 81001-5-1, AAMI SW96, and IEC 62443
  • Experience defining security requirements and producing verification evidence in a regulated product development environment (FDA QSR / ISO 13485 QMS preferred)
  • Experience with CVE/NVD triage and vulnerability impact assessment at the system level including CVSS-based vulnerability scoring and cybersecurity risk assessment methodologies
  • Experience supporting or managing third-party penetration testing engagements, including findings triage and remediation scoping, is strongly preferred
  • Working knowledge of networking fundamentals (ports, protocols, firewalls) and OS-level security concepts across Linux and/or Windows environments relevant to connected medical devices
  • Relevant security certification (e.g., CISSP, CISM, CEH, CompTIA Security+, or equivalent) is preferred; candidates with equivalent demonstrated experience will be considered
  • Familiarity with SBOM concepts and supply chain security considerations for medical devices is an asset
  • Strong written communication skills with demonstrated ability to produce clear, audit-ready technical documentation
Why Join Us?
  • Be part of an innovative team that is dedicated to improving patient outcomes.
  • Engage in meaningful work that makes a difference in the healthcare industry.
  • Competitive salary and comprehensive benefits package.
    • Salary range - $125,000 - $193,400  (Compensation will vary based on skills, experience and location; it is not typical to be hired at or above the top of the salary range).
    • Full-time employees who are not on a commission plan are eligible for Verathon’s annual bonus plan based on company and individual performance.
    • Verathon provides a competitive benefits package including a generous HCSA, paid holidays, paid time off and a retirement matching plan.

Skills Required

  • Bachelor’s degree in Systems Engineering, Electrical Engineering, Computer Engineering, or a related technical discipline
  • 5+ years of experience in systems engineering, product security engineering, or a related field
  • At least 3 years focused on cybersecurity for connected or regulated products
  • Experience with system-level threat modeling methodologies such as STRIDE, PASTA, or TARA
  • Working knowledge of medical device cybersecurity requirements, including FDA guidance, IEC 81001-5-1, AAMI SW96, and IEC 62443
  • Experience defining security requirements and producing verification evidence in a regulated product development environment
  • Experience with CVE/NVD triage, vulnerability impact assessment, CVSS scoring, and cybersecurity risk assessment
  • Experience supporting or managing third-party penetration testing engagements
  • Working knowledge of networking fundamentals, ports, protocols, firewalls, and OS-level security across Linux and/or Windows
  • Relevant security certification such as CISSP, CISM, CEH, CompTIA Security+, or equivalent
  • Familiarity with SBOM concepts and supply chain security for medical devices
  • Strong written communication skills and ability to produce clear, audit-ready technical documentation
Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
HQ: Bothell, WA
714 Employees
Year Founded: 1984

What We Do

Verathon is a global medical device company focused on supporting customers by being their trusted partner, delivering high-quality products that endure over time and ensure clinical and economic utility. Two areas where Verathon has significantly impacted patient care, and become the market leader in each, are bladder volume measurement and airway management. The company’s BladderScan portable ultrasound and GlideScope video laryngoscopy systems effectively address unmet needs for healthcare providers and meaningfully raise the standard of care for patients. Verathon, a subsidiary of Roper Technologies, is headquartered in Bothell, Washington, and has international subsidiaries in Canada, Europe and Asia. For more information, please visit www.verathon.com

Similar Jobs

Square Logo Square

Product GTM Operations Senior Manager

eCommerce • Fintech • Hardware • Payments • Software • Financial Services
Remote or Hybrid
8 Locations
12000 Employees
164K-297K Annually

CrowdStrike Logo CrowdStrike

Sr. Competitive Intelligence Analyst, Exposure Management (Remote)

Cloud • Computer Vision • Information Technology • Sales • Security • Cybersecurity
Remote or Hybrid
5 Locations
11000 Employees
145K-225K Annually

Block Logo Block

Product GTM Operations Senior Manager

Blockchain • eCommerce • Fintech • Payments • Software • Financial Services • Cryptocurrency
In-Office or Remote
8 Locations
12000 Employees
164K-297K Annually

Block Logo Block

Staff Software Engineer

Blockchain • eCommerce • Fintech • Payments • Software • Financial Services • Cryptocurrency
In-Office or Remote
8 Locations
12000 Employees
264K-395K Annually

Similar Companies Hiring

OneImaging Thumbnail
Healthtech
Miami, FL
62 Employees
Rosendin Thumbnail
Other • Manufacturing
San Jose, CA
6219 Employees
Amalgamated Sugar Thumbnail
Food • Greentech • Agriculture • Industrial • Manufacturing
Boise, Idaho
768 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account