As the leading company in the field of software solutions for healthcare, we operate in 19 countries and employ over 9,000 dedicated staff members. You will work in a dynamic and innovative environment full of opportunities. With your commitment and passion, you have the chance to make a sustainable difference.
CGM Leverages AI: We’re looking for people who feel the power of AI in the e-health environment, who want to help shape change, and who are driven by a curious passion to see how technology can make healthcare smarter, simpler, and better.
Together, we are shaping the healthcare system of the future. Become part of our mission and make a difference – for a world where knowledge saves lives!
Are you passionate about groundbreaking products? Do you have the talent to turn ideas into real, valuable solutions—while always keeping the bigger picture in mind? Then we’d love to meet you!
Your Responsibilities:
- You define and own the product security strategy for our global portfolio and establish the policy framework for secure development, security baselines, and release criteria.
- You drive CRA readiness across the entire portfolio – from product classification to conformity assessment, and the build-out of SBOM and evidence processes.
- You set the mandatory security tooling baseline (SAST, DAST, SCA, secrets scanning) and define security quality gates within the delivery pipeline.
- You shape the governance for our AI-driven security remediation (agentic OpenCode pipeline) – including guardrails, approval criteria, and quality assurance.
- You build the Security Guild and a network of Security Champions embedded in the FIRE teams, and foster lived security practice through training and coaching
Your Profile:
- Several years of experience in product security, application security, or as a deputy CISO within a complex, multi-product software organisation.
- Demonstrable, current expertise in the EU Cyber Resilience Act – requirements, classification logic, and conformity assessment – along with working knowledge of NIS2 and GDPR.
- Strong, practical knowledge of the secure development lifecycle, threat modelling, and application security testing, together with hands-on experience with SAST, DAST, SCA, and SonarQube tooling.
- Experience with SBOM generation and governance, as well as with managing supply chain risk; understanding of AI-assisted and agentic development workflows.
- Strong communication and stakeholder management skills to enforce standards without direct line authority; CISSP or an equivalent certification is an advantage.
What you can expect from us:
Mobile work: Work flexibly on the move two days a week and on site three days a week.
Attractive locations: In addition to fully equipped workplaces, regular events such as summer parties and Christmas parties await you at our locations.
Development: Our in-house academy and our portfolio of external cooperation partners will support you in your further development.
Health: Health is a valuable asset for us. Our in-house canteen offers a selection of tasty and healthy dishes every day, and we welcome you to our fully equipped fitness center for weekly courses (online & offline).
More is always possible: The kindergarten on our CGM campus in Koblenz helps our employees to organize their working day even more flexibly. We also offer corporate benefits, the option of a job bike, a company pension scheme, and much more.
Diversity is part of CGM! We look forward to receiving your application regardless of disability, gender, nationality, ethnic and social background, religion, age, sexual orientation, and identity.
Convinced? Apply online now with your detailed application documents (including salary expectations and earliest possible starting date).
Skills Required
- Several years of experience in product security, application security, or deputy CISO within a complex, multi-product software organisation.
- Demonstrable, current expertise in the EU Cyber Resilience Act (classification logic and conformity assessment) and working knowledge of NIS2 and GDPR.
- Strong practical knowledge of secure development lifecycle, threat modelling, and application security testing.
- Hands-on experience with SAST, DAST, SCA, SonarQube, and secrets scanning.
- Experience with SBOM generation and governance, managing supply chain risk, and understanding AI-assisted/agentic development workflows.
- Strong communication and stakeholder management skills to influence without direct line authority.
- CISSP or equivalent certification.
CompuGroup Medical US Compensation & Benefits Highlights
The following summarizes recurring compensation and benefits themes identified from responses generated by popular LLMs to common candidate questions about CompuGroup Medical US and has not been reviewed or approved by CompuGroup Medical US.
-
Leave & Time Off Breadth — Paid time off, sick leave, and company holidays are part of the package, and feedback suggests the time-off policies are viewed favorably by many.
-
Retirement Support — A 401(k) plan with company match is offered, which feedback suggests adds meaningful value to total rewards.
-
Flexible Benefits — Remote or flexible work options are available in some roles and are framed as part of the total package, which feedback suggests can improve perceived value even when base pay varies.
CompuGroup Medical US Insights
What We Do
CompuGroup Medical is a global e-health provider with a comprehensive portfolio of cutting-edge IT solutions for the healthcare industry. We connect doctors, hospitals, community health facilities, dentists, pharmacists, health insurers and other service providers to create an integrated network of all healthcare stakeholders. As a result, we can help these organizations improve efficiency, optimize care and increase patient satisfaction while also improving profitability. Our market-leading solutions include everything from electronic health records to innovative practice management systems. These solutions are present in over 400,000 practices and healthcare organizations worldwide. We are also proud to maintain and sustain long-term relationships with our clients, many of whom have been using our products for decades. Our dedicated, knowledgeable team consistently delivers innovative products and services with the customer in mind, knowing that in addition to running an effective business, their main focus is to heal the patient. We share that same passion and it drives everything we do. As an owner-led and publicly traded company, CGM uniquely combines the personal touch of a local business with the strength of a global entity. We are committed to meeting and exceeding our clients’ expectations, and our goal is to become the #1 choice for all healthcare providers in the United States – a position we have already achieved in many other countries around the world.
.png)






