Senior Quality Engineer, Cybersecurity

Posted 8 Days Ago
Be an Early Applicant
3 Locations
In-Office
113K-170K Annually
Senior level
Healthtech
We are an Alphabet company bringing the promise of precision health to everyone, every day.
The Role
Lead integration of cybersecurity into the Software QMS and SDLC for consumer, research, and SaMD products. Guide creation/maintenance of design files, risk management, verification/validation, post-market surveillance, CAPA and audit responses, and cross-functional cybersecurity initiatives to meet FDA and international medical device standards.
Summary Generated by Built In
Who We Are

Verily Health is a data platform and technology company purpose-built to power AI-enabled precision health solutions that accelerate research and improve care for individuals and communities. Uniquely positioned at the intersection of technology, data science, and healthcare, Verily transforms multimodal health data into insights, models, and actions that make healthcare more personalized, predictive, and precise.

Description

The Senior Quality Engineer, Cybersecurity is a hands-on individual contributor and subject matter expert who bridges quality engineering and cybersecurity across Verily's consumer, research, and medical device (SaMD) product portfolio. This role champions quality and security throughout the software development lifecycle — partnering closely with engineering, security, and product teams to ensure that cybersecurity processes are embedded in the QMS, meet applicable regulatory requirements, and scale across Verily's evolving product domains. The role proactively identifies risk, drives cross-functional initiatives, and brings deep technical fluency in both quality engineering and cybersecurity to protect the integrity of Verily's systems, data, and regulated products.

Responsibilities
  • Leads ongoing implementation and continuous improvement of the Software Quality Management System (QMS) across consumer, research, and SaMD product domains — in conformance with FDA QMSR, ISO 13485:2016 design controls, and SDLC processes — integrating internal best practices and medical device industry standards. Serves as the Quality Lead for the cybersecurity process, partnering closely with the Security team to embed security requirements, threat modeling, vulnerability management, and secure coding practices into the SDLC and QMS in alignment with FDA cybersecurity guidance and AAMI TIR57.

  • Guides software development teams in the creation and maintenance of Design and Development Files (DDFs), including software development plans, verification and validation plans, software requirements specifications, architecture and design documents, design and code reviews, Risk Management Files (RMF), test protocols and reports, and traceability matrices. 

  • Supports integration of ISO 14971 risk management, IEC 62366 usability engineering, and FDA cybersecurity guidance into SDLC processes, ensuring a cohesive and compliant approach to product safety, security, and usability across the development lifecycle.

  • Supports post-market cybersecurity surveillance activities for SaMD and LLM-enabled products, including monitoring for emerging threats, coordinating vulnerability disclosures, and assessing the impact of security findings on regulated product safety and performance.

  • Provides CAPA, complaints, audit, and QMS support related to software and cybersecurity incidents, driving root cause analysis and effective corrective actions across product teams.

Qualifications

Minimum Qualifications

  • Bachelor's degree in Computer Science, Software Engineering, Informatics, Biomedical Engineering, or a related technical field; or equivalent practical experience with 5+ years in software quality engineering within the FDA QMSR / ISO 13485 medical device industry, with primary focus on Software as a Medical Device (SaMD).

  • Proven expertise in medical device cybersecurity, including working knowledge of FDA premarket and postmarket cybersecurity guidance and applicable standards (e.g., AAMI TIR57).

  • Demonstrated experience applying IEC 62304 (Medical Device Software Lifecycle Processes), ISO 14971 (Risk Management), IEC 62366 (Usability Engineering), and AAMI TIR57 within a regulated software development environment.

  • Experience collaborating directly with software development and security teams, with proficiency in Google Workspace, Jira, GitHub, and document control systems to operationalize quality and cybersecurity requirements within engineering workflows.

Preferred Qualifications

  • Experience with AI/ML-enabled medical device products, including familiarity with FDA AI/ML SaMD guidance, predetermined change control plans (PCCP), and post-market performance monitoring for generative AI applications; experience using generative AI tools (e.g., Gemini, Claude, ChatGPT) to enhance quality and compliance workflows is a plus.

  • Experience with digital health, Health IT, mobile medical applications, or consumer health products, with working knowledge of scalable QMS and SDLC approaches across wellness, low-risk, and high-risk software classifications.

  • Demonstrated ability to implement and continuously improve Software QMS and secure SDLC processes using agile/scrum methodologies, best-practice tooling, and iterative development frameworks in a fast-paced, innovative environment.

  • Relevant cybersecurity certification (e.g., AAMI Cybersecurity Certificate, CISSP, or equivalent) and/or quality certification (e.g., ASQ CQE); or advanced degree in a related technical or biomedical field.

  • Excellent cross-functional communication, organizational, and leadership skills, with a proven ability to drive quality and cybersecurity initiatives with minimal supervision across engineering, security, and product teams.

Qualified applicants must not require employer sponsored work authorization now or in the future for employment in the United States.

The US base salary range for this full-time position is $113,000 - $170,000 + bonus  + equity + benefits. Our salary ranges are determined by role, level, and location. The range displayed on each job posting reflects the minimum and maximum target for new hire salaries for the position across all US locations. Within the range, individual pay is determined by work location and additional factors, including job-related skills, experience, and relevant education or training. Your recruiter can share more about the specific salary range for your preferred location during the hiring process.

Please note that the compensation details listed in US role postings reflect the base salary only, and do not include bonus, equity, or benefits.

Verily Health Inc. is an equal opportunity employer. Qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability or protected veteran status. For our EEO Policy Statement, please click here. If you'd like more information on your EEO rights under the law, please click here.

If you have a need that requires accommodation, please let us know by completing our Accommodations for Applicants form.

Skills Required

  • Bachelor's degree in Computer Science, Software Engineering, Informatics, Biomedical Engineering, or related field OR equivalent experience with 5+ years in software quality engineering within FDA QMSR / ISO 13485 medical device industry focused on SaMD
  • Proven expertise in medical device cybersecurity, including working knowledge of FDA premarket and postmarket cybersecurity guidance and applicable standards (e.g., AAMI TIR57)
  • Demonstrated experience applying IEC 62304, ISO 14971, IEC 62366, and AAMI TIR57 in a regulated software development environment
  • Experience collaborating with software development and security teams and proficiency in Google Workspace, Jira, GitHub, and document control systems
  • Ability to support post-market cybersecurity surveillance, vulnerability disclosures, and assess security impact on regulated product safety/performance
  • Must not require employer sponsored work authorization now or in the future for employment in the United States
  • Experience with AI/ML-enabled medical device products, FDA AI/ML SaMD guidance, PCCP, and generative AI tools (e.g., Gemini, Claude, ChatGPT)
  • Experience with digital health, Health IT, mobile medical applications, or consumer health products and scalable QMS/SDLC approaches
  • Demonstrated ability to implement and continuously improve Software QMS and secure SDLC using agile/scrum methodologies and best-practice tooling
  • Relevant cybersecurity certification (AAMI Cybersecurity Certificate, CISSP, or equivalent) and/or quality certification (ASQ CQE) or advanced degree
  • Excellent cross-functional communication, organizational, and leadership skills

Verily Compensation & Benefits Highlights

The following summarizes recurring compensation and benefits themes identified from responses generated by popular LLMs to common candidate questions about Verily and has not been reviewed or approved by Verily.

  • Retirement Support Feedback suggests the 401(k) program and employer match are notably competitive and valued. This support is seen as a standout element within the total rewards package.
  • Parental & Family Support Parental leave is characterized as generous versus common industry practice. This breadth of family support stands out within the overall benefits offering.
  • Healthcare Strength Health coverage is described as comprehensive across medical, dental, and vision, with HSA support referenced. These features contribute to a perception of robust healthcare benefits.

Verily Insights

Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
HQ: Dallas, Texas
1,418 Employees
Year Founded: 2015

What We Do

Verily is an Alphabet company combining a data-driven, people-first approach to bring the promise of precision health to everyone, every day. We are focused on generating and applying evidence from a wide variety of sources to change the way people manage their health and the way healthcare is delivered - shifting the paradigm from “one size fits all” medicine to one focused on a more comprehensive view of the individual that leads to a more personalized path forward. For more information, please visit verily.com.

Similar Jobs

Enverus Logo Enverus

Consultant

Big Data • Information Technology • Software • Analytics • Energy
In-Office
Austin, TX, USA
1800 Employees

Enverus Logo Enverus

Principal Software Engineer

Big Data • Information Technology • Software • Analytics • Energy
In-Office or Remote
2 Locations
1800 Employees

MetLife Logo MetLife

Group Life Claim Reviewer - 19452 - Oriskany NY - 9/1/26

Fintech • Information Technology • Insurance • Financial Services • Big Data Analytics
Remote or Hybrid
United States
43000 Employees
42K-54K Annually

MetLife Logo MetLife

Customer Service Associate - 19328

Fintech • Information Technology • Insurance • Financial Services • Big Data Analytics
Remote or Hybrid
United States
43000 Employees
42K-49K Annually

Similar Companies Hiring

Sailor Health Thumbnail
Healthtech • Social Impact • Telehealth
New York City, NY
20 Employees
Granted Thumbnail
Artificial Intelligence • Healthtech • Insurance • Mobile • Financial Services
New York, New York
23 Employees
OneImaging Thumbnail
Healthtech
Miami, FL
62 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account