| Location | Westborough, MA |
| Job Type | Contractor |
| Industry | Healthcare Services |
| Salary | $60–$70 Per Hour |
| Year Founded | 2001 |
| Headquarters | Atlanta, Georgia, US |
| Website | http://www.insightglobal.net |
Our Client is developing software-based products that will require security engineering. The Senior Product Security Engineer within the team will identify security related requirements, assist with threat models, help architect secure solutions, analyze software designs and implementations from a security perspective, and develop and maintain compliant documentation associated with product security. This role requires technical expertise, knowledge of safety critical systems, and the ability to work in a team environment to ensure security and resilience of our current and developing digital products.
Plan, test, and implement advanced software security controls and techniques in alignment with enterprise security architecture and secure design principles. • Conduct ongoing security testing, code reviews, and vulnerability assessments to strengthen the security posture of software applications and platforms. • Identify, assess, and mitigate AI-specific security risks, including prompt injection, adversarial machine learning attacks, model evasion, model extraction, training data poisoning, inference attacks, and unauthorized model manipulation. • Perform security architecture reviews and threat modeling activities for software, cloud-based solutions, connected devices, and AI/ML-enabled products. • Design and implement security solutions to address vulnerabilities and reduce product and application risk. • Develop, maintain, and contribute to product threat models, security risk assessments, and cybersecurity risk management activities throughout the product development lifecycle. • Serve as a Product Security and AI Security subject matter expert, guiding development teams on secure design, secure coding practices, and emerging security threats. • Promote security awareness across engineering teams and help drive adoption of security best practices and compliance requirements. • Collaborate with cross-functional teams to define and execute security testing strategies, including static code analysis, dynamic testing, fuzz testing, penetration testing, compliance validation, and vulnerability management. • Design, develop, evaluate, and maintain AI-powered security tools, automations, and intelligent agents that enhance security processes such as threat modeling, risk assessments, security testing, compliance documentation, and secure design reviews. • Provide technical guidance and consultation on secure software development, application security, cloud security, and AI security practices. • Ensure compliance with applicable regulatory requirements, industry standards, cybersecurity frameworks, and internal security policies. • Support secure product development activities by integrating security requirements into design, development, testing, and release processes. • Monitor emerging threats, vulnerabilities, technologies, regulations, and industry best practices, and recommend improvements to security programs and controls. • Contribute to continuous improvement initiatives that enhance product security, cybersecurity resilience, and AI governance practices across the organization.
Experience with embedded technology and software security. • Experience in using Secure Software Development Lifecycle (SSDLC) within agile framework. • Expertise in threat modelling, security risk management, secure coding, secure system development, and DevSecOps • Knowledge of application security and code analysis tools such as Veracode, SonarQube, BlackDuck, Cyberspect, Nessus or similar. • Experience with security techniques, standards, and methods for authentication and authorization, applied cryptography, security vulnerabilities and remediation in Windows .NET and Azure environments. • Knowledge of government and industry standards, guidance’s and frameworks applicable to product software development such as NIST Cybersecurity Framework, OWASP, HIPAA, GDPR, SANS/CWE and/or CERT. • Solid technical background and understanding of all aspects of security research and development • Excellent analytical and troubleshooting skills. • Ability to work both independently and in a team environment. • Excellent communication skills, oral and written. • Able to work in a multi-discipline collaborative environment to include international colleagues and Olympus partners. • Bachelor's degree in Computer Science, information technology, cybersecurity, or related area required, or minimum of 5 years’ experience in a relevant industry.
Olympus is a global medical technology company focused on improving patient outcomes through innovative medical devices and solutions. Originally founded in Japan, Olympus is best known for its leadership in endoscopy, minimally invasive surgical technologies, and therapeutic medical devices used by healthcare providers worldwide.