Sunrise Systems Inc logo

Sr Product Security Engineer

Sunrise Systems Inc

  • Irvine, CA
  • 1 day ago
  • Remote
  • $105–$115 Per Hour

Highlights

Depth in web/API security beyond OWASP Top 10: OWASP ASVS levels as requirement source, API Top 10, authorization logic flaws (IDOR, broken object-level and function-level authz), SSRF, deserialization, app security in multi-tenant context. Ability to perform manual secure code review and triage SAST findings for exploitability, tuning rules to drive false-positive rates down rather than escalating raw tool output.

Numbers & Facts

LocationIrvine, CA (
Remote
)
IndustryStaffing/Employment Agencies
Salary$105–$115 Per Hour
Company Size100 to 499 employees
Year Founded1990
Websitehttp://www.sunrisesys.com/

Description

Our client, a leading Medical Device Manufacturing Company is looking for Sr Product Security Engineer and This is for an initial duration of 12 MonthsContractRemote Role
 
Job Title: Sr Product Security Engineer
Job Id: 26-04148
Location: Remote Role
Duration: 12 Months Contract
Position Type: Hourly Contract Position (W2 only)

Technical Skills
Must Have 
  • API Documentation
  • Application Programming Interface (API) Security
  • Application Security Architecture
  • Application Security Testing
  • Artificial Intelligence (AI)
  • Cloud Security
  • Cyber Risks
  • Cybersecurity
  • Cyber Security Assessments
  • Cybersecurity Compliance
  • Cybersecurity Risk Management
  • Cyber Threat Analysis
  • Cyber Threat Modeling
  • Design Documentation
  • Documentation Compliance
  • Security Engineering
Applications preferred location in the Orange County / Irvine, CA area.

Job Description 
  • Temp to Perm possibility but that depends on experience
  • Sr Product Security Engineer to support Client's STS business unit and develop AI powers skills, agents, and services.
  • The Client portfolio includes FDA Class I and Class II medical devices and their associated cloud-connected platforms, on premise deployed software, and hosted applications.
  • The Sr Product Security Engineer owns, leads, and executes the activities and documentation outlined in Client's security lifecycle. These activities and documents include Security Requirements, Threat Modeling, Risk Assessments and Analysis, Vulnerability & Risk Management Plans, Security Testing, and White Papers.
  • In addition, the use and development of AI tools/capabilities require the candidate to have both strategic and tactical experience in building with AI.
  • This role focuses on risk-based security that ensures patient safety, data protection, and regulatory readiness.
Role Focus 
  • Execution of Product Security Engineering Lifecycle activities
  • Building AI based skills, agents, services, and platforms
  • Integration of AI driven capabilities into product development lifecycles
  • Generation and Maintenance of Product Security Documentation
  • Apply risk-proportionate security controls
  • Emphasize secure-by-design and secure-by-default
  • Balance usability, workflow, and security
Key Responsibilities 
  • Security Engineering, Architecture & Design
  • Define end-to-end security engineering/design/solutions/controls across devices, apps, and cloud
  • Establish baseline security patterns (auth, encryption, secure updates)
  • Conduct Threat Modeling, Risk Assessments, Requirements/Controls Mapping, Security White Papers
  • Lead and Drive Security Design Reviews & Roadmap Remediations/Mitigations
  • Perform architecture risk analysis on device/cloud boundaries: trust boundary decomposition, data flow diagrams, attack surface enumeration, and abuse/misuse case development
  • Develop AI skills, agents, services
Secure SDLC 
  • Implement lean Secure SDLC aligned to NIST, OWASP, and BSIMM
  • Integrate SAST, SCA, secrets scanning, container/IaC scanning
  • Define minimum viable security gates
Regulatory & Compliance 
  • Support FDA cybersecurity documentation (threat models, SBOMs, risk assessments)
  • Align with IEC 62304, ISO 14971
  • Ensure audit-ready documentation
Cloud Security 
  • Design secure integrations with Client's Cloud Platforms
  • Secure device-to-cloud data flows
SBOM & Vulnerability Management 
  • Establish SBOM processes (SPDX, CycloneDX)
  • Implement continuous vulnerability monitoring
  • Define risk-based remediation SLAs
Cross-Functional Leadership 
  • Collaborate with engineering, quality, regulatory, and product teams
  • Translate security into patient safety and business risk
  • Mentor teams
Required Qualifications 
  • 5+ years cybersecurity experience
  • Software Development, System Engineering background
  • AI (Agentic, Generative, ML) skills and agent development
  • Regulatory/Quality Control product development
  • Demonstrated working experience in the domains of embedded, cloud, and application security
Preferred Qualifications 
  • Experience with FDA Class I/II devices and FDA submissions
  • Experience with IoMT ecosystems
  • Knowledge of FDA Cybersecurity Pre & Post Market Guidance, UL 2900, AAMI TIR57/TIR97
  • DevSecOps experience
  • Certifications (CISSP, CCSP, CSSLP)
Key Competencies 
  • Ability to right-size security controls
  • Strong risk-based decision-making
  • Communication across technical and non-technical teams
  • Ability to perform manual secure code review and triage SAST findings for exploitability, tuning rules to drive false-positive rates down rather than escalating raw tool output
  • Produce and consume VEX (CSAF, OpenVEX) alongside SBOMs; maintain component provenance and transitive dependency accuracy
  • Depth in web/API security beyond OWASP Top 10: OWASP ASVS levels as requirement source, API Top 10, authorization logic flaws (IDOR, broken object-level and function-level authz), SSRF, deserialization, app security in multi-tenant context
  • Design and review authentication/authorization implementations: OAuth 2.0/OIDC flow selection and misuse, token lifetime and revocation, session management, SAML assertion validation
  • Demonstrated ability to read and write production code in at least one systems language
Success Metrics 
  • Comprehensive Threat Modeling and effective Security Risk Management
  • SBOM completeness
  • Reduction in critical vulnerabilities
  • FDA submission success
  • Time-to-remediate vulnerabilities
Compensation: The hourly rate for this position is between $105.00-$115.00 per hour.

Factors which may affect starting pay within this range may include [geography/market, skills, education, experience and other qualifications of the successful candidate].

Benefits: Sunrise offers ACA compliant medical coverage/dental insurance/vision insurance to all employees. We also offer Sick time benefits as required per State regulations.

Qualified candidates please send your word format updated resume at the earliest to Pavan:

Pavan.p@sunrisesys.com

[732-395-4444].
 
Thank You.

About Company

Sunrise Systems was founded in 1990 with a clear vision to deliver world-class staffing service solutions in all labor categories, including IT consulting and solutions; all with the commitment to provide service that exceeds expectations and become the most trusted name in the industry. More than two and a half decades later, we pride ourselves on being at the forefront of the staffing industry. Combining our deep industry expertise, insights, and global resources, we have partnered with our clients to connect them with top professionals across several different industries.

We provide cost-effective Managed Staffing Solutions, Information Technology and Information Technology Consulting Services to several Fortune 500 companies and U.S. Government agencies. We provide our clients with flexible engagement models and customized products that are budget and time specific. Understanding the challenges that every business faces, we offer our services either on-site at the clients' site or from one of our globally distributed technology centers. Our onshore and offshore development capabilities ensure that we excel at meeting customer requirements every single time.

Our collective business experience spans over two and a half decades and ranges from:

  • Business, management, and technical fields
  • Information technology consulting and software solutions.
  • Providing strategic support for the development and long-term growth of new business ventures across several industries including but not limited to; accounting, banking, finance, and recruitment.
  • Motivating technology staff and establishing partnerships with Fortune 500 companies

Sunrise Systems has a vast range of competence in:

  • Design, development, and support of cloud-based solutions from simple to highly complexed
  • Database administration of multi-platform applications, complex databases, and web-based environments that include all aspects of installation, planning, maintenance, and monitoring.
  • Data processing and data migration
  • Application re-engineering and platform migration
  • Working with the Information Systems and end-user communities at all levels to resolve issues and establish consensus.

Similar Jobs

See more jobs