JOBSEARCHER

Senior Product Security Engineer

Trident Consulting is seeking a " Senior Product Security Engineer " for one of our clients in " Burlington, MA" A global leader in business and technology services.Job Title: Senior Product Security EngineerLocation: Burlington, Massachusetts (Onsite)Type: Fulltime PositionJob SummaryThe Senior Product Security Engineer is a critical engineering role responsible for leading security initiatives across the entire product lifecycle. This position ensures products comply with regulatory standards and cybersecurity best practices, while providing hands-on expertise and cross-functional leadership across engineering, QA, DevOps, and compliance teams.Key Responsibilities1. Security Architecture & RequirementsDefine security requirements and risk mitigation strategies for products and featuresTranslate standards ( FDA, ISO 27001, NIST, OWASP ) into actionable requirementsDevelop and maintain security architecture designs and models2. Secure Development Lifecycle (SDLC)Embed secure development practices (threat modeling, secure coding, code reviews)Implement secure CI/CD practices (secrets management, dependency management, supply-chain security)Collaborate with DevOps/IT to secure cloud and deployment environments3. Testing & ValidationSupport penetration testing, fuzzing, and static/dynamic analysisManage vulnerability processes including SBOM creation and trackingIntegrate automated security testing into QA and release pipelines4. Documentation & CompliancePrepare pre-market cybersecurity documentation for regulatory submissionsMaintain records of risk assessments, vulnerabilities, and remediationEnsure audit-ready documentation and compliance traceability5. Vulnerability & Incident ManagementLead vulnerability assessment and mitigation activities (pre/post-market)Coordinate incident response, remediation, and regulatory reportingMonitor third-party component vulnerabilities6. Cross-Functional LeadershipAct as a Security Subject Matter Expert (SME)Mentor engineering teams on secure design and coding practicesAlign security strategy with compliance, regulatory, and quality teamsRequired Qualifications7–10 years of experience in software engineering, cybersecurity, or related fields3–5 years in product/embedded system security (regulated industries preferred)Experience in:Security architecture design for embedded/connected systemsSecure Development Lifecycle (SDL) implementationVulnerability management and disclosure processesRegulatory documentation (FDA, ISO 14971, IEC 81001-5-1)Cross-functional collaboration (Engineering, QA, IT, Regulatory)Preferred QualificationsExperience as a Product Security Lead / Security POCExperience integrating security automation in CI/CD pipelinesExposure to external audits, penetration testing, third-party assessmentsCore Technical SkillsProduct SecuritySecure design principles: least privilege, defense-in-depth, zero trustRisk frameworks: NIST 800-53, NIST 800-30, ISO 27001, ISO 14971, IEC 81001-5-1Cryptography: TLS, encryption, key management, hashingAuthentication, authorization, identity & session managementSecure coding: OWASP, CERT, MISRA, CWE/SANS Top 25Supply chain security & SBOM (SPDX, CycloneDX)DevOps & InfrastructureCI/CD security, container security ( Docker, Podman )Security tools: SAST, DAST, SCA, fuzzing, pen-testing toolsCloud & infrastructure knowledge ( AWS / Linux )Incident response & vulnerability disclosureRegulatory & ComplianceFDA cybersecurity (premarket & postmarket)Patch/update management strategiesAudit-ready documentation & traceabilityEducationMinimum: Bachelor's in Computer Science, Engineering, Cybersecurity, or related fieldPreferred: Master's in Cybersecurity, Software Engineering, or Systems Engineering