יועץ/ת בכיר/ה אבטחת מידע (סייבר) – מכשור רפואי ותוכנה רגולטורית
פורסם אתמול · 0 מועמדים
- Risk assessment, threat modeling, and security controls implementation
- Secure software development lifecycle (Secure SDLC) and secure architecture review
- Validation & Verification (V&V) processes, security testing, and regulatory documentation/submissions
- Experience with regulatory standards and frameworks (e.g., ISO 13485, IEC 62304, IEC 62443, ISO 14971, NIST, FDA Guidelines, GDPR, HIPAA)
- Senior-level experience in cybersecurity / information security
- Advanced certifications in cybersecurity (e.g., CISSP, CISM, CEH)
- Experience working with critical systems or regulated environments
חולץ מתיאור המשרה · מתעדכן אוטומטית
תיאור המשרה המלא
המשרה המקורית · נשמר לעיוןRole Description The Senior Cyber Information Security Consultant – Medical Devices and Regulatory Software will lead cybersecurity and information security activities across medical device and regulatory software projects. This full-time, on-site role is based in Ramot Menashe and involves close collaboration with software developers, quality, and regulatory teams. Daily responsibilities include assessing and mitigating security risks, defining security requirements, reviewing architectures, and ensuring compliance with relevant standards and regulations. The role also includes developing and implementing security policies and procedures, supporting Validation & Verification processes with a focus on cybersecurity, and preparing documentation for regulatory submissions. The consultant will act as a subject matter expert for clients and internal teams, providing guidance on secure design, incident response readiness, and best practices in medical device cybersecurity.
Qualifications
• Candidates should possess strong expertise in cybersecurity and information security for medical devices and healthcare software, including risk assessment, threat modeling, and security controls implementation.
• Candidates should possess experience with regulatory frameworks and standards relevant to medical devices and healthcare IT (e.g., ISO 13485, IEC 62304, IEC 62443, ISO 14971, GDPR, HIPAA or similar data protection and privacy regulations).
• Candidates should possess skills in secure software development practices, secure architecture review, and collaboration with R&D teams to integrate security into the development lifecycle.
• Candidates should possess capabilities in Validation & Verification processes, including test planning, security testing, documentation, and support of regulatory submissions and audits.
• Candidates should possess strong analytical and problem-solving skills, with the ability to translate complex security and regulatory requirements into practical solutions for cross-functional teams.
• Candidates should possess excellent written and verbal communication skills in English, with the ability to produce clear technical and regulatory documentation and to present recommendations to stakeholders.
• Candidates should possess relevant academic background, such as a bachelor’s degree in Computer Science, Engineering, Information Security, or a related field; advanced certifications in cybersecurity (e.g., CISSP, CISM, CEH) are an advantage.
• Candidates should possess the ability to work on-site in Ramot Menashe
תחומי אחריות
• הובלת פעילויותCybersecurity Governance, Risk & Compliance (GRC) בהתמחות על תוכנה רפואית עבור חברות המפתחות מכשור רפואי
• ביצוע והובלת הערכות סיכוני סייבר למוצרים ולמערכות רפואיות
• הגדרת דרישות אבטחה ויישום בקרות אבטחה לאורך מחזור חיי הפיתוח (Secure SDLC)
• בניית Threat Models ניתוח איומים והגדרת מנגנוני הגנה
• ייעוץ וליווי צוותי פיתוח בהטמעת עקרונות פיתוח מאובטח
• השתתפות בפגישות סטטוס, אפיון והגדרת צרכים
• עבודה בהתאם לדרישות ותקנים רגולטוריים (FDA / MDR / IEC / ISO)
• תמיכה בהגשות רגולטוריות והכנת תיעוד סייבר
• תרגום דרישות רגולטוריות מורכבות לפתרונות מעשיים וברורים
• עבודה מול ממשקים מרובים ולקוחות בארץ ובחו"ל
דרישות התפקיד
• מהנדס תוכנה / מהנדס מערכות מידע
• ניסיון של שנים (Senior Level) בתחום אבטחת מידע / סייבר
• ניסיון בעבודה עם מערכות קריטיות או סביבות רגולטוריות – יתרון משמעותי
• הבנה מעמיקה של ניהול סיכונים ואבטחת מידע
• ניסיון בהטמעת Secure SDLC ומתודולוגיות פיתוח מאובטח
• היכרות עם רגולציות ותקנים רלוונטיים בתחום הרפואה בפרט ואבטחת מידע ככלל (NIST, FDA Guidelines, IEC 62304, ISO 14971, IEC 81001-5-1)
• יכולת הובלת תהליכים וייעוץ לגורמים טכנולוגיים ועסקיים
• יכולת ניתוח מערכתית וחשיבה אסטרטגית
• יחסי אנוש מצוינים ויכולת עבודה בצוותים Multi Discipline
• שליטה גבוהה באנגלית – חובה
שאלות על המשרה
- המשרה לא ציינה שכר. אנחנו מציגים שכר רק כשהמעסיק מפרסם אותו.
- Risk assessment, threat modeling, and security controls implementation, Secure software development lifecycle (Secure SDLC) and secure architecture review, Validation & Verification (V&V) processes, security testing, and regulatory documentation/submissions, Experience with regulatory standards and frameworks (e.g., ISO 13485, IEC 62304, IEC 62443, ISO 14971, NIST, FDA Guidelines, GDPR, HIPAA), Senior-level experience in cybersecurity / information security