Integrate cybersecurity requirements into the design and development of software for diagnostic platforms, ensuring secure-by-design implementation.
Ensure compliance with FDA cybersecurity guidance and applicable North American regulations throughout the product lifecycle.
Collaborate with cross-functional teams including R&D, Quality, and Regulatory to translate cybersecurity and regulatory requirements into technical specifications.
Own cybersecurity compliance for connected hardware products, including threat modeling and security validation.
Translate security findings into technical documentation and risk assessments for regulatory frameworks like RED and CRA.
Collaborate with engineering teams to embed security early in the development lifecycle.
Nabu Casa develops the Home Assistant open-source smart home platform, focused on privacy and local control. The company is a distributed team with a culture of autonomy, ownership, and sustainability.
Design and implement enterprise security architecture and cyber security protection initiatives.
Install, upgrade, and maintain security hardware and software systems to ensure data integrity.
Serve as Tier-3 escalation support and collaborate on vulnerability remediation plans.
We are shaping the healthcare of the future by providing actively managed care that prevents disease and supports chronic conditions. We are the largest Independent Physician Association in Northern California and have been recognized as one of the Best Places to Work in the Bay Area.
Own cybersecurity compliance for connected hardware products, including RED, EN 18031, and CRA.
Perform threat modeling, security validation, and manage vulnerability risks across firmware, cloud, and devices.
Collaborate with engineering teams to integrate security early and translate technical findings into compliance evidence.
Nabu Casa builds cloud services and hardware for the open-source Home Assistant smart home platform. It is a profitable, fully remote company with no external investors, funded by users, and supports several open-source projects.
Participate in assessing client environments against frameworks like NIST CSF 2.0, CIS Controls, and ISO 27001.
Design and implement secure solutions across cybersecurity, networking, and cloud technologies.
Perform configuration, installation, and maintenance of security products and services.
Apollo Information Systems is a cybersecurity services company delivering unified security and compliance programs through a subscription-based platform. Backed by Series A funding, the company is growing rapidly with a collaborative, mission-driven culture and a remote-first team with a hub in Denver.
Draft and prosecute patent applications for software and electromechanical inventions.
Collaborate with partners and clients to develop IP strategies and manage portfolios.
Ensure compliance with USPTO rules and maintain strong attention to detail.
Vanguard Intellectual Partners specializes in the placement of IP/Patent professionals nationwide. With over 10 years of IP recruiting experience, our team offers trusted career advice and has a broad network of client relationships.
Lead a high-performing software engineering organization spanning bioinformatics, data platforms, and production systems to drive clinical genomic diagnostics.
Oversee architecture, development, and operational support of production-grade software platforms and bioinformatics workflows.
Drive modernization initiatives including legacy systems, workflow automation, cloud computing, and scalable software architectures.
The company develops software platforms for clinical genomic diagnostics. It fosters an inclusive workplace committed to equal employment opportunity and diversity.
Lead global information security strategy across manufacturing, product, and application security, ensuring resilience and regulatory readiness.
Oversee OT/ICS security, product security for FDA-regulated medical devices, and application security with DevSecOps practices.
Build and lead a global team, partner with senior executives, and establish risk management frameworks and metrics.
They are a global industrial and healthcare technology company operating in over 50 countries, manufacturing connected products and medical devices. They are a large, decentralized organization with a collaborative culture and a focus on security and innovation.
Lead complex projects with multiple stakeholders and engineers to design systems that adapt Vanta's compliance platform for government needs.
Build net-new product capabilities for government compliance, working with early design partners to validate and iterate.
Partner with engineering teams on shared infrastructure and drive technical initiatives across product and go-to-market.
Vanta helps businesses earn and prove trust by automating security monitoring for compliance standards like SOC 2, HIPAA, and ISO 27001. The company has a kind and talented team, with many having succeeded without prior security experience, and is growing rapidly.
Support DoD cybersecurity requirements by integrating security controls, automation, and compliance into DevSecOps pipelines, tooling, and configurations.
Design, implement, and maintain automated security controls for CI/CD pipelines, including SAST, DAST, SCA, container scanning, and vulnerability management.
Collaborate with engineering teams to ensure secure software supply chain practices, including SBOMs, artifact signing, and automated compliance evidence collection.
Raft is a customer-obsessed non-traditional defense tech company dedicated to empowering U.S. military and government agencies with cutting-edge AI/ML and data solutions. We are a hyper-collaborative team that values innovation, diversity, and a culture of Ubuntu, where each member adds unique value.
Review CMC sections of regulatory submissions for drug-device combination products, ensuring accuracy and alignment with global requirements.
Contribute to global regulatory CMC strategies and provide guidance to cross-functional stakeholders.
Collaborate with device development, quality, clinical, human factors, and other teams to support product compliance and change controls.
The company specializes in drug-device combination products and operates in a cross-functional, science-driven environment. The culture emphasizes collaboration across regulatory, device development, quality, clinical, and human factors teams.
Provide consistent and qualified responses to tenders and assurance questionnaires from customers.
Produce and maintain security assurance documentation required for accreditation.
Schedule security testing, create remediation plans, and drive remediation of vulnerabilities.
NEC Software Solutions, part of global tech giant NEC Corporation, develops software that powers emergency services, public transport, healthcare, and government operations. With over 3,000 employees, we foster a collaborative culture focused on pushing boundaries and supporting public services.
Independently execute endpoint security, identity management, and vulnerability remediation across Windows, macOS, Linux, and cloud platforms.
Monitor and analyze alerts within SIEM and EDR, conduct initial investigations, and escalate complex findings as needed.
Partner with IT, Engineering, DevOps, and IAM teams to maintain security controls and support compliance frameworks like SOC 2, HIPAA, and ISO 27001.
Accela is an industry leader in designing and delivering government software to improve efficiency, increase citizen engagement, and enable the development of thriving communities. The company has been operating for nearly 20 years, fosters a diverse and inclusive culture, and is committed to equity and belonging.
Lead technical roadmap for FedRAMP Continuous Monitoring, transitioning manual reporting to automated telemetry and validation.
Design compliance-as-code frameworks and automated evidence generation to reduce manual effort during assessments and audits.
Partner with cross-functional teams to define compliance verification requirements and mentor on FedRAMP practices.
Our partner is a technology company specializing in security and compliance for public sector cloud environments. They foster a collaborative, fast-moving culture with significant autonomy and cross-functional exposure.
Provide regulatory affairs support for FDA medical device compliance, including pre-market submissions (510(k), PMA), post-market surveillance, and quality system audits.
Collaborate cross-functionally with R&D, Quality Assurance, and Sales to ensure compliance with U.S. FDA and international regulations (ISO 13485, MDSAP, EU MDR).
Perform regulatory documentation and submissions for new products and changes, and handle customer complaints, field actions, and risk assessments.
FUJIFILM Healthcare Americas Corporation provides cutting-edge healthcare solutions spanning diagnostic imaging, enterprise imaging, endoscopic and surgical imaging, and in-vitro diagnostics. The company is part of Fujifilm, which has over 70,000 employees globally and fosters a dynamic, flexible environment focused on innovation and collaboration.
Monitor, investigate, and respond to cybersecurity alerts, incidents, vulnerabilities, and threats across enterprise, endpoint, cloud, network, and application environments.
Support compliance with NIST SP 800-171, CMMC, and applicable federal/DoD cybersecurity requirements, including protection of CUI and FCI.
Conduct cybersecurity risk assessments, vulnerability assessments, and security reviews; prioritize findings and coordinate remediation efforts.
Tlingit Haida Tribal Business Corporation (THTBC) delivers mission-critical services to federal clients globally, including logistics, IT, cybersecurity, and facilities operations. For over 35 years, the company has been committed to generating economic opportunity for the Tlingit & Haida Tribes of Alaska, fostering a purpose-driven culture.
Develop and implement cybersecurity strategies and architectures aligned with organizational objectives and regulatory requirements.
Lead RMF activities for large distributed systems to obtain and maintain Authority to Operate.
Collaborate with government stakeholders and cross-functional teams to integrate security across systems and networks.
The company specializes in cybersecurity architecture and Zero Trust solutions for U.S. Department of Defense clients. It offers a fully remote work environment with a focus on work-life balance and professional development opportunities.
Serve as Global Process Owner for CAPA subsystem, ensuring compliance with FDA, ISO, and EU MDR requirements.
Lead complex investigations using root cause analysis tools and mentor cross-functional teams on best practices.
Monitor CAPA performance through KPIs, facilitate CAPA Review Board, and drive systemic improvements.
Heartflow is a medical technology company advancing the diagnosis and management of coronary artery disease using AI-driven, non-invasive cardiac tests. The company is publicly traded, has been used for over 500,000 patients worldwide, and is supported by international medical societies.
Lead QMS and regulatory remediation to align global procedures with FDA QMSR and ISO 13485.
Manage global regulatory submissions and interactions with Notified Bodies for EU MDR, UKCA, and other markets.
Serve as RA representative on core project teams for hardware and AI/software releases.
Eko Health develops AI-powered digital stethoscopes and ECG tools to help clinicians detect heart and lung disease. The company is venture-backed, recognized by TIME as a top healthtech company, and has a mission-driven team of engineers, physicians, and creatives.
Support day-to-day information security operations and maintain strong operational security posture across the platform.
Develop and maintain the System Security Plan and other cybersecurity documentation for security authorization and compliance.
Support FedRAMP High and DoD IL5 compliance activities including continuous monitoring, audits, assessments, and remediation.
The partner company operates a secure, mission-focused technology platform supporting government and commercial teams. It is an equal opportunity workplace committed to considering qualified candidates from all backgrounds.