At a Glance
- Tasks: Join us as a Product Security Specialist, ensuring the safety of IoT medical devices.
- Company: PA is a global leader in innovation, transforming complex challenges into opportunities.
- Benefits: Enjoy flexible working, 25 days annual leave, health perks, and a generous pension scheme.
- Why this job: Make a real impact in healthcare security while growing in a diverse and inclusive environment.
- Qualifications: 8+ years in IoT security, with strong communication skills and relevant cybersecurity accreditations.
- Other info: We encourage applications from all backgrounds and offer support for adjustments during recruitment.
The predicted salary is between 48000 - 72000 £ per year.
We believe in the power of ingenuity to build a positive human future. As strategies, technologies, and innovation collide, we create opportunity from complexity. Our teams of interdisciplinary experts combine innovative thinking and breakthrough technologies to progress further, faster. Our clients adapt and transform, and together we achieve enduring results.
We are seeking a Product Security Specialist with expertise in connected/IoT medical devices or healthcare products to join our team. The ideal candidate will be responsible for working with our clients to advise and shape the overall security strategy for products, ensure secure design, development, and deployment across the entire product lifecycle, and implement industry best practices to protect sensitive healthcare data.
Key Responsibilities:- Work with client product teams and functional groups on determining objectives, scope, and timelines for key product security initiatives and architecting the delivery methodologies.
- Assess security risks across client product portfolios and recommend remediation strategies while balancing business and technical requirements.
- Advise on strategies around coding, threat modeling, and security testing for embedded systems, IoT devices while ensuring compliance with industry regulations.
- Work alongside client R&D teams to lead on secure code reviews, threat modeling, security risk assessments, vulnerability assessments and validation and verification of controls.
- Monitor emerging cybersecurity threats in the IoT and medical device landscape and write thought leadership to showcase PA’s point of view on these.
- Build strong stakeholder relationships across our clients.
- Foster team growth, training and deliver outcomes.
- Support and drive business development efforts.
- Manage projects with expertise.
- Solve problems with a consulting approach.
Qualifications:
- 8+ years of experience in IoT security, preferably in the medical device or the pharmaceutical industry.
- Proficiency in security frameworks (e.g., NIST, OWASP, MITRE ATT&CK, PASTA, STRIDE) and standards such as FDA cybersecurity guidance.
- Experience assessing security risks using industry standard methods (penetration test results, threat modeling, security testing) and determining residual risk after applying compensating security controls.
- Experience implementing and demonstrating compliance to security frameworks such as NIST, IEC, HITRUST, HIPAA, GDPR, ISO 27001, SOC 2 Type 2 and familiarity working with Quality Management Systems.
- Experience working with teams in a structured software development lifecycle process.
- Excellent interpersonal skills, both written and verbal, with the ability to clearly convey complex security topics to a wide audience - technical and non-technical teams.
- Proven track record of achieving outcomes and nurturing relationships.
- Skilled in crafting compelling proposals and other business development materials.
- Proficient in cultivating opportunities within the client base and network.
- Holds Cyber Security accreditations/qualifications such as (CISSP, CSSLP, CISM), indicating a solid foundation in the field.
We know the skill-gap and ‘somewhat need to tick every box’ can get in the way of meeting brilliant candidates, so please don’t hesitate to apply – we’d love to hear from you.
Additional Information: Life At PA encompasses our peoples' experience at PA. It's about how we enrich peoples’ working lives by giving them access to unique people and growth opportunities and purpose led meaningful work. Our purpose guides how we work with our clients and our teams, and support our communities, to deliver insight and impact, solving the world’s most complex challenges. We're focused on building a workplace that values human difference and diverse mindsets, and a culture of inclusion and equality that unlocks the potential in our people so everyone can be their best self.
We are dedicated to supporting the physical, emotional, social and financial well-being of our people. Check out some of our extensive benefits:
- Health and lifestyle perks accompanying private healthcare for you and your family.
- 25 days annual leave (plus a bonus half day on Christmas Eve) with the opportunity to buy 5 additional days.
- Generous company pension scheme.
- Opportunity to get involved with community and charity-based initiatives.
- Annual performance-based bonus.
- PA share ownership.
- Tax efficient benefits (cycle to work, give as you earn).
We’re committed to advancing equality. We recruit, retain, reward and develop our people based solely on their abilities and contributions and without reference to their age, background, disability, genetic information, parental or family status, religion or belief, race, ethnicity, nationality, sex, sexual orientation, gender identity (or expression), political belief veteran status, or other by any other range of human difference brought about by identity and experience. We welcome applications from underrepresented groups.
Adjustments or accommodations - Should you need any adjustments or accommodations to the recruitment process, at either application or interview, please contact us.
Product Security Specialist employer: PA Consulting
Contact Detail:
PA Consulting Recruiting Team
StudySmarter Expert Advice 🤫
We think this is how you could land Product Security Specialist
✨Tip Number 1
Familiarise yourself with the latest trends and challenges in IoT security, especially in the medical device sector. This knowledge will not only help you during interviews but also demonstrate your genuine interest in the role.
✨Tip Number 2
Network with professionals in the field by attending industry conferences or webinars focused on cybersecurity and IoT. Building connections can provide valuable insights and potentially lead to referrals.
✨Tip Number 3
Prepare to discuss specific security frameworks and standards relevant to the role, such as NIST and OWASP. Being able to articulate your experience with these frameworks will set you apart from other candidates.
✨Tip Number 4
Showcase your problem-solving skills by preparing examples of past projects where you successfully managed security risks. Highlighting your consulting approach will resonate well with the expectations of the role.
We think you need these skills to ace Product Security Specialist
Some tips for your application 🫡
Tailor Your CV: Make sure your CV highlights relevant experience in IoT security and medical devices. Use specific examples that demonstrate your expertise in security frameworks and compliance with industry regulations.
Craft a Compelling Cover Letter: In your cover letter, express your passion for product security and how your background aligns with the company's mission. Mention your experience with security risk assessments and your ability to communicate complex topics clearly.
Showcase Relevant Qualifications: List any cybersecurity accreditations you hold, such as CISSP or CISM, prominently in your application. This will help establish your credibility and expertise in the field.
Highlight Interpersonal Skills: Since the role requires building strong stakeholder relationships, emphasise your interpersonal skills in both your CV and cover letter. Provide examples of how you've successfully collaborated with technical and non-technical teams in the past.
How to prepare for a job interview at PA Consulting
✨Showcase Your Expertise in IoT Security
Make sure to highlight your experience with IoT security, especially in the medical device or pharmaceutical industry. Be prepared to discuss specific projects where you assessed security risks and implemented compliance with frameworks like NIST or OWASP.
✨Demonstrate Your Problem-Solving Skills
Prepare examples of how you've approached complex security challenges in previous roles. Use a consulting mindset to explain how you balanced business needs with technical requirements while ensuring product security.
✨Communicate Clearly with Diverse Audiences
Since the role involves conveying complex security topics to both technical and non-technical teams, practice explaining your past work in simple terms. This will show your ability to build strong stakeholder relationships.
✨Stay Updated on Cybersecurity Trends
Research current trends and emerging threats in the IoT and medical device landscape. Being able to discuss these topics during your interview will demonstrate your proactive approach and thought leadership in the field.