Job Closed
This listing is no longer active.
Cybersecurity Engineer, DiGA – Contract
Location
New York
Posted
130 days ago
Salary
$125 - $135 / hour
Seniority
Senior
Job Description
Cybersecurity Engineer, DiGA – Contract
Click Therapeutics, Inc.
• Requirement Engineering: Translate German regulatory requirements (SGB V, DiGAV Annex 1) into actionable technical security specifications for the development team. • Penetration Testing Coordination: Define the scope for mandatory white-box penetration tests and manual code reviews; manage the relationship with BSI-certified testing centers. • Risk Assessment: Conduct and document data protection impact assessments (DPIA) and security risk assessments tailored to high-protection health data. • Vulnerability Management: Establish a lifecycle process for vulnerability handling and incident reporting as required by the EU Cyber Resilience Act (CRA) and DiGA guidelines.
Job Requirements
- DiGA Expertise: Proven experience in a successful DiGA submission process or deep familiarity with the BfArM Guide for Manufacturers.
- Regulatory Knowledge: Deep understanding of German and EU regulations, including GDPR, DiGAV, and the Digital Healthcare Modernisation Act (DVPMG).
- Technical Security: Strong background in OWASP Top 10 (Mobile/Web), secure API design, and cryptographic standards (AES-256, TLS 1.3).
- Certifications: Professional certifications such as CISSP, CISA, or ISO 27001 Lead Implementer are highly preferred.
- Fluency in English is required.
Benefits
- Your choice of mac or linux equipment.
Related Guides
Related Categories
Related Job Pages
More Security Engineer Jobs
Information Security Member
Anchorage DigitalTrusted institutional partner in crypto and first federally chartered crypto bank
• Help build and scale a forward-looking security program • Ensure security of data and client’s digital assets • Work on various information security projects • Identify and evaluate risk to the Information Security Program • Create and improve controls to manage operational risks • Contribute to the long-term strategy of Information Security Team
Security Architect
CrowdStrikeCrowdStrike has redefined security with the world’s most advanced cloud-native platform that protects and enables the people, processes and technologies that drive modern enterprise. Tested and proven, the world's largest organizations trust CrowdStrike to stop breaches with unparalleled protection against the most sophisticated cyberattacks. The CrowdStrike culture has been built upon our Core Values since the day we began. We are Fanatical About the Customer, Relentlessly Focused on Innovation and believe that our Limitless Passion drives Unlimited Potential for every CrowdStriker. As a purpose-built remote-first company, we believe cultivating a connected culture for every employee, no matter where they are in the world, is a key ingredient in building a high-performing, diverse team. We don’t have a mission statement. We’re on a mission—to stop breaches. Ready to join a mission that matters?
• Support the design and configuration of enterprise information systems in alignment with security standards and requirements • Review and improve the security posture • Review new and existing system security plans • Participate in architecture reviews • Create and refine threat models • Offer technical guidance to minimize security risks • Oversee the execution of cybersecurity initiatives • Collaborate with other teams and serve as a subject matter expert while adhering to best security practices
• Ensure the security and safety of all business information, both at rest and in transit. • Work with Policy and Compliance to build and maintain IT networks and systems that adhere to government/contractual requirements. • Partner with engineering and DevOps on secure architecture. • Partner with Compliance and Legal on regulatory requirements. • Manage Vulnerability review and work with IT operations to regularly perform internal and external scans and audits and fix any identified issues to ensure IT security. • Manage Infrastructure Security. • Enhance and maintain the current network per IT policy. • Analyze security breaches to determine root cause, then mitigate any discovered issues. • Participate in architecture reviews and provide security approvals. • Manage security incident policy and response plan execution. • Provide quarterly and security assessment reviews. • Conduct all 3rd party vendor security assessment. • Manage and maintain perimeter defense systems (firewalls, VPN tunnels, etc.). • Maintain and administer security awareness training curriculum for employees. • Lead certification efforts for SOC 2, SOX ITGC Audits. • Work cross-functionally within the company to fulfill security requirements.
Senior Program Manager, Security Engineering
Kong Inc.The cloud connectivity company. Powering connections to build a reliable digital world.
• Lead and manage Kong Cybersecurity Programs across OCISO • Establish, develop and track KPIs • Collaborate with engineering, product, and business stakeholders to define, prioritize, and deliver technical solutions. • Present complex technical challenges and resolutions to leadership and stakeholders. • Stay current on regulatory and industry standards (for example, ISO 27001, PCI-DSS, FedRAMP, NIST 800-53) to inform risk and control strategies. • Build strategies for issue and risk mitigation, contingency planning, and compliance adherence. • Demonstrate ownership and autonomy in managing programs and delivering high-quality results.




