Hologic logo
Hologic

Hologic is a leader in women's health innovation, empowering people to live healthier lives every day. Our engineering teams are the driving force behind our business, constantly challenging and innovating our processes.

Senior Product Security Engineer

Security EngineerSecurity EngineerFull TimeRemoteSeniorTeam 5,001-10,000

Location

United States

Posted

74 days ago

Salary

$106K - $171K / year

Seniority

Senior

Job Description

Senior Product Security Engineer

Hologic

Join Hologic's mission to drive a Secure by Design culture within our Breast & Skeletal Health division. As a Senior Product Security Engineer, you will play a pivotal role in ensuring the security and integrity of our innovative healthcare solutions. If you are passionate about cybersecurity and eager to work in a dynamic environment, we invite you to apply. This role may sit in Newark, DE, Santa Clara, CA, Marlborough, MA or can sit remotely. This is your chance to be part of something truly transformative and contribute to advancements in women's health. Key Responsibilities: - Champion Security: Drive a Secure by Design culture across product teams, ensuring adherence to security standards and best practices. - Policy Enhancement: Participate in the continuous improvement of our Secure by Design policies and procedures, aligning products with the latest security requirements and regulatory standards. - Documentation and Architecture: Support the creation and maintenance of security design documentation and architecture diagrams. - Security Assessments: Conduct and document ongoing security assessments, including Threat Modeling, for Hologic products and remote connectivity solutions, providing support to product teams as needed. - Risk Management: Perform Security Risk Management activities to address identified vulnerabilities and security design issues. - Design Discussions: Create and maintain security controls and requirements while actively participating in design discussions and activities. - Development Support: Assist in product development efforts, including Security Code Reviews, to ensure compliance with Secure by Design principles and the implementation of appropriate security controls. - Automation and DevSecOps: Support the automation of security testing and reporting, manage security tooling, and secure our cloud environments. - Monitoring and Incident Response: Oversee ongoing security monitoring of in-market products and connected health solutions, participating in incident response investigations as necessary. - Education and Training: Educate sales and service teams on securing our products, connected health solutions, and their operating environments. Ideal Candidate Profile: - Industry Awareness: Maintain vigilance on industry security threats, assess risks to Hologic products, and manage these risks according to established quality procedures. - Troubleshooting Expertise: Effectively diagnose and resolve issues associated with networked, computer-based products. - Travel Flexibility: Be available for travel to Hologic offices, training, and customer sites. - Autonomous Alignment: Work with some supervision while aligning with strategic intentions and corporate priorities. - Network Knowledge: Possess a strong understanding of network design concepts and a working knowledge of security analysis and protection tools. Qualifications: - Education: Master’s or Bachelor’s degree in Computer Science, Management Information Science, Engineering, or a related technical field. - Experience: 4+ years of relevant experience in: - Computer and network security - Cloud base platform experience - Computer networking administration - Microsoft Windows and Linux operating systems - Software application testing and maintenance - Cybersecurity Risk Assessment - Technical Skills: - Knowledge of the secure development lifecycle and experience in a development environment. - Expertise in application secure design and code reviews, with an understanding of Secure Coding standards and common vulnerabilities (e.g., OWASP Top 10, CWEs). - Proficiency in scripting and simple application development (e.g., PowerShell, Python, C#, C++). - Experience with industry-standard security tools (SAST, SCA, DAST, vulnerability scanning). - Expertise in Threat Modeling (STRIDE method preferred). - Penetration Testing experience (direct or supportive). - Experience securing development and cloud environments (Azure preferred) and the DevSecOps (CI/CD) pipeline. - Strong communication skills, both verbal and written. Preferred Qualifications: - Medical Systems Knowledge: Experience with medical information system administration and familiarity with medical device security standards and regulations (e.g., FDA Premarket Cybersecurity Guidance, IEC 81001-5-1, AAMI TIR57, AAMI SW96). - Regulated Industry Experience: Experience in software development and verification within a regulated industry. - Technical Support Experience: Experience providing technical support to field service teams and/or end-users. - Certifications: Security-related certifications (e.g., CISSP), OS (Windows, Linux), and networking (Cisco) certifications are strongly preferred. - DoD Certification: Experience obtaining and maintaining Department of Defense (DoD) Authority to Operate (ATO) certifications. So why join Hologic? We are committed to making Hologic the company where top talent comes to grow. For you to succeed, we want to enable you with the tools and knowledge required and so we provide comprehensive training when you join as well as continued development and training throughout your career. We offer a competitive salary and annual bonus scheme, one of our talent partners can discuss this in more detail with you. If you have the right skills and experience and want to join our team, apply today. We can’t wait to hear from you! The annualized base salary range for this role is $106,600 - $171,900 and is bonus eligible. Final compensation packages will ultimately depend on factors including relevant experience, skillset, knowledge, geography, education, business needs and market demand. Agency and Third-Party Recruiter Notice: Agencies that submit a resume to Hologic must have a current executed Hologic Agency Agreement executed by a member of the Human Resource Department. In addition Agencies may only submit candidates to positions for which they have been invited to do so by a Hologic Recruiter. All resumes must be sent to the Hologic Recruiter under these terms or they will not be considered. Hologic, Inc. is proud to be an Equal Opportunity Employer inclusive of disability and veterans. LI-#DS1 #remote #hybird

Job Requirements

  • Master’s or Bachelor’s degree in Computer Science, Management Information Science, Engineering, or a related technical field.
  • 4+ years of relevant experience in: Computer and network security
  • Cloud base platform experience
  • Computer networking administration
  • Microsoft Windows and Linux operating systems
  • Software application testing and maintenance
  • Cybersecurity Risk Assessment
  • Knowledge of the secure development lifecycle and experience in a development environment.
  • Expertise in application secure design and code reviews, with an understanding of Secure Coding standards and common vulnerabilities (e.g., OWASP Top 10, CWEs).
  • Proficiency in scripting and simple application development (e.g., PowerShell, Python, C#, C++).
  • Experience with industry-standard security tools (SAST, SCA, DAST, vulnerability scanning).
  • Expertise in Threat Modeling (STRIDE method preferred).
  • Penetration Testing experience (direct or supportive).
  • Experience securing development and cloud environments (Azure preferred) and the DevSecOps (CI/CD) pipeline.
  • Strong communication skills, both verbal and written.
  • Maintain vigilance on industry security threats, assess risks to Hologic products, and manage these risks according to established quality procedures.
  • Effectively diagnose and resolve issues associated with networked, computer-based products.
  • Be available for travel to Hologic offices, training, and customer sites.
  • Work with some supervision while aligning with strategic intentions and corporate priorities.
  • Possess a strong understanding of network design concepts and a working knowledge of security analysis and protection tools.
  • Preferred Qualifications
  • Experience with medical information system administration and familiarity with medical device security standards and regulations (e.g., FDA Premarket Cybersecurity Guidance, IEC 81001-5-1, AAMI TIR57, AAMI SW96).
  • Experience in software development and verification within a regulated industry.
  • Experience providing technical support to field service teams and/or end-users.
  • Security-related certifications (e.g., CISSP), OS (Windows, Linux), and networking (Cisco) certifications are strongly preferred.
  • Experience obtaining and maintaining Department of Defense (DoD) Authority to Operate (ATO) certifications.

Benefits

  • Comprehensive training upon joining and continued development throughout your career.
  • Competitive salary and annual bonus scheme.

Related Categories

Related Job Pages

More Security Engineer Jobs

Stefanini LATAM logo

Cybersecurity Specialist

Stefanini LATAM

Co-creating solutions for a better future

Full TimeRemoteTeam 10,001+Since 1987H1B No Sponsor

• Diseño de Soluciones de Seguridad: Analizar los requerimientos del negocio para diseñar arquitecturas, patrones y soluciones que mitiguen riesgos en los proyectos de transformación, asegurando la alineación con el gobierno corporativo. • Gestión y Aplicabilidad de Controles: Construir matrices de controles personalizadas según el contexto tecnológico (Nube, Aplicación, APIs, Microservicios). • Aseguramiento y Validación Técnica: Verificar la correcta implementación de los controles en todas las capas del software mediante la ejecución de escaneos de línea base y la validación de evidencias técnicas. • Gestión de Vulnerabilidades (Shift Left): Realizar el seguimiento, priorización y recomendaciones técnicas para el cierre de vulnerabilidades identificadas durante el ciclo de desarrollo de aplicaciones. • Socialización y Referencia Técnica: Actuar como referente frente a las células de transformación, detallando activos críticos, amenazas y riesgos asociados a la arquitectura. • Atención a Entes Reguladores y Auditoría: Coordinar la respuesta a requerimientos de auditorías internas/externas y evaluaciones de riesgo, especialmente para el ecosistema offshore. • Reporting y Escalabilidad: Elaborar informes sobre el estado de seguridad de las iniciativas y comunicar desviaciones de manera oportuna a las partes interesadas.

Colombia
Job Closed
Jobgether logo

Cloud Identity Security Sales Specialist

Jobgether

We use an AI-powered matching process to ensure your application is reviewed quickly, objectively, and fairly against the role's core requirements. Our system identifies the top-fitting candidates, and this shortlist is then shared directly with the hiring company. The final decision and next steps (interviews, assessments) are managed by their internal team. We appreciate your interest and wish you the best! Data Privacy Notice: By submitting your application, you acknowledge that Jobgether will process your personal data to evaluate your candidacy and share relevant information with the hiring employer. This processing is based on legitimate interest and pre-contractual measures under applicable data protection laws (including GDPR). You may exercise your rights (access, rectification, erasure, objection) at any time. #LI-CL1 We may use artificial intelligence (AI) tools to support parts of the hiring process, such as reviewing applications, analyzing resumes, or assessing responses. These tools assist our recruitment team but do not replace human judgment. Final hiring decisions are ultimately made by humans. If you would like more information about how your data is processed, please contact us.

Full TimeRemoteH1B No Sponsor

Role Description This role offers a strategic opportunity to drive revenue and expand commercial adoption of identity security solutions across a defined U.S. territory. You will act as both a direct sales owner and a specialist overlay, collaborating closely with account executives to identify, influence, and close opportunities where identity security solutions provide critical value. The position requires leading complex, multi-stakeholder engagements with C-level and senior security leaders, delivering consultative insights on privilege risk reduction, identity governance, and cloud security. You will leverage expertise to shape account strategies, create compelling ROI-driven proposals, and coordinate cross-functional resources to accelerate deals. This role combines high autonomy, strategic thinking, and impact in a fast-paced, performance-driven environment. Success here contributes directly to reducing organizational security risks while driving measurable business growth. - Own and execute a strategic territory plan focused on net-new commercial acquisition and revenue growth - Manage full-cycle sales engagements from prospecting through deal closure - Operate as an overlay specialist with aligned account executives to identify and advance opportunities for identity security solutions - Build and maintain strong internal partnerships to create joint account plans and pipeline acceleration strategies - Lead complex, multi-threaded sales engagements within commercial organizations, engaging C-level and senior security stakeholders - Deliver consultative discovery and present solutions that reduce privilege risk and improve cloud security posture - Coordinate cross-functional resources (Sales Engineering, Marketing, Professional Services, Customer Success) to drive successful outcomes - Develop compelling business cases and ROI-driven proposals aligned with customer security initiatives - Maintain disciplined pipeline management and forecasting using Salesforce Qualifications - 5+ years of experience selling commercial SaaS, cybersecurity, or cloud security solutions - Proven success closing complex deals in competitive environments - Experience in both direct quota-carrying and overlay/specialist sales models - Ability to influence peer sellers and drive alignment across matrixed sales teams - Expertise engaging C-level security stakeholders (CISO, CIO, VP Security, Cloud Security leaders) - Strong understanding of Identity & Access Management (IAM), Privileged Access Management (PAM), Cloud Security, Endpoint Security, or related domains - Skilled in consultative selling, executive alignment, value-based positioning, and account-based sales strategies - Proficiency with Salesforce and disciplined pipeline and territory management - Exceptional communication, negotiation, and stakeholder management skills - High integrity, resilience, and comfort operating in a performance-driven environment Benefits - Competitive salary and performance-based incentives - Comprehensive healthcare coverage (medical, dental, vision) - Flexible remote work options within the United States - Generous paid time off and holiday benefits - Professional development opportunities and continuous learning - Access to wellness resources and employee support programs - Collaborative, inclusive work environment valuing diverse perspectives - Opportunities to engage with cutting-edge cloud identity security technologies

United States
Job Closed
Partner One Capital logo

Senior Security Engineer

Partner One Capital

At NetWitness, we believe in challenging the established mindsets, approaches, and product categories in the information security industry. Every product that we deliver to market is based on a core set of principles grounded in the major paradigm shifts in play and the implications that they have for our customers. Do the right thing – by our customers, employees, and shareholders...think long-term, but act with a sense of urgency. What we do matters – our work makes a difference in the world. We give a damn – about our customers, about what we’re doing, about each other...we’re in this together. We are a fun company – building cool products with technical insight that help our customers solve meaningful problems. Our mission is delighting our customers with everything we do. We provide thousands of customers around the world with essential security capabilities, leading with our Intelligence Driven Security Strategy and Vision, to protect their most valuable assets from cyber threats. With NetWitness’s award-winning products, organizations effectively detect, investigate, and respond to advanced attacks; reduce IP theft and cybercrime.

Role Description Partner One is looking for a Due Diligence Analyst to join the team. This is a full-time, permanent role. The Due Diligence Analyst will be a part of the Mergers and Acquisition team and will be responsible for supporting activities related to due diligence and execution of acquisitions. We are seeking a high-impact Senior Security Engineer to design and lead the strategic security architecture across our diverse technical landscape. In this role, you aren't just responding to threats—you are building the systems that prevent them. You will be responsible for: - Implementing sophisticated security tooling - Creating centralized dashboards - Ensuring a unified, compliant security posture across multiple, distinct environments This is a "builder" role designed for someone who enjoys the challenge of creating order out of complexity and maintaining world-class standards in a fast-paced, high-growth setting. Qualifications - 5+ years in security engineering - Proven track record of implementing security tools in complex, multi-tenant, or fragmented environments - Deep familiarity with SOC2 (Trust Services Criteria) and ISO 27001 frameworks - Hands-on experience with modern security stacks (e.g., Splunk, Elastic, Sentinel, or similar) - Strong proficiency in Cloud Security (AWS/Azure/GCP), Containerization (Docker/K8s), and Infrastructure as Code (Terraform/Ansible) - The ability to mentor junior analysts and explain the "why" behind compliance and security strategy to stakeholders Requirements - Evaluate, deploy, and manage enterprise-grade security tools (SIEM, SOAR, EDR) - Design comprehensive dashboards to provide real-time risk visibility across all environments - Act as the technical lead for SOC2 and ISO 27001 alignment - Ensure that security controls are technically enforced and auditable across various platforms - Build automated workflows to streamline incident response and evidence collection for compliance audits - Serve as a subject matter expert for network design and cloud migrations - Develop and maintain standardized security baselines (access control, encryption, logging) Benefits - Autonomy to shape our security roadmap - Opportunity to solve problems across a wide variety of industries and tech stacks simultaneously - Chance to build a world-class, audit-ready security program from the ground up

Romania
Jobgether logo

Senior Security Engineer

Jobgether

We use an AI-powered matching process to ensure your application is reviewed quickly, objectively, and fairly against the role's core requirements. Our system identifies the top-fitting candidates, and this shortlist is then shared directly with the hiring company. The final decision and next steps (interviews, assessments) are managed by their internal team. We appreciate your interest and wish you the best! Data Privacy Notice: By submitting your application, you acknowledge that Jobgether will process your personal data to evaluate your candidacy and share relevant information with the hiring employer. This processing is based on legitimate interest and pre-contractual measures under applicable data protection laws (including GDPR). You may exercise your rights (access, rectification, erasure, objection) at any time. #LI-CL1 We may use artificial intelligence (AI) tools to support parts of the hiring process, such as reviewing applications, analyzing resumes, or assessing responses. These tools assist our recruitment team but do not replace human judgment. Final hiring decisions are ultimately made by humans. If you would like more information about how your data is processed, please contact us.

Full TimeRemoteH1B No Sponsor

Role Description This role offers the chance to shape and protect the security posture of a fast-moving, technology-driven organization. You will lead initiatives to secure software, infrastructure, and systems while collaborating closely with engineering, product, and IT teams. Your work will directly influence how teams build and deploy software safely, ensuring both compliance and resilience against emerging threats. This position balances hands-on technical work with strategic planning, including threat detection, vulnerability management, and automation of security processes. You will help cultivate a culture of security-minded developers while contributing to the design and implementation of scalable security solutions. The role is fully remote but includes opportunities for collaboration through in-person gatherings and cross-functional projects. - Establish secure software development standards and integrate security best practices into the engineering workflow - Build frictionless processes for teams to safely develop, deploy, and maintain software - Conduct security assessments of systems, applications, and services to identify risks and ensure compliance - Triage threats and vulnerabilities, driving timely remediation and resolution - Collaborate with stakeholders to promote a culture of security-conscious engineering - Assess third-party vendors to verify their security posture and compliance - Develop automation and tooling to detect, prevent, and mitigate active security threats - Document and conduct post-incident reviews, implementing lessons learned to enhance defenses Qualifications - 5+ years of experience in security engineering, software engineering, or related fields - Proficiency in multiple programming languages such as Go, Python, Clojure, or JavaScript - Strong understanding of application and cloud security best practices - Experience scaling cloud infrastructure security and working with high-performing software engineering teams - Ability to quickly understand complex systems and architectures - Skilled in prioritizing security initiatives using a risk-based approach - Excellent collaboration, communication, and stakeholder management abilities - Experience working cross-functionally to implement impactful security improvements Benefits - Competitive base salary range: $189,200–$240,000, depending on location and experience, plus equity opportunities - Full health coverage including medical, dental, and vision - Remote-first work environment with support for necessary home office tools - Opportunities for professional growth and innovation in a fast-paced technology environment - Flexible work arrangements and regular in-person team gatherings for collaboration and team building - Wellness stipends and additional perks to support work-life balance

United States
$189.2K - $240K / year
Job Closed