Apply now »

Senior Cyber Security Manager

Req ID:  8225

Working Location: MASSACHUSETTS, WESTBOROUGH 

Workplace Flexibility: Hybrid

Are you looking for a company that cares about people’s lives and health, including yours? Let’s inspire healthier lives, together.

 

Olympus, a leading medical technology company, has focused on making people’s lives better for over 100 years.

Our Purpose is to make people’s lives healthier, safer, and more fulfilling.

 

Our Core Values are reflected in all we do: Integrity – Empathy – Agility – Unity – Long-Term View

 

We deliver on our purpose and our core values by staying True to Life.

Job Description

Under direction of the Executive Director of Systems Engineering, this position is responsible for managing the cybersecurity team through the design, development, documentation and execution of product design and test strategies. Ensuring the team meets the published system requirements and are compliant with Quality System Regulations.

As a Senior Cyber Security Manager in OSTA, you will join our systems team to help manage, coach, and lead our cyber security team to ensure that the products comply to IEC81001-1-5. In this role, you will work together with the Cyber Security CoE team, the Cyber Security team within quality and the design teams within OSTA to deliver all required documentation for product release. It is expected that you utilize your full range of skills including people management, Cyber Security analysis and test methods and partnerships to dive harmonization of tools and methods across all regions.

Job Duties

  • Coach, manage, lead and grow a talented team of cyber security engineers in the US and India that consistently delivers on projects.
  • Provide support and be the interface to the CoE team supporting all workstreams relating to the Cyber Security corporate strategy.
  • Support the policy definition with all regions.
  • Coordinates and drives product development and implementation teams in the requirements, specification, development, verification, and deployment of security measures in new, currently marketed, and legacy products, which run Linux or Windows operating systems.
  • Support all vendors in ensuring delivery of their cyber security deliverables.
  • Proposes solutions and define the technical direction for product security development efforts. Shares responsibility for ensuring secure architecture designs.
  • Owns the development and execution of security plans and product security specifications for new products.
  • Performs vulnerability scans on software prior to release.
  • Leads cybersecurity risk management activities, including threat modelling and vulnerability assessments. Works with the product team to specify risk controls based on the calculated CVSS scores.
  • Participates in design and code reviews to identify security-related issues and recommends design changes as appropriate.
  • Evaluate and harmonize tools:  e.g. Veracode, Black Duck, Cybellum, Polaris, Cyclone DX, SASI, DAST, Splunk, Qradar.
  • Assists development teams in penetration and fuzz testing of new products containing software.
  • Implements security code and configuration within products and supporting infrastructure.
  • Responsible for customer-facing product security documents such as MDS2 forms (Manufacturer Disclosure Statement for Medical Device Security).
  • Provides support on product security issues and questions that are escalated to Engineering.
  • Develops awareness of security concerns, shares best engineering practices, and creates/updates procedures to ensure compliance.
  • Assists with creating and maintaining facility-level procedures and work instructions for the cybersecurity program.
  • Coordinates the response to cybersecurity incidences.
  • Supports product teams in implementing and verifying security measures by providing guidance, helping to establish security measures, and applying appropriate tools.
  • Champions continued improvement of security-related processes and tools. Collaborates with other facilities and corporate to facilitate improvements.
  • Provides training on product security to internal teams with the support of the CoE.
  • Continuously expands knowledge and expertise in cybersecurity.
  • Remains abreast of the evolving regulatory guidance, legislation, and industry standards applicable to medical device and healthcare IT cybersecurity (e.g., CVSS, ISO, IEC, NIST, AAMI, FDA, HIPAA, GDPR, DoD RMF guidance/standards).
  • Identifies and evaluates new technologies and tools related to security.
  • Works with other regions to harmonize approach across all regions
  • Proposes solutions and helps define the future technical direction for product security.

Job Qualifications

Required:

  • BS Degree in Computer Science, Information Assurance, Computer Networking, and other related fields.
  • Cybersecurity Bootcamp graduates with a bachelor’s degree in other areas will be considered.
  • A minimum of 10 years of professional experience within Information Technology, Software Development or related field. Must have proven Linux and networking/infrastructure experience.
  • Minimum 7 years of working knowledge and understanding of security engineering, system and network security, authentication and application security. Including multiple combinations of the following: 
    • Software development processes and secure coding,
    • Developing security procedures and product security specifications,
    • Secure web and server-side application development,
    • Identity management, authentication, DDKG, cryptography, and encryption, including data encryption in transfer and at rest,
    • System administration and network security, including firewalls, VPNs, SSH, Site-to-Site tunnels, and network certificates,
    • Vulnerability/penetration testing,
    • TCP/IP, UDP, IPSEC, HTTP, HTTPS, routing protocols.

 

Preferred:

  • People leader, who resources look to follow.
  • General knowledge of medical device standards, security standards and test methods.
  • Strong Analytical and problem-solving skills.
  • Self-motivated person that can work individually and lead a team of cyber security engineers.
  • Ability to express ideas clearly both in written and oral communications.
  • Ability to analyze technical requirements and develop well-structured solutions.

Why join Olympus?

Here, people matter—our health, our happiness, and our lives.

  • Competitive salaries, annual bonus and 401(k)* with company match
  • Comprehensive Medical, Dental, Visions coverage effective on start date
  • 24/7 Employee Assistance Program
  • Free virtual live and on-demand wellness classes
  • Work-life balance supportive culture with hybrid and remote roles
  • 12 Paid Holidays
  • Educational Assistance
  • Parental Leave and Adoption Assistance
  • Volunteering and charitable donation match programs
  • Diversity & Inclusion Programs including Colleague Affinity Networks
  • On-Site Child Daycare, Café, Fitness Center**

*US Only

**Limited locations

 

We care about your health and financial well-being and offer the resources you need to feel vital, confident and ready for wherever life takes you. Learn more about our benefit offerings at https://www.olympusamerica.com/careers/benefits-perks.

        

About us:

Our Medical business uses innovative capabilities in medical technology, therapeutic intervention, and precision manufacturing to help healthcare professionals deliver diagnostic, therapeutic, and minimally invasive procedures to improve clinical outcomes, reduce costs, and enhance the quality of life for patients and their safety.

 

Headquartered in Tokyo, Japan, Olympus employs more than 31,000 employees worldwide in nearly 40 countries and regions. Olympus Corporation of the Americas, a wholly owned subsidiary of Olympus Corporation, is headquartered in Center Valley, Pennsylvania, USA, and employs more than 5,200 employees throughout locations in North and South America.  For more information, visit www.olympusamerica.com.

 

Olympus is dedicated to building a diverse, inclusive and authentic workplace

We recognize diversity in people, views and lifestyle choices and emphasize the importance of inclusion and mutual respect. We strive to continue to foster empathy and unity in the workplace so that our employees can fully contribute and thrive.

 

Let’s realize your potential, together.

It is the policy of Olympus to extend equal employment and advancement opportunity to all applicants and employees without regard to race, color, national origin (including language use restrictions), citizenship status, religious creed (including dress and grooming practices), age, sex (including pregnancy, childbirth, breastfeeding, medical conditions related to pregnancy, childbirth and/or breastfeeding), gender, gender identity and expression, sexual orientation, marital status, disability (physical or mental) and/or a medical condition, genetic information, ancestry, veteran status or service in the uniformed services, and any other characteristic protected by applicable federal, state or local law.

 

Applicants with Disabilities: As a Federal Contractor, Olympus is committed to ensuring our hiring process is accessible to everyone. If you need an accommodation in order to complete the application or hiring process, please contact Olympus via email at OCAAccommodations@olympus.com. If your disability impairs your ability to email, you may call our HR Compliance Manager at 1-888-Olympus (1-888-659-6787).

 

Posting Notes: || United States (US) || Massachusetts (US-MA) || Westborough || Research and Development 


Nearest Major Market: Worcester

Job Segment: Testing, R&D Engineer, Systems Engineer, Linux, Engineer, Technology, Engineering

Apply now »