Skip to Content

Jobs

Product Security Engineer

|  Posted On: Aug 18, 2026

location:Irvine, CA 92618

Duration:12 Months, Contract

mode of work:On-site

Log In and Apply

Job Summary

Job Title:  
Product Security Engineer
Posted Date:  
Aug 18, 2026
Duration:  
12 Months, Contract
Shift(s):  

08:00 - 16:00

Salary ($): 
94.98 - 100.01 per Hourly (compensation based on experience and qualifications)
We care about you! Explore Rangam’s benefits information

Talk to our Recruiter

Name:
 
Christopher Massey

Email:
 
christopher@rangam.com

Phone:
 
908-704-8843

Description

Applications preferred location in the Orange County / Irvine, CA area.

Temp to Perm possibility but that depends on experience

Primarily remote positions with the requirements to travel into the office when required. Travel into the office could extend to a 4/1 schedule but not immediately

Job Description

Sr Product Security Engineer to support Client’s STS business unit and develop AI powers skills, agents, and services.

  • The Client portfolio includes FDA Class I and Class II medical devices and their associated cloud-connected platforms, on premise deployed software, and hosted applications.
  • The Sr Product Security Engineer owns, leads, and executes the activities and documentation outlined in Client’s security lifecycle.
  • These activities and documents include Security Requirements, Threat Modeling, Risk Assessments and Analysis, Vulnerability & Risk Management Plans, Security Testing, and White Papers. In addition, the use and development of AI tools/capabilities require the candidate to have both strategic and tactical experience in building with AI.

This role focuses on risk-based security that ensures patient safety, data protection, and regulatory readiness.

Role Focus

  • Execution of Product Security Engineering Lifecycle activities
  • Building AI based skills, agents, services, and platforms
  • Integration of AI driven capabilities into product development lifecycles
  • Generation and Maintenance of Product Security Documentation
  • Apply risk-proportionate security controls
  • Emphasize secure-by-design and secure-by-default
  • Balance usability, workflow, and security

Key Responsibilities

  • Security Engineering, Architecture & Design
  • Define end-to-end security engineering/design/solutions/controls across devices, apps, and cloud
  • Establish baseline security patterns (auth, encryption, secure updates)
  • Conduct Threat Modeling, Risk Assessments, Requirements/Controls Mapping, Security White Papers
  • Lead and Drive Security Design Reviews & Roadmap Remediations/Mitigations
  • Perform architecture risk analysis on device/cloud boundaries: trust boundary decomposition, data flow diagrams, attack surface enumeration, and abuse/misuse case development
  • Develop AI skills, agents, services

Secure SDLC

  • Implement lean Secure SDLC aligned to NIST, OWASP, and BSIMM
  • Integrate SAST, SCA, secrets scanning, container/IaC scanning
  • Define minimum viable security gates

Regulatory & Compliance

  • Support FDA cybersecurity documentation (threat models, SBOMs, risk assessments)
  • Align with IEC 62304, ISO 14971
  • Ensure audit-ready documentation

Cloud Security

  • Design secure integrations with Client’s Cloud Platforms
  • Secure device-to-cloud data flows

SBOM & Vulnerability Management

  • Establish SBOM processes (SPDX, CycloneDX)
  • Implement continuous vulnerability monitoring
  • Define risk-based remediation SLAs

Cross-Functional Leadership

  • Collaborate with engineering, quality, regulatory, and product teams
  • Translate security into patient safety and business risk
  • Mentor teams

Required Qualifications

  • 5+ years cybersecurity experience
  • Software Development, System Engineering background
  • AI (Agentic, Generative, ML) skills and agent development
  • Regulatory/Quality Control product development
  • Demonstrated working experience in the domains of embedded, cloud, and application security

Preferred Qualifications

  • Experience with FDA Class I/II devices and FDA submissions
  • Experience with IoMT ecosystems
  • Knowledge of FDA Cybersecurity Pre & Post Market Guidance, UL 2900, AAMI TIR57/TIR97
  • DevSecOps experience
  • Certifications (CISSP, CCSP, CSSLP)

Key Competencies

  • Ability to right-size security controls
  • Strong risk-based decision-making
  • Communication across technical and non-technical teams
  • Ability to perform manual secure code review and triage SAST findings for exploitability, tuning rules to drive false-positive rates down rather than escalating raw tool output
  • Produce and consume VEX (CSAF, OpenVEX) alongside SBOMs; maintain component provenance and transitive dependency accuracy
  • Depth in web/API security beyond OWASP Top 10: OWASP ASVS levels as requirement source, API Top 10, authorization logic flaws (IDOR, broken object-level and function-level authz), SSRF, deserialization, app security in multi-tenant context
  • Design and review authentication/authorization implementations: OAuth 2.0/OIDC flow selection and misuse, token lifetime and revocation, session management, SAML assertion validation
  • Demonstrated ability to read and write production code in at least one systems language

Success Metrics

  • Comprehensive Threat Modeling and effective Security Risk Management
  • SBOM completeness
  • Reduction in critical vulnerabilities
  • FDA submission success
  • Time-to-remediate vulnerabilities

 

 

AI-Assisted Application Screening

As part of our recruitment process, we may use automated tools or AI-enabled technologies to assist with resume screening and candidate matching. These tools help our recruitment team review applications more efficiently, but they do not make hiring decisions. All final decisions are made by human reviewers.