Jobs and Careers
IN

Sr. Director, Product Security - Acton, Mass. or San Diego, CA (Hybrid)

Insulet Corporation
San Diego, United Statesfull_timeVerifiedPosted 26 Jun 2025
💰 $361,350/yr($240,900/yr$361,350/yr)

About the role

Position Overview: The Sr. Director of Product Security will be responsible for developing and executing a comprehensive product security strategy that aligns with our business objectives and regulatory requirements. This role requires a dynamic leader with a deep understanding of cybersecurity in the medical device industry, experience managing large teams, and the ability to collaborate effectively with senior security leaders and cross-functional teams.

 

Key Responsibilities:

 

  • Strategic Leadership – Implement and refine the product security strategy and maturity effort, while tightly partnering and communicating with product delivery teams to ensure secure product launches and continuous risk reduction. Strong problem solving and decision-making skills.
  • Culture – foster a tightknit team, by motivating, mentoring, and aligning their day-to-day activities with security and business objectives. Promote education and awareness across the organization.
  • Communication at all Levels – Across potential board-level meetings to technical engineering discussions, strong communication needed to ensure visibility and alignment of security risks, impacts, and mitigating actions.
  • Cloud, Mobile App, and Application Security Engineering Services: Provide managed and repeatable application and Cloud security engineering services in support of the company's products and services, including threat modeling, risk management, and vulnerability testing. Collaborating with various technical teams to architect secure cloud environments and mobile application products; confirming they meet corporate and technology security standards and guidelines.
  • Cybersecurity Design Requirements: Support the development and testing of standard cybersecurity design requirements for medical device products.
  • Process Integration: Collaborate with Cybersecurity and Quality Teams to ensure cybersecurity processes are fully integrated with the company's Quality Management System (QMS) and operationalized.
  • Documentation Management: Support the publication of documentation related to the management of cybersecurity in medical device FDA submissions.
  • Post-Market Cybersecurity Management: Ensure continuous threat and vulnerability assessments against all products in the field, manage the company's Coordinated Disclosure Program, and participate in Information Sharing and Analysis Organizations (ISAOs).
  • Incident Management: Support and provide input into best practices related to medical device cybersecurity incident management processes, in alignment with the broader cyber security team.
  • Risk Management: Taking a pragmatic and business-aligned approach in solutioning risk reduction efforts with business partners and product delivery teams.. Develop and monitor risk registers for all medical device products.
  • Secure Software Development Lifecycle (S-SDLC): Develop, implement, train, and maintain the S-SDLC program.
  • Security Assessment: Lead Penetration testing, continuous application vulnerability assessment efforts, including static and dynamic application security testing (SAST & DAST/SBOM) for Insulet products.
  • Identity and Access Management: Partner with cybersecurity teams to support the identification, development, and maintenance of Identity and Access Management solutions for consumer and patient identity.
  • Security Posture Evaluation: Collaborate with cybersecurity teams to evaluate and document the cybersecurity posture of applications by leveraging standard and repeatable procedures informed by industry best practice guidance (e.g., NIST Cybersecurity Framework, NIST Risk Management Framework, ISO 2700x).
  • Innovation: Provide innovative and creative solutions to mitigate business or technical cybersecurity issues.
  • Compliance: Ensure compliance with all regulatory, audit, security, and risk management requirements.
  • IT Systems Integration: Partner to integrate IT systems development and vulnerability management with security policies and information protection strategies to support the company's product, patient, and corporate environments.
  • Security Architecture: Support IT systems security architecture design and review, along with the creation and maintenance of documented security standards.
  • Stakeholder Management – working with stakeholders to translate security requirements into operational security practices.<

Apply for this role

Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.

Apply Now →Generate Application Kit

Free account required — sign up in 30s

Company

Insulet Corporation

View company profile →