Let’s get started
By clicking ‘Next’, I agree to the Terms of Service
and Privacy Policy
Jobs / Job page
Product Security Specialist image - Rise Careers
Job details

Product Security Specialist

Company Description

We believe in the power of ingenuity to build a positive human future.  

As strategies, technologies, and innovation collide, we create opportunity from complexity. 

Our teams of interdisciplinary experts combine innovative thinking and breakthrough technologies to progress further, faster. Our clients adapt and transform, and together we achieve enduring results. 

We are over 4,000 strategists, innovators, designers, consultants, digital experts, scientists, engineers, and technologists. And we have deep expertise in consumer and manufacturing, defence and security, energy and utilities, financial services, government and public services, health and life sciences, and transport.  

Our teams operate globally from offices across the UK, Ireland, US, Nordics, and Netherlands. 

PA. Bringing Ingenuity to Life. 

Job Description

We are seeking a Product Security Specialist with expertise in connected/ IoT medical devices or healthcare products to join our team. The ideal candidate will be responsible for working with our clients to advice and shape the overall security strategy for products, ensure secure design, development, and deployment across the entire product lifecycle, and implement industry best practices to protect sensitive healthcare data.

Key Responsibilities:

  • Work with client product teams and functional groups on determining objectives, scope, and timelines for key product security initiatives and architecting the delivery methodologies
  • Assess security risks across client product portfolios and recommend remediation strategies while balancing business and technical requirements
  • Advice on strategies around coding, threat modeling, and security testing for embedded systems, IoT devices while ensuring compliance with industry regulations
  • Work alongside client R&D teams to lead on secure code reviews, threat modeling, security risk assessments, vulnerability assessments and validation and verification of controls
  • Monitor emerging cybersecurity threats in the IoT and medical device landscape and write though leadership to showcase PA’s point of view on these
  • Build strong stakeholder relationships across our clients
  • Foster team growth, training and deliver outcomes.
  • Support and drive business development efforts
  • Manage projects with expertise.
  • Solve problems with a consulting approach.

Flexible working - We are guided by our client work and needs; however, you have autonomy to manage your time and diary to suit your work/life balance.

Qualifications

  • 8+ years of experience in IoT security, preferably in the medical device or the pharmaceutical industry.
  • Proficiency in security frameworks (e.g., NIST, OWASP, MITRE ATT&CK, PASTA, STRIDE) and standards such as FDA cybersecurity guidance
  • Experience assessing security risks using industry standard methods (penetration test results, threat modeling, security testing) and determining residual risk after applying compensating security controls
  • Experience implementing and demonstrating compliance to security frameworks such as NIST, IEC, HITRUST, HIPAA, GDPR, ISO 27001, SOC 2 Type 2 and familiarity working with Quality Management Systems
  • Experience working with teams in a structured software development lifecycle process
  • Excellent interpersonal skills, both written and verbal, with the ability to clearly convey complex security topics to a wide audience - technical and non-technical teams.
  • Proven track record of achieving outcomes and nurturing relationships.
  • Skilled in crafting compelling proposals and other business development materials. Proficient in cultivating opportunities within the client base and network.
  • Holds Cyber Security accreditations/qualifications such as [CISSP, CSSLP, CISM], indicating a solid foundation in the field.

 

We know the skill-gap and ‘somewhat need to tick every box’ can get in the way of meeting brilliant candidates, so please don’t hesitate to apply – we’d love to hear from you.

Apply today by completing our online application

#LI-IC2

Additional Information

Life At PA encompasses our peoples' experience at PA. It's about how we enrich peoples’ working lives by giving them access to unique people and growth opportunities and purpose led meaningful work. 

Our purpose guides how we work with our clients and our teams, and support our communities, to deliver insight and impact, solving the world’s most complex challenges. We're focused on building a workplace that values human difference and diverse mindsets, and a culture of inclusion and equality that unlocks the potential in our people so everyone can be their best self. 

Find out more about Life at PA here

We are dedicated to supporting the physical, emotional, social and financial well-being of our people. Check out some of our extensive benefits: 

  • Health and lifestyle perks accompanying private healthcare for you and your family 
  • 25 days annual leave (plus a bonus half day on Christmas Eve) with the opportunity to buy 5 additional days 
  • Generous company pension scheme 
  • Opportunity to get involved with community and charity-based initiatives 
  • Annual performance-based bonus 
  • PA share ownership 
  • Tax efficient benefits (cycle to work, give as you earn) 

We’re committed to advancing equality. We recruit, retain, reward and develop our people based solely on their abilities and contributions and without reference to their age, background, disability, genetic information, parental or family status, religion or belief, race, ethnicity, nationality, sex, sexual orientation, gender identity (or expression), political belief veteran status, or other by any other range of human difference brought about by identity and experience. We welcome applications from underrepresented groups. 

Adjustments or accommodations - Should you need any adjustments or accommodations to the recruitment process, at either application or interview, please contact us on [email protected] 

Average salary estimate

$110000 / YEARLY (est.)
min
max
$100000K
$120000K

If an employer mentions a salary or salary range on their job, we display it as an "Employer Estimate". If a job has no salary data, Rise displays an estimate if available.

What You Should Know About Product Security Specialist, PA Consulting

At PA Consulting, we are excited to welcome a talented Product Security Specialist to our London office, located at 10 Bressenden Place, SW1E 5DN. In this pivotal role, you will play a key part in shaping the security strategies for connected and IoT medical devices, safeguarding sensitive healthcare data throughout the product life cycle. Collaborating closely with our client product teams, you'll determine objectives and timelines for critical security initiatives while implementing industry best practices. Your experience in assessing security risks and recommending effective remediation strategies will be invaluable as you work alongside our R&D teams to conduct secure code reviews and threat modeling. We also expect you to monitor emerging cybersecurity threats and share thought leadership on them, underscoring PA’s commitment to innovation and excellence in security practices. Flexibility is at the heart of our culture; while you will have autonomy over your schedule, your collaborative spirit and excellent communication skills will help you build strong relationships with stakeholders across various industries. If you thrive in a dynamic environment and are passionate about fostering team growth while driving business development, this role is for you. With over 8 years of experience in IoT security, particularly in the medical device or pharmaceutical sector, you'll also bring proficiency in key security frameworks and be well-equipped to guide our clients through compliance challenges. Join us and help us advance our purpose-driven mission while enjoying a balanced work/life dynamic!

Frequently Asked Questions (FAQs) for Product Security Specialist Role at PA Consulting
What responsibilities does the Product Security Specialist have at PA Consulting?

The Product Security Specialist at PA Consulting is responsible for developing security strategies for IoT medical devices, identifying security risks, and leading secure design and development initiatives. The role also includes conducting threat modeling, vulnerability assessments, and ensuring compliance with industry standards such as NIST and FDA cybersecurity guidance.

Join Rise to see the full answer
What qualifications are needed for the Product Security Specialist position at PA Consulting?

Candidates for the Product Security Specialist role at PA Consulting should have over 8 years of experience in IoT security, preferably within the medical devices sector. Proficiency in security frameworks, risk assessment methods, and prior experience in structured software development lifecycle processes are critical. Certifications like CISSP or CISM would also be beneficial.

Join Rise to see the full answer
How does PA Consulting support the professional growth of a Product Security Specialist?

At PA Consulting, we cultivate professional growth through mentoring, training opportunities, and access to innovative projects. The Product Security Specialist will not only work on diverse client initiatives but also have the chance to lead training sessions and contribute to thought leadership, thus enhancing their expertise in the field.

Join Rise to see the full answer
What does a typical workday look like for a Product Security Specialist at PA Consulting?

A typical workday for a Product Security Specialist at PA Consulting includes collaborating with client teams to assess security risks, conducting code reviews, and leading security testing initiatives. The role also involves monitoring emerging cybersecurity trends and preparing business development materials while enjoying a flexible work environment.

Join Rise to see the full answer
What kind of projects would a Product Security Specialist work on at PA Consulting?

The Product Security Specialist at PA Consulting will engage with a diverse array of projects focusing on the security of IoT medical devices. This includes advising on product security strategies, executing threat modeling, and implementing security assessments to ensure compliance and the protection of sensitive health data.

Join Rise to see the full answer
Common Interview Questions for Product Security Specialist
How do you assess security risks in IoT devices?

To effectively assess security risks in IoT devices, start by identifying potential vulnerabilities, collecting threat intelligence, and analyzing penetration testing results. Leverage experiences with threat modeling frameworks, ensuring a comprehensive evaluation while prioritizing remediation strategies.

Join Rise to see the full answer
Can you explain your experience with security compliance frameworks?

Yes, I have significant experience implementing and demonstrating compliance with frameworks such as NIST, HIPAA, and ISO 27001. I can discuss specific scenarios where I led compliance assessments and developed action plans to address gaps identified during evaluations.

Join Rise to see the full answer
Describe a successful project you managed related to product security.

In my previous role, I led a project redesigning the security protocols for a connected medical device. This involved cross-functional collaboration, conducting threat assessments, and implementing a new secure coding standard that resulted in a 40% reduction in vulnerabilities.

Join Rise to see the full answer
How do you stay updated with the latest cybersecurity threats?

Staying updated involves regularly reading industry journals, attending webinars, and participating in cybersecurity forums. I also follow credible organizations like NIST and attend conferences to network with peers and share insights on emerging threats.

Join Rise to see the full answer
What is your approach to threat modeling?

My approach to threat modeling involves identifying assets, understanding potential threats and vulnerabilities, then developing a model that maps these elements. This helps in prioritizing risks based on potential impact and likelihood, allowing for more informed mitigation strategies.

Join Rise to see the full answer
How do you communicate complex security issues to non-technical stakeholders?

When communicating with non-technical stakeholders, I focus on simplifying the technical jargon, using analogies and visual aids. It’s important to relate the implications of security risks to their business objectives, making the conversation relatable and aligned with their concerns.

Join Rise to see the full answer
What tools do you use for vulnerability assessments?

I have experience with various vulnerability assessment tools like Nessus and Qualys. I focus on integrating tools that best fit the project needs while ensuring thorough coverage of security vulnerabilities during assessments.

Join Rise to see the full answer
How would you handle a security incident?

In the event of a security incident, I would first contain the breach to prevent further damage, then analyze the cause, and follow an incident response plan. Keeping stakeholders informed and documenting the process ensures transparency and aids in future prevention strategies.

Join Rise to see the full answer
Describe your experience with secure coding practices.

I have implemented secure coding practices across multiple projects, emphasizing the importance of adhering to established coding standards and conducting code reviews. Regular training sessions for the development teams have also been instrumental in promoting a security-first culture.

Join Rise to see the full answer
What are your thoughts on the future of IoT security?

I believe the future of IoT security will require a shift towards proactive measures, including AI-driven security solutions and continuous monitoring. As technology evolves, collaboration among stakeholders will be crucial in establishing robust security frameworks to counteract emerging threats.

Join Rise to see the full answer
Similar Jobs
Photo of the Rise User
Argo Group Hybrid US NY - New York City
Posted 8 days ago
Photo of the Rise User
NBCUniversal Hybrid 100 Universal City Plaza, Universal City, CALIFORNIA
Posted 11 days ago
Photo of the Rise User
Posted yesterday
Posted 6 days ago
Photo of the Rise User
Posted 12 days ago
Photo of the Rise User
Posted 3 days ago
Photo of the Rise User
Verisign Remote Reston,Virginia,United States
Posted 4 days ago
Photo of the Rise User
Posted 5 days ago
Vision Insurance
Dental Insurance
Performance Bonus
Paid Holidays

Our clients recognise we’re different. We’re different in ‘what’ we do, and even more in ‘how’ we do it. Our strategy work helps clients deliver innovation into the real world. At the heart of our business are our people – strategists, technologis...

34 jobs
MATCH
VIEW MATCH
FUNDING
SENIORITY LEVEL REQUIREMENT
TEAM SIZE
EMPLOYMENT TYPE
Full-time, remote
DATE POSTED
March 12, 2025

Subscribe to Rise newsletter

Risa star 🔮 Hi, I'm Risa! Your AI
Career Copilot
Want to see a list of jobs tailored to
you, just ask me below!
LATEST ACTIVITY
Photo of the Rise User
Someone from OH, Cleveland just viewed Accounting Co-Op (Part-Time) at Avery Dennison
Photo of the Rise User
Someone from OH, North Ridgeville just viewed Product Manager at ShiftCare
Photo of the Rise User
Someone from OH, North Ridgeville just viewed Product Operations at Binance
Photo of the Rise User
Someone from OH, Mentor just viewed Sales & Service Lead - Pinecrest at Alo Yoga
Photo of the Rise User
8 people applied to Excel Developer at Valcre
Photo of the Rise User
Someone from OH, Mason just viewed Marketing & Communications Intern at Per Scholas
Photo of the Rise User
Someone from OH, Lakewood just viewed Recruiter (Talent Sourcing), 6 month contract at Jerry
Photo of the Rise User
Someone from OH, Westerville just viewed Director Change Management at Discover