Skip to main content
Tallo logoTallo logo

Find Jobs

Find Jobs Near You – Available Work in Your Location

Skip to job details

Back to Results

Apply for this opportunity

To apply for this job, you'll continue to an external website or email application.

Systems Ally

Product Security Enginee

Career Insights for Risk Engineer

See where this job fits in the broader career landscape. Knowing your career path helps you see what's possible from here.

Scorecard

Based on California data

Review key factors to help you decide if this role fits your goals. How is this calculated?

Were these scores useful?

What they do

A Risk Engineer is responsible for identifying, analyzing and minimizing risks often associated with construction or resource extraction projects. May work for insurance companies, or engineering firms.

$147,120 / year median in California

Explore Career

Job Description

Product Security Enginee Systems Ally Irvine, CA Job Details Contract $60 an hour 1 hour ago Qualifications AI models Software engineering AI tools proficiency CISSP Cloud security best practices implementation Cloud-based systems Quality control Systems engineering IT services information & network security Vulnerability management Engineering product development Full Job Description W2 Only No C2C please Sr Product Security Engineer to support Client's STS business unit and develop AI powers skills, agents, and services. The Client portfolio includes FDA Class I and Class II medical devices and their associated cloud-connected platforms, on premise deployed software, and hosted applications. The Sr Product Security Engineer owns, leads, and executes the activities and documentation outlined in Client's security lifecycle. These activities and documents include Security Requirements, Threat Modeling, Risk Assessments and Analysis, Vulnerability & Risk Management Plans, Security Testing, and White Papers. In addition, the use and development of AI tools/capabilities require the candidate to have both strategic and tactical experience in building with AI. This role focuses on risk-based security that ensures patient safety, data protection, and regulatory readiness. Role Focus Execution of Product Security Engineering Lifecycle activities Building AI based skills, agents, services, and platforms Integration of AI driven capabilities into product development lifecycles Generation and Maintenance of Product Security Documentation Apply risk-proportionate security controls Emphasize secure-by-design and secure-by-default Balance usability, workflow, and security Key Responsibilities Security Engineering, Architecture & Design Define end-to-end security engineering/design/solutions/controls across devices, apps, and cloud Establish baseline security patterns (auth, encryption, secure updates) Conduct Threat Modeling, Risk Assessments, Requirements/Controls Mapping, Security White Papers Lead and Drive Security Design Reviews & Roadmap Remediations/Mitigations Perform architecture risk analysis on device/cloud boundaries: trust boundary decomposition, data flow diagrams, attack surface enumeration, and abuse/misuse case development Develop AI skills, agents, services Secure SDLC Implement lean Secure SDLC aligned to NIST, OWASP, and BSIMM Integrate SAST, SCA, secrets scanning, container/IaC scanning Define minimum viable security gates Regulatory & Compliance Support FDA cybersecurity documentation (threat models, SBOMs, risk assessments) Align with
IEC 62304, ISO 14971
Ensure audit-ready documentation SBOM & Vulnerability Management Establish SBOM processes (SPDX, CycloneDX) Implement continuous vulnerability monitoring Define risk-based remediation SLAs Required Qualifications 5+ years cybersecurity experience Software Development, System Engineering background AI (Agentic, Generative, ML) skills and agent development Regulatory/Quality Control product development Demonstrated working experience in the domains of embedded, cloud, and application security Preferred Qualifications Experience with FDA Class I/II devices and FDA submissions Experience with IoMT ecosystems Knowledge of FDA Cybersecurity Pre & Post Market Guidance, UL 2900, AAMI
TIR57/TIR97
DevSecOps experience Certifications (CISSP, CCSP, CSSLP) Key Competencies Ability to right-size security controls Strong risk-based decision-making Communication across technical and non-technical teams Ability to perform manual secure code review and triage SAST findings for exploitability, tuning rules to drive false-positive rates down rather than escalating raw tool output Produce and consume VEX (CSAF, OpenVEX) alongside SBOMs; maintain component provenance and transitive dependency accuracy Depth in web/API security beyond OWASP Top 10:
OWASP ASVS
levels as requirement source, API Top 10, authorization logic flaws (IDOR, broken object-level and function-level authz), SSRF, deserialization, app security in multi-tenant context Design and review authentication/authorization implementations: OAuth 2.0/OIDC flow selection and misuse, token lifetime and revocation, session management, SAML assertion validation Demonstrated ability to read and write production code in at least one systems language
Pay:
$60.00 per hour
Work Location:
In person