Find Jobs
Find Jobs Near You – Available Work in Your Location
Skip to job details
M
Mindlance
Staff Engr, Software
Career Insights for Risk Engineer
See where this job fits in the broader career landscape. Knowing your career path helps you see what's possible from here.
Scorecard
Based on California data
Review key factors to help you decide if this role fits your goals. How is this calculated?
What they do
A Risk Engineer is responsible for identifying, analyzing and minimizing risks often associated with construction or resource extraction projects. May work for insurance companies, or engineering firms.
$147,120 / year median in California
Job Description
Staff Engr, Software#26-23369
$80
- 90 per hour Irvine, CA Onsite Job Description Bill rate is
- Temp to Perm possibility but that depends on experience !
- Execution of Product Security Engineering Lifecycle activities
- Building AI based skills, agents, services, and platforms
- Integration of AI driven capabilities into product development lifecycles
- Generation and Maintenance of Product Security Documentation
- Apply risk-proportionate security controls
- Emphasize secure-by-design and secure-by-default
- Balance usability, workflow, and security Key Responsibilities
- Security Engineering, Architecture & Design
- Define end-to-end security engineering/design/solutions/controls across devices, apps, and cloud
- Establish baseline security patterns (auth, encryption, secure updates)
- Conduct Threat Modeling, Risk Assessments, Requirements/Controls Mapping, Security White Papers
- Lead and Drive Security Design Reviews & Roadmap Remediations/Mitigations
- Perform architecture risk analysis on device/cloud boundaries: trust boundary decomposition, data flow diagrams, attack surface enumeration, and abuse/misuse case development
- Develop AI skills, agents, services Secure SDLC
- Implement lean Secure SDLC aligned to NIST, OWASP, and BSIMM
- Integrate SAST, SCA, secrets scanning, container/IaC scanning
- Define minimum viable security gates Regulatory & Compliance
- Support FDA cybersecurity documentation (threat models, SBOMs, risk assessments)
- Align with
IEC 62304, ISO 14971
- Ensure audit-ready documentation Cloud Security
- Design secure integrations with Client's Cloud Platforms
- Secure device-to-cloud data flows SBOM & Vulnerability Management
- Establish SBOM processes (SPDX, CycloneDX)
- Implement continuous vulnerability monitoring
- Define risk-based remediation SLAs Cross-Functional Leadership
- Collaborate with engineering, quality, regulatory, and product teams
- Translate security into patient safety and business risk
- Mentor teams Required Qualifications
- 5+ years cybersecurity experience
- Software Development, System Engineering background
- AI (Agentic, Generative, ML) skills and agent development
- Regulatory/Quality Control product development
- Demonstrated working experience in the domains of embedded, cloud, and application security Preferred Qualifications
- Experience with FDA Class I/II devices and FDA submissions
- Experience with IoMT ecosystems
- Knowledge of FDA Cybersecurity Pre & Post Market Guidance, UL 2900, AAMI
TIR57/TIR97
- DevSecOps experience
- Certifications (CISSP, CCSP, CSSLP) Key Competencies
- Ability to right-size security controls
- Strong risk-based decision-making
- Communication across technical and non-technical teams
- Ability to perform manual secure code review and triage SAST findings for exploitability, tuning rules to drive false-positive rates down rather than escalating raw tool output
- Produce and consume VEX (CSAF, OpenVEX) alongside SBOMs; maintain component provenance and transitive dependency accuracy
- Depth in web/API security beyond OWASP Top 10:
OWASP ASVS
levels as requirement source, API Top 10, authorization logic flaws (IDOR, broken object-level and function-level authz), SSRF, deserialization, app security in multi-tenant context- Design and review authentication/authorization implementations: OAuth 2.0/OIDC flow selection and misuse, token lifetime and revocation, session management, SAML assertion validation
- Demonstrated ability to read and write production code in at least one systems language Success Metrics
- Comprehensive Threat Modeling and effective Security Risk Management
- SBOM completeness
- Reduction in critical vulnerabilities
- FDA submission success
- Time-to-remediate vulnerabilities Applications preferred location in the Orange County / Irvine, CA area.
Shift:
['API Documentation', 'Application Programming Interface (API) Security', 'Application Security Architecture', 'Application Security Testing', 'Artificial Intelligence (AI)', 'Cloud Security', 'Cyber Risks', 'Cybersecurity', 'Cyber Security Assessments', 'Cybersecurity Compliance', 'Cybersecurity Risk Management', 'Cyber Threat Analysis', 'Cyber Threat Modeling', 'Design Documentation', 'Documentation Compliance', 'Security Engineering']Start:
[]EEO:
"Mindlance is an Equal Opportunity Employer and does not discriminate in employment on the basis of- Minority/Gender/Disability/Religion/LGBTQI/Age/Veterans.