Medical Device Cybersecurity Engineer
BIOBOT SURGICAL PTE. LTD.
Role Overview
Biobot Surgical is seeking a Medical Device Cybersecurity Engineer to strengthen the cybersecurity compliance and inter-connectivity of her product family throughout the total product lifecycle. The successful candidate will work closely with Engineering, Quality, Regulatory and Service teams to establish cybersecurity requirements, perform risk assessment and verification, manage software vulnerabilities and SBOMs, support regulatory submissions, and ensure the secure deployment of Biobot products within hospital IT environments.
Key Responsibilities
- Perform cybersecurity threat modelling and risk assessment for medical device systems, workstations, software, network interfaces and connected components.
- Define and implement secure-by-design requirements and controls, including authentication, access control, secure communication, logging, software updates, data protection, etc.
- Plan and support cybersecurity V&V, including vulnerability scanning, penetration testing, software/component analysis and security regression testing.
- Manage SBOMs, third-party/open-source software and vulnerabilities, including CVE monitoring, impact assessment, remediation and patch management.
- Support secure integration/deployment with hospital IT infrastructure, PACS/RIS/HIS, network storage and other connected systems.
- Prepare cybersecurity documentation and evidence for regulatory submissions and QMS/design-control activities.
- Support post-market cybersecurity activities, including vulnerability monitoring, disclosure, incident assessment and security updates.
- Bachelor’s degree or above in cybersecurity, computer science, software engineering, or a related discipline.
- Preferably 3+ years of cybersecurity or secure software development experience; experience with medical devices, healthcare technology, or healthcare IT systems is highly desirable.
- Practical experience in threat modelling, security risk assessment, vulnerability assessment, penetration testing, network security and secure software development.
- Able to translate cybersecurity risks and technical findings into practical engineering controls, risk-management evidence and regulatory documentation.
- Knowledge of SBOM, software supply-chain security, CVE/CWE/CVSS, third-party/open-source software management and vulnerability remediation.
- Familiarity with TCP/IP, TLS, REST APIs, Windows security and client-server architectures; experience with PACS/RIS/HIS and/or C++/C#/Qt programming is advantageous.
- Familiarity with FDA cybersecurity requirements/Section 524B, IEC 81001-5-1, AAMITIR57/TIR97, ISO 14971 and IEC 62304; knowledge of EU MDR/MDCG and Singapore HSA cybersecurity requirements is advantageous.