Project details
Recommended projects
Cyber Security Consultant – Product Security & Regulatory Compliance (m/f/d)
Freelance Cybersecurity Consultant for AI Red Teaming
Cyber Risk Consulting (Senior Level)
Quality Compliance Auditor (GCP/GCLP/GVP) (M/W/D)
Senior Regulatory Compliance Expert (FDA Inspection Preparation) (m/f/d)
Java IT Architect (m/f/d)
IT Project Manager ISO 27.001 - Gap Closure (m/f/d)
Senior Factor 10 Developer (IPS / IPM) (m/f/d)
Fullstack Engineer (m/f/d)
HSE Specialist – Cell Manufacturing
HSE Specialist – Facilities (M/F/D)
HSE Specialist – Body in White (M/W/D)
Senior Cloud Developer TypeScript (m/f/d)
Tax Strategy Consulting
Construction & Contractor Safety Specialist (SigeKo) (M/w/d)
Freelance Product Manager for Android App (m/f/d)
Adobe Experience Cloud Consultant (m/f/d)
Data Engineer (m/f/d)
Senior Project Manager Customer Interaction
Evaluation Scenario Writer (m/w/d)
AI Evaluation Consultant (m/w/d)
Management Consultant (Senior Level) (m/f/d)
Freelance Product Owner for Point of Sale App
Commissioning & Qualification (C&Q) Engineer (m/w/d)
ERP Transformation Manager (m/f/d)
Infor AS Consultant (m/f/d)
Project Manager Brand Guardianship (m/f/d)
IT Project Manager ServiceNow (Senior)
Safety and Health Protection Coordinator (SiGeKo) and Safety Specialist (SiFa) (m/f/d)
Control System Technician / Control Systems Specialist (m/f/d)
TM1 Planning Analytics and Interfaces Development (m/f/d)
Frontend developer to HR platform with Angular experience
Cyber Security Consultant – Product Security & Regulatory Compliance (m/f/d)
Project info
- Period01.03.2026 - 28.02.2027
- LocationGermany
- Languages Essential:
- English(Advanced)
Desirable:- German(Advanced)
- English
- Remoteup to 100%
Description
A medical technology company is looking for an experienced Cyber Security Consultant to act as an independent advisor at the intersection of software architecture, DevOps and regulatory affairs. The goal of the project is to develop and secure innovative digital health products (Software as a Medical Device / Connected Devices). This position includes purely specialist consulting, technical assessments and delivery of validated security artifacts, without operational management decisions. The focus is on translating regulatory requirements (FDA, MDR, EU CRA, NIS2) into technical solutions and objectively assessing security risks.
- Holistic Threat Modeling: Conduct STRIDE-based analyses for APIs, cloud-native services, AI components and CI/CD pipelines, and maintain formal threat model reports.
- Security Architecture & Design: Create technical data flow diagrams (DFD) and security architecture review reports to document security decisions in cloud and container environments.
- DevSecOps & Supply Chain Security: Advise on hardening CI/CD pipelines, implementing "security-by-default" and managing SBOM artifacts (third-party risk).
- Penetration Testing Support: Define the scope for pen tests and fuzzing, and technically validate the results and CVSS scores.
- Vulnerability Management: Assess vulnerabilities (vulnerability impact assessments) and develop remediation plans.
- Audit Preparation: Compile technical evidence and documentation for regulatory submissions (FDA, MDR, MDS2).
Requirements
- Completed degree (Computer Science, Cyber Security, Engineering).
- 5–8+ years of project experience in product security, application security or security architecture.
- Excellent knowledge of threat modeling (STRIDE, PASTA), risk assessments (CVSS) and secure SDLC.
- Deep expertise in cloud security (Azure/AWS), containerization (Kubernetes/Docker), API security and CI/CD toolchains.
- Experience with AI/ML security is a plus.
- Proven experience with medical technology standards (FDA Cybersecurity Guidelines, EU MDR, ISO 14971, IEC 62304) or comparable critical standards (ISO 21434, IEC 62443).
- Ability to independently drive technical topics as an independent consultant, as well as a structured, "audit-ready" documentation style.
- Fluent English (C1/C2) is required (project and documentation language).
- Fluent German (B2/C1) is desirable.
- Relevant certifications such as CISSP, CCSP, CSSLP, CISM or OSCP are highly desired.