Director, Product Security Operations

Company: Intuitive Surgical, Inc.
Location: Sunnyvale, CA 94087

Apply

Job: IT/Information Systems
Primary Location: United States-California-Sunnyvale-US-CA-Sunnyvale
Schedule: Full-time
Requisition ID: 193867

Description

Joining Intuitive Surgical means joining a team dedicated to using technology to benefit patients by improving surgical efficacy and decreasing surgical invasiveness, with patient safety as our highest priority.

The Product Security Operations Team is responsible for software products, infrastructure and cloud services, and IoMT solutions that collect and analyze medical device machine data from thousands of systems deployed world-wide.

The ideal candidate for the position of Director, Product Security Operations will have proven experience working designing, building, securing, and operating; on-premise, public, and private cloud, customer facing products and services, and 24x7x365 operations. The position requires a candidate with strong Cybersecurity, technical, and interpersonal skills, the ability to work effectively and collaboratively with the business, pre-market cybersecurity, peer Engineering teams, and across business units; to deliver high quality solutions that ensure patient safety and data/system security.

Roles & Responsibilities:

  • Leads the Product Security Operations Center for Intuitive Surgical
  • Responsible for the timely and successful resolution for all Product and shared Cyber Security incidents and events
  • Manages the coordination of internal and external SOC capabilities and resources to include coverage for private and public cloud environments
  • Develops, manages, and reports upon SecOps and FDA post-market cybersecurity programs
  • Ensures comprehensive, real-time status updates and reporting to key stakeholders
  • Leads and contributes practically in key projects, ensuring their compatibility with the strategic direction, compliance, and regulatory requirements
  • As required, supports the cyber risk teams in cyber Risk Analysis and Threat Modeling of complex systems, including interconnected web, application and database technology stacks with networked medical devices
  • Creates and manages post-market and operational cybersecurity requirements, playbooks, and operations
  • Creates and/or contributes to Quality Management System documentation
  • Prepare and Update Incident Response Plans / Playbooks across multiple product lines
  • Participate in the selection, implementation, and operations of Cyber threat counter measures and technologies
  • Prepare business and technical analysis
  • Participate in design of policies to improve the robustness and defense-in-depth for product lines
  • Other duties as assigned


Qualifications

Skills, Experience, Education, & Training:

  • Deep knowledge of Incident Response, Vulnerability Management, and Cyber Threat Intelligence functions
  • Subject Matter Expert in Operations Management
  • In-depth knowledge and understanding of cyber-attack vectors, malware analysis, and forensics capabilities
  • Familiarity with SIEM platforms, scanning platforms, and varieties of supporting SOC tooling
  • Ability to provide leadership and razor-sharp focus during times of crisis and stressful situations
  • Ability to be concise and clear in communication
  • Five or more years’ experience, with medical device, ICS/SCADA or embedded system experience highly desirable
  • 5+ years’ experience in an FDA regulated industry with direct application of FDA regulation for Cybersecurity
  • 10+ years in IT / Information Security roles, with 7+ years managing teams in a Security Operations Center
  • BS/BA required; MS highly desirable along with demonstration of sophisticated and logical thought processes
  • CAP, CISA, CISSP, GCIA, GIAC, GISF, GSEC, SSCP or equivalent certification required.
  • Strong analytic skills
  • Excellent judgment; proven ability to make difficult trade-offs with sound judgment and rationale
  • Travel: <10~20%
  • Job location: Sunnyvale, CA

We are an AA/EEO/Veterans/Disabled employer.
We will consider for employment qualified applicants with arrest and conviction records in accordance with fair chance laws.