Job position Product Security Engineer
Share this job
Freelance Product Security Engineer - Contract / Contract-to-Perm
Industry: Medical Device / Life Sciences
Location: Limerick, Ireland
Working model: Hybrid - 2 days minimum per week onsite
Contract length: Initial 6 months
Rate: Competitive
Eligibility: Candidates must already have the right to work in Ireland
We are working with a global organisation in the medical device / life sciences industry to recruit a Freelance Product Security Engineer for a long-term contract opportunity based in Limerick.
This role is focused on product security, application security, secure SDLC, software security and secure-by-design development within a regulated medical product environment. The successful contractor will work closely with software engineering, product development, quality, regulatory and cybersecurity teams.
The work will include security requirements, threat modelling, SAST, DAST, SCA, SBOM review, software composition analysis, vulnerability assessment, exploitability assessment, secure coding and remediation planning.
This is not a SOC, SIEM, network security, cloud security or general infrastructure security operations role.
Key responsibilities include:
- Support product security and application security across regulated software-based medical products.
- Define and support secure SDLC and secure-by-design practices.
- Partner with software and product engineering teams on security requirements, secure coding and remediation.
- Lead or support threat modelling and product security risk assessments.
- Review software/product designs and provide practical application security guidance.
- Support vulnerability assessment, exploitability assessment, impact assessment and risk review.
- Work with SAST, DAST, SCA, vulnerability scanning and dependency analysis tools.
- Support SBOM review, software composition analysis and open-source governance.
- Contribute to product security documentation within a regulated quality environment.
- Collaborate with software, systems, quality, regulatory and cybersecurity teams.
Required experience:
- 3+ years' experience in product security, application security, software security, secure software development or security architecture.
- Strong understanding of secure SDLC, secure-by-design and secure software development principles.
- Hands-on experience with SAST, DAST and SCA / software composition analysis.
- Experience with SBOMs, dependency analysis, open-source governance or software supply chain security.
- Experience assessing vulnerabilities, exploitability, risk, impact and remediation options in application or product environments.
- Strong cyber fundamentals, including cryptography, CIA triad, threat modelling, authentication, encryption and secure communications.
- Understanding of secure coding standards and frameworks such as OWASP, NIST or similar.
- Ability to work directly with engineering teams and provide clear, practical technical guidance.
- Strong written documentation skills.
- Experience working in a regulated, quality-managed or safety-critical environment.
Nice to have:
- Experience in medical device, life sciences, regulated software, product security or application security environments.
- Experience with Windows applications, .NET, SQL Server, Angular, jQuery or similar software environments.
- Familiarity with FDA, MDR, ISO 13485, IEC 62304, NIS2 or similar regulated frameworks.
- Security certifications such as CISSP, CSSLP, CEH or similar.
This is a strong freelance contract opportunity for someone who wants a hands-on, engineering-facing Product Security Engineer role in the medical device / life sciences industry.
Applicants must already have the right to work in Ireland.
Please click to find out more about our Key Information Documents. Please note that the documents provided contain generic information. If we are successful in finding you an assignment, you will receive a Key Information Document which will be specific to the vendor set-up you have chosen and your placement.
To find out more about Real, please visit
Real Staffing, a trading division of SThree Partnership LLP is acting as an Employment Business in relation to this vacancy | Registered office | 8 Bishopsgate, London, EC2N 4BQ, United Kingdom | Partnership Number | OC387148 England and Wales
Candidate profile
The right candidate will be confident working with software engineering, product, quality, regulatory and cybersecurity teams. They should be able to assess security risks, explain technical issues clearly and give practical guidance that helps engineering teams build and maintain secure software-based products.
This role suits someone with real application security / product security experience. It is not aimed at candidates whose background is mainly SOC, SIEM, network security, cloud security or infrastructure security operations.
Core experience:
- 3+ years in product security, application security, software security, secure software development or security architecture.
- Strong understanding of secure SDLC, secure-by-design and secure software development.
- Hands-on experience with SAST, DAST and SCA / software composition analysis.
- Experience with SBOM review, dependency analysis, open-source governance or software supply chain security.
- Experience assessing vulnerabilities, exploitability, impact, risk and remediation options in application or product environments.
- Strong cyber fundamentals including cryptography, CIA triad, threat modelling, authentication, encryption and secure communications.
- Knowledge of secure coding standards and frameworks such as OWASP, NIST or similar.
- Clear communication with engineering teams and strong written documentation skills in regulated, quality-managed or safety-critical environments.
Relevant backgrounds include:
- Product Security Engineer
- Application Security Engineer
- Software Security Engineer
- Cybersecurity Engineer - application or product security focused
- Security Architect - software, application or product focused
- Secure Software Development Engineer / Secure SDLC Engineer
- Security Consultant with product security, application security or regulated software experience
Nice to have:
- Experience in regulated software, product security or application security environments.
- Experience with Windows applications, .NET, SQL Server, Angular, jQuery or similar software environments.
- Familiarity with FDA, MDR, ISO 13485, IEC 62304, NIS2 or similar regulated frameworks.
- Security certifications such as CISSP, CSSLP, CEH or similar.
Availability and eligibility:
- Available for a freelance contract role.
- Able to work hybrid in Limerick, Ireland.
- Must already have the right to work in Ireland.
- Suitable for contractors who can work independently, support technical teams quickly and contribute to long-term product security activity.
Working environment
The client is a global organisation operating in a highly regulated product development environment within the medical device / life sciences industry.
They design, develop and support software-based medical products where software quality, product security, compliance and patient/user safety are critical. The business has long-term project demand linked to new product development, global regulatory requirements and ongoing security improvements across existing products.
The role sits within a technical function that works closely with software engineering, product development, quality, regulatory and cybersecurity teams. This is a good fit for someone who wants to work in a structured, regulated environment where product security has real impact across engineering, compliance and end-user safety.
Apply to this job!
Find your next career move from +800 jobs!
-
Manage your visibility
Salary, remote work... Define all the criteria that are important to you.
-
Get discovered
Recruiters come directly to look for their future hires in our CV library.
-
Join a community
Connect with like-minded tech and IT professionals on a daily basis through our forum.
Product Security Engineer
Real Staffing
