Manager Product Security
United States of America : Remote
JOB DESCRIPTION:
Working at Abbott
At Abbott, you can do work that matters, grow, and learn, care for yourself and your family, be your true self, and live a full life. You’ll also have access to:
- Career development with an international company where you can grow the career you dream of.
- Employees can qualify for free medical coverage in our Health Investment Plan (HIP) PPO medical plan in the next calendar year.
- An excellent retirement savings plan with a high employer contribution
- Tuition reimbursement, the Freedom 2 Save student debt program, and FreeU education benefit - an affordable and convenient path to getting a bachelor’s degree.
- A company recognized as a great place to work in dozens of countries worldwide and named one of the most admired companies in the world by Fortune.
- A company that is recognized as one of the best big companies to work for as well as the best place to work for diversity, working mothers, female executives, and scientists.
The Opportunity
The Manager of Product Security is a key leadership role within our Informatics business unit within the Abbott Rapid Diagnostics (ARDx) Division. This position can be based in Willis Tower, IL, Charlottesville, VA, Lake Forest, IL, or San Diego, CA or can be performed remotely within the Continental United States near an airport.
We’re empowering smarter medical and economic decision making to help transform the way people manage their health at all stages of life. Every day, more than 10 million tests are run on Abbott’s diagnostics instruments, providing lab results for millions of people.
The Product Security Manager is a high caliber performer responsible for identifying security risks of developed, marketed, and fielded products, including, but not limited to, patient safety and data protection risks. The person hired will also support the product security program that offers services such as: product security risk assessment, security testing, security documentation, security event handling, metrics & monitoring, External communications and staffing, education and training.
What You’ll Work On
Lead penetration testing efforts to identify gaps/opportunities for improvement
Drive execution of efforts to implement regulatory compliance frameworks
Support engineering and development efforts to remediate security and compliance risks
Support the development and compliance of Product Security Policies and Procedures
Support the integration of Product Security Policies and Procedures into Product Quality Systems.
Develops local strategy which is aligned with the business strategy and implements related tactical activities.
Lead the execution of product security program, including aligning with business and product strategy, gaining management approval and support, and overseeing successful execution.
Support cross-functional activities that help the product teams build safe and secure products that are compliant with industry regulation and meeting customer and patient security/safety expectations.
Maintain positive and cooperative communications and collaboration with all levels of employees, customers, contractors, and vendors.
Perform all procedures necessary to ensure the safety of information systems and to protect systems from intentional or inadvertent access or destruction; provide oversight and generation of necessary deliverables
Must be able to weigh business needs against security concerns and articulate issues to management.
Reporting of security related metrics to local, Division, and Corporate Management.
Lead product security communication efforts, training, and governance programs.
Collaborate with product teams to create and maintain a secure product development lifecycle process to ensure that security requirements/controls can be embedded within the product and development process.
Lead efforts to integrate new security requirements into Quality System and processes.
Provides strategic consultancy support to clients, Senior Technical Specialists, and other technical architects in all aspects of enabling technologies to meet business demands.
Works with legal and other regulatory and compliance groups to ensure the company is compliant with key laws, regulations, and certifications
Coach and guide lower-level security professionals.
Serve as the point of contact for all security related activities.
Required Qualifications
Bachelor’s degrees in Information Security, Computer Science, Information Technology (IT), or equivalent combination of education and work experience
7 years of work experience in information security.
Preferred Qualifications
10+ years of relevant professional experience in information security, software development, or IT management.
Exposure to software and cloud infrastructure security
Certifications such as CISA, CIMS, CRISC, CISSP, CPP or CFE
Knowledge of national and internation regulatory compliances and frameworks such as NIST Cybersecurity Frameworks, ISO 27001, GDPR, HIPAA/HITECH, Department of Defense Risk Management Framework.
Experience with implementation and operational use of Governance Risk and Compliance (GRC) toolsets.
Strong analytical skills, business intelligence, effective communication, interpersonal skills, organizational intelligence, relationship management
Ability to make meaningful decisions based on sound judgement
Ability to work effectively with a variety of roles from executive management to cybersecurity analysts
Learn more about our health and wellness benefits, which provide the security to help you and your family live full lives: www.abbottbenefits.com
Follow your career aspirations to Abbott for diverse opportunities with a company that can help you build your future and live your best life. Abbott is an Equal Opportunity Employer, committed to employee diversity.
Connect with us at www.abbott.com, on Facebook at www.facebook.com/Abbott, and on Twitter @AbbottNews.
The base pay for this position is
$97,300.00 – $194,700.00In specific locations, the pay range may vary from the range posted.
JOB FAMILY:
Information Risk & Quality Assurance
DIVISION:
CMI ARDx Cardiometabolic and Informatics
LOCATION:
United States of America : Remote
ADDITIONAL LOCATIONS:
United States > Charlottesville : 915 E High Street, United States > Lake Forest : J55, United States > San Diego : 4545 Towne Center Court
WORK SHIFT:
Standard
TRAVEL:
Yes, 10 % of the Time
MEDICAL SURVEILLANCE:
No
SIGNIFICANT WORK ACTIVITIES:
Continuous sitting for prolonged periods (more than 2 consecutive hours in an 8 hour day), Keyboard use (greater or equal to 50% of the workday)Abbott is an Equal Opportunity Employer of Minorities/Women/Individuals with Disabilities/Protected Veterans.
EEO is the Law link - English: http://webstorage.abbott.com/common/External/EEO_English.pdf
EEO is the Law link - Espanol: http://webstorage.abbott.com/common/External/EEO_Spanish.pdf Apply
Job Profile
RestrictionsMust be located in the continental United States near an airport Remote
Benefits/PerksCareer development Education benefit Education benefits Excellent retirement savings plan Freedom 2 Save student debt program Free medical coverage FreeU education benefit Great Place to Work Health and wellness benefits Medical coverage Recognized as a great place to work Retirement savings Retirement savings plan Student debt program Training Tuition reimbursement Work that matters
Tasks- Develop product security policies
- Documentation
- Identify security risks
- Leadership
- Lead penetration testing
- Oversee product security program execution
- Product development
- Regulatory Compliance
- Relationship Management
- Reporting
- Support regulatory compliance
Analytical Branded generic medicines Business strategy Cloud Cloud Infrastructure Collaboration Communication Compliance Compliance frameworks Computer Science Cross-functional Collaboration Cybersecurity Diagnostics Documentation Education Education and Training Effective Communication Engineering English Healthcare Informatics Information security Information systems Integration Interpersonal ISO IT IT Management Leadership Management Medical Devices Metrics/Monitoring Monitoring Nutritionals Organizational Penetration Testing Product Development Product Security Quality Assurance Quality System Regulatory Compliance Reimbursement Relationship Management Risk Assessment Risk Management SAFe Security Documentation Security Event Handling Security policies Security requirements Security Testing Software Software Development Training
Experience5 years
EducationBusiness Computer Science DO Engineering Equivalent Healthcare Information Security Information Systems Information Technology Science
Certifications Timezones