A company in the medical technology sector is looking for an experienced Cyber Security Consultant to act as an independent advisor at the intersection of software architecture, DevOps, and regulatory affairs. The project goal is to develop and secure innovative digital health products (Software as a Medical Device / Connected Devices). The role involves purely technical consulting, technical assessments, and the delivery of validated security artifacts, without operational management decisions. The focus is on translating regulatory requirements (FDA, MDR, EU CRA, NIS2) into technical solutions and objectively assessing security risks.
- Holistic Threat Modeling: Conducting STRIDE-based analyses for APIs, cloud-native services, AI components, and CI/CD pipelines, as well as maintaining formal Threat Model Reports.
- Security Architecture & Design: Creating technical data flow diagrams (DFDs) and Security Architecture Review Reports to document security decisions in cloud and container environments.
- DevSecOps & Supply Chain Security: Advising on hardening CI/CD pipelines, implementing "security-by-default," and managing SBOM artifacts (third-party risk).
- Penetration Testing Support: Defining the scope for pen tests and fuzzing, as well as technically validating the results and CVSS scores.
- Vulnerability Management: Assessing vulnerabilities (Vulnerability Impact Assessments) and creating remediation plans.
- Audit Preparation: Compiling technical evidence and documentation for regulatory submissions (FDA, MDR, MDS2).
- Completed degree (Computer Science, Cyber Security, Engineering).
- 5–8+ years of project experience in product security, application security, or security architecture.
- Excellent knowledge of threat modeling (STRIDE, PASTA), risk assessments (CVSS), and secure SDLC.
- Deep expertise in cloud security (Azure/AWS), containerization (Kubernetes/Docker), API security, and CI/CD toolchains.
- Experience with AI/ML security is a plus.
- Proven experience with medical technology standards (FDA Cybersecurity Guidelines, EU MDR, ISO 14971, IEC 62304) or equivalent critical standards (ISO 21434, IEC 62443).
- Ability to drive technical topics independently as an external consultant, as well as a structured, "audit-ready" documentation style.
- Business fluent English (C1/C2) is mandatory (project and documentation language).
- Fluent German (B2/C1) is desirable.
- Relevant certifications such as CISSP, CCSP, CSSLP, CISM, or OSCP are strongly preferred.
Frequently asked questions
Where is the project located?
What is the duration of the project?
What is the remote work policy for the project?
What language skills are required for the project?
Which industries is the project related to?
Which business areas does the project cover?
Not available? Can I still benefit from the project?
How to apply for the project?
Similar Projects
Cyber Risk Consulting (Senior Level)
Quality Compliance Auditor (GCP/GCLP/GVP) (M/W/D)
Social Compliance Auditor (m/f/d)
Senior Regulatory Compliance Expert (FDA-Inspection Preparation) (m/f/d)
Java IT Architect (m/f/d)
ISO 20121 Auditor (w/m/d)
IT Project Manager ISO 27.001 - Gap Closure (m/f/d)
Auditor – FSC® and PEFC Chain of Custody (m/f/d)
Vibe Coding Web Scraping Expert (m/f/d)
HSE Specialist – Cell Manufacturing
HSE Specialist – Facilities (M/W/D)
HSE Specialist – Body in White (M/W/D)
Senior Cloud Developer TypeScript (m/f/d)
Consulting in the field of Tax Strategy
Area Product Manager (m/f/d)
Construction & Contractor Safety Specialist (SiGeKo) (m/f/d)
Adobe Experience Cloud Consultant (m/f/d)
Data Engineer (m/f/d)
Senior Project Manager Customer Interaction
AI Evaluation Consultant (m/w/d)
Management Consultant (Senior Level) (m/f/d)
Evaluation Scenario Writer (m/w/d)
Freelance Product Owner for Point Of Sale App
Commissioning & Qualification (C&Q) Engineer (m/f/d)
ERP Transformation Manager (m/f/d)
Infor AS Consultant (m/f/d)
Project Manager (Project Control Focus) (m/f/d)
Construction Manager according to LBO - Civil and MEP (m/f/d)
Safety and Health Protection Coordinator (SiGeKo) and Safety Specialist (SiFa) (m/f/d)
Financial Accountant (m/f/d)