- Company Name
- DivIHN Integration Inc
- Job Title
- Cyber Security Specialist
- Job Description
-
**Job Title:** Cyber Security Specialist
**Role Summary:**
Senior‑level consultant focused on securing medical‑device, IoT, mobile, and backend product technologies. Provides security guidance, conducts architecture reviews, threat modeling, and risk assessments, and ensures compliance with industry and regulatory standards. Works cross‑functionally with product owners, developers, and security architects to embed security by design and drive remediation of identified vulnerabilities.
**Expectations:**
- Apply deep knowledge of global cybersecurity frameworks (ISO 27001/2, SOC 2, HITRUST, FedRAMP, ISO 22301, etc.).
- Influence product security policies and standards for emerging technologies (AI, quantum, cloud).
- Communicate risk findings and mitigation recommendations clearly to technical and non‑technical stakeholders.
- Maintain documentation, dashboards, and compliance evidence; track remediation SLAs.
- Participate actively in governance forums and architecture review boards.
**Key Responsibilities:**
- Develop and maintain security standards, frameworks, and guidance documentation.
- Perform full‑stack architecture reviews and threat‑modeling for products and platforms, including consumer identity solutions.
- Validate security of software supply chains and deployment pipelines.
- Assess vulnerability assessment and penetration testing results; prioritize risks and define mitigation strategies.
- Monitor and report on compliance with risk‑based and regulatory cybersecurity requirements.
- Produce risk management plans aligned with organizational risk tolerance.
- Represent Product Cybersecurity in governance, architecture, and technical discussions.
**Required Skills:**
- 7+ years in cybersecurity, technology architecture, or security consulting.
- Expertise in ISO 27001/2, SOC 2, HITRUST, FedRAMP, ISO 22301, SOX, HIPAA, PCI‑DSS, EU DPD, Basel II.
- Proficient with GRC toolsets (e.g., RSA Archer, ServiceNow GRC).
- Strong understanding of cloud‑native, API‑driven architectures, IAM, secure SDLC, network security, cryptography, and modern phishing‑resistant auth (WebAuthn, Passkeys).
- Experience with risk assessments, control assessments, and governance reporting.
- Ability to influence policy for AI, quantum computing, and cloud technologies.
- Excellent analytical, problem‑solving, and written/oral communication skills.
**Required Education & Certifications:**
- Bachelor’s degree in Computer Science, Information Security, Engineering, or related field (or equivalent experience).
- CISSP (or equivalent) certification required; additional certifications such as CISM, CISA, or CCSP preferred.