What are the responsibilities and job description for the Senior Security Architect position at Arkhya Tech. Inc.?
Role – Security Architect
Location: Onsite, Hercules, CA (Onsite 3 days/Week)
We are seeking a Security Architect to design, implement, and maintain secure systems and processes within an FDA-regulated medical device environment. The role focuses on overseeing Product Security Incident Response Team (PSIRT) processes for R&D while delivering critical security architecture artifacts, including Global System View, Multi-Patient Harm View, Updateability/Patchability View, and Security Use Case View. The ideal candidate will drive proactive risk mitigation, ensure compliance with regulatory standards, and enhance the security posture of medical systems as well as cloud systems with patient safety as a core priority.
Key Responsibilities:
1. Security Architecture Development
- Develop and maintain comprehensive architecture and artifacts for multiple device platforms with the help of respective platform R&D team:
- Global System View: High-level design illustrating interconnected systems and data flows.
- Multi-Patient Harm View: Analyze and mitigate potential security threats leading to risks for multiple patients.
- Updateability/Patchability View: Ensure systems support secure and timely updates/patches to address vulnerabilities.
- Security Use Case View: Define security requirements and controls based on specific use cases and threat models.
- Collaborate with cross-functional teams (Product, DevOps, IT, Regulatory) to integrate security into the product lifecycle.
2. Product Security Incident Response Team (PSIRT)
- Lead the PSIRT process for R&D alongside PSIRT lead for IT, ensuring swift response and mitigation of product vulnerabilities.
- Establish incident playbooks and coordinate root cause analysis (RCA) for reported security incidents.
- Work with engineering teams to implement fixes and ensure long-term improvements.
3. Risk Assessment & Compliance
- Perform risk analyses to evaluate security threats, especially those with potential impacts on patient safety.
- Ensure compliance with FDA cybersecurity guidelines, including premarket and postmarket regulatory expectations.
- Collaborate with Quality and Regulatory teams to provide security input for FDA submissions and audits.
4. System Updateability & Patchability