FREE ACCESS
5,000–10,000 jobs/day
See all jobs on Scoutfield
Search thousands of fresh jobs every day.
Discover
- Fresh listings
- Fast filters
- No subscription required
Create a free account and start exploring right away.
Core Competencies
Role fitCore Competencies
Use this summary to align your resume positioning with the role.
Demonstrates expertise in building and managing security programs, including vulnerability management and compliance with ISO 27001 and C5 standards. Proficient in addressing regulatory requirements and developing security documentation, with a focus on AI security in healthcare environments.
Highest-signal resume keywords
Security Program OwnershipISO 27001 ComplianceVulnerability ManagementAI Security ExpertiseHealthcare Security Experience
ATS Keywords
Tailor your resumeApplicant Tracking System Keywords
Tip: use these terms in your resume and cover letter to boost ATS matches.
Hard Skills
Security EngineeringVulnerability ScanningPenetration TestingControl DesignIncident ResponseThreat MonitoringDependency ManagementRegulatory ComplianceTechnical WritingAI Security
Soft Skills
CommunicationCollaborationCuriosity
Tools & Technologies
HSMAI-Assisted ToolsSecurity Documentation Tools
Certifications & Qualifications
OSCPCISSP
Industry Keywords
HealthcareRegulated DomainEU Cyber Resilience ActClass IIa Medical DeviceISO 27001C5SOC 2
About the role
Key responsibilities & impact- Serve as the first dedicated security engineer and senior individual contributor
- Act as Deputy CISO, report to the Director of Technology, and build security engineering from scratch
- Build and own the security program, tooling, and customer-facing security narrative
- Manage vulnerabilities across repositories, including scanning, dependency updates, remediation processes, and closure of findings
- Partner with Platform on security-sensitive infrastructure decisions, including customer-managed keys and HSM options
- Design controls and support assessments for ISO 27001 and C5
- Develop the security case for a potential Class IIa medical device under MDR
- Scope and follow up on penetration tests
- Address regulatory requirements such as the EU Cyber Resilience Act
- Create reusable customer security documentation, evidence, and AI-assisted questionnaires
- Participate in hospital CISO calls regarding AI architecture
- Establish incident response processes, runbooks, escalation, and appropriately sized on-call arrangements
- Monitor the threat landscape and translate emerging threats into concrete company-wide security actions
- Set security baselines for devices and accounts applied by IT
- Address AI security areas including agent sandboxing, prompt injection, voice data, and computer-use automation in hospitals
Requirements
What you’ll need- 6+ years across software and security engineering
- Experience owning a security program or a significant part of one
- Technical counterpart through at least one ISO 27001, C5, or SOC 2 certification cycle
- Experience designing controls, facing an auditor, and writing the technical side of a Statement of Applicability
- Experience running vulnerability management, including scanners, dependency bots, triage, and remediation follow-through
- Close familiarity with the security landscape, including advisories and incident write-ups
- Curiosity about AI security, including agents, sandboxing, and data flows
- Ability to communicate with engineers, auditors, and hospital security teams in English
- German language skills are nice to have
- Experience in healthcare or another regulated domain is nice to have
- Offensive security experience is nice to have
- Security certifications such as OSCP or CISSP are nice to have
- Legal authorization to work in Germany/the EU
Benefits
Comp & perks- Purposeful work with a positive impact on patients, their families, and healthcare professionals
- Flat hierarchies and strong team dynamics
- Flexible working hours
- Remote-friendly work arrangement
- Workations possible by arrangement
- Edenred card
- Extra vacation day for the employee's birthday
- Professional growth opportunities
