Lead IT Security Engineer @CONMED Corporation
All Others
Salary usd 104,134 - 1..
Remote Location
🇺🇸 USA Only
Employment Type full-time
Posted 1mth ago

[Hiring] Lead IT Security Engineer @CONMED Corporation

1mth ago - CONMED Corporation is hiring a remote Lead IT Security Engineer. 💸 Salary: usd 104,134 - 163,640 per year 📍Location: USA

Role Description

The Lead Information Security Engineer is a senior cybersecurity leader responsible for protecting the organization’s digital ecosystem across product development, manufacturing, and enterprise IT systems. This role ensures the security of connected medical/surgical devices, intellectual property, and regulated environments, while maintaining compliance with cybersecurity guidance, ISO standards, and global regulations. This position plays a critical role in enabling secure product innovation, patient safety, and operational resilience across the device lifecycle.

This REMOTE opportunity is not eligible for employer-visa sponsorship.

Key Responsibilities:

  • Security Operations & Incident Response
    • Lead detection and response for incidents affecting: manufacturing systems (OT/ICS), connected medical/surgical devices, and enterprise IT environments.
    • Manage SOC operations with prioritization of IT security, production integrity, and supply chain impact.
    • Investigate and respond to incidents involving intellectual property theft, disruptions and/or ransomware affecting production lines, and IT vulnerabilities.
    • Lead regulatory-aligned incident handling and disclosure (local/global authorities).
  • Production & IT Security (Critical Focus Area)
    • Partner with IT, production, and engineering to embed secure-by-design principles across the IT & product lifecycle.
    • Conduct threat modeling and security risk assessments for surgical and medical devices.
    • Support compliance with IT security guidance, SOX, ISO27001 & EU GDPR / NIS2.
    • Identify and remediate product vulnerabilities (secure firmware, APIs, connectivity).
    • Support coordinated vulnerability disclosure (CVD) processes.
  • Manufacturing & Operational Technology (OT) Security
    • Secure manufacturing environments (plants, production lines, robotics, control systems).
    • Implement segmentation between IT and OT networks.
    • Lead vulnerability and patch management for industrial control systems.
    • Reduce risk to production continuity and product integrity.
  • Threat & Vulnerability Management
    • Monitor threat landscape with emphasis on nation-state attacks targeting IP, supply chain compromise, medical device exploitation.
    • Lead proactive threat hunting across cloud environments, OT/manufacturing systems, & product telemetry (if applicable).
    • Drive enterprise-wide vulnerability management with prioritization based on patient and product impact.
  • Security Engineering & Architecture
    • Implement Zero Trust principles across corporate IT and manufacturing environments.
    • Drive consolidation and optimization of SIEM/XDR (Sentinel, Defender, etc.), identity platforms (Entra ID, PAM), data protection tools (DLP, encryption for IP and regulated data).
    • Secure cloud platforms supporting R&D, analytics, and digital health capabilities.
  • Regulatory Compliance & Risk Management
    • Ensure alignment with SOX, ISO 27001, NIST CSF / NIST 800-53 & Global data protection regulations (GDPR where applicable).
    • Lead cyber risk assessments tied to patient safety, product risk, and regulatory exposure.
    • Support internal and external audits and regulatory inspections.
    • Translate cybersecurity risk into business impact (recalls, production disruption, liability).
  • Data Protection & Intellectual Property Security
    • Protect sensitive data, designs, and trade secrets.
    • Implement controls for secure collaboration with third-party manufacturers and partners and data encryption and access governance.
    • Monitor for data exfiltration and insider threats.
  • Leadership & Mentorship
    • Provide technical leadership across security operations and engineering functions.
    • Mentor analysts and engineers on IT/OT security, production security, and incident response in regulated environments.
    • Act as escalation point for high-impact security events affecting products or manufacturing.
  • Stakeholder Collaboration
    • Partner with CIO, CISO, and Chief Product/Engineering Officers, Quality & Regulatory Affairs, Manufacturing / Plant leadership & Legal and Compliance teams.
    • Communicate cybersecurity risks in terms of IT security & safety, regulatory impact and revenue / production risk.

Qualifications

  • Bachelor’s degree in Cybersecurity, Engineering, IT, or related field (or equivalent experience).
  • 5+ years of experience in cybersecurity, with exposure to regulated industries or manufacturing environments, with hands-on experience with SIEM/XDR platforms, endpoint, network, and cloud security and/or vulnerability and incident response programs.

Requirements

  • Strong knowledge of Security frameworks (NIST, ISO 27001), Identity and access management & network segmentation and Zero Trust principles.
  • Experience in medical device, healthcare technology, or manufacturing (OT/ICS).
  • Familiarity with ISO27001, NIS2, SOX, NIST CF 800-53, & EU GDPR.
  • Preferred Certifications: CISSP, CEH, GIAC & GICSP (Industrial Control Systems) or HCISPP (strong plus).
  • Experience with IT/Production security testing, Threat modeling (e.g., STRIDE), Secure SDLC practices.

Benefits

  • Competitive compensation.
  • Excellent healthcare including medical, dental, vision and prescription coverage.
  • Short & long term disability plus life insurance -- cost paid fully by CONMED.
  • Retirement Savings Plan (401K) -- CONMED matches your contributions dollar for dollar, with the potential for up to 7% per pay period.
  • Employee Stock Purchase Plan -- allows stock purchases at discounted price.
  • Tuition assistance for undergraduate and graduate level courses.
Before You Apply
️
🇺🇸 Be aware of the location restriction for this remote position: USA Only
‼ Beware of scams! When applying for jobs, you should NEVER have to pay anything. Learn more.
Lead IT Security Engineer @CONMED Corporation
All Others
Salary usd 104,134 - 1..
Remote Location
🇺🇸 USA Only
Employment Type full-time
Posted 1mth ago
Apply for this position
Did not apply ✓
Applied ✓
Sent Follow-Up ✓
Interview Scheduled ✓
Interview Completed ✓
Offer Accepted ✓
Offer Declined ✓
Application Denied ✓
Unlock 125,000+ Remote Jobs
️
🇺🇸 Be aware of the location restriction for this remote position: USA Only
‼ Beware of scams! When applying for jobs, you should NEVER have to pay anything. Learn more.
Apply for this position
Did not apply ✓
Applied ✓
Sent Follow-Up ✓
Interview Scheduled ✓
Interview Completed ✓
Offer Accepted ✓
Offer Declined ✓
Application Denied ✓
Unlock 125,000+ Remote Jobs
×
Apply to the best remote jobs
before everyone else

Access 125,000+ vetted remote jobs and get daily alerts.

4.9 ★★★★★ from 500+ reviews

⚡ 126,991+ remote jobs, refreshed hourly

🔔 Real-time alerts: Apply first, direct to employer

🛡️ Vetted companies, no scams, true remote only

Unlock All Jobs Now

Maybe later