Full-Time

Product Security Engineer

m/f/d

Posted on 8/31/2025

Deadline 12/1/25
Fresenius Medical Care

Fresenius Medical Care

11-50 employees

Operates dialysis facilities and renal care

No salary listed

Frankfurt, Germany

In Person

Category
IT & Security (1)
Required Skills
Software Testing
Risk Management
Requirements
  • Bachelor's degree in Computer Science, Information Technology or a similar field of specialization
  • Minimum 5 years of professional experience in IT Security, cybersecurity (e.g. embedded systems, risk management, regulatory requirements) with in-depth knowledge of enabling technologies and technical solutions in the field of cybersecurity
  • Knowledge of relevant cybersecurity regulations and guidelines (FDA pre-market and post-market guidance, section 2.4b CFR, IEC 81001-5-1, IEC 62443-4-1, JSP 2.0)
  • Knowledge of R&D related processes and methodologies (e.g. cybersecurity, product risk management, etc.)
  • Knowledge of software testing and software development tools
  • High engagement on achieving the targets and on the objectives of the position, proactive and solution-oriented approach towards problems, ability to work cross functional with all levels of employees
  • Fluent in English in written and spoken; German language is a plus
Responsibilities
  • Provide hands-on security engineering support across the Water Systems product family, including embedded controllers, IoT components, and connected digital services
  • Partner with R&D to integrate cybersecurity controls early in the development lifecycle, including, but not limited to secure boot, encrypted communication, and access control mechanisms
  • Perform security design reviews, support code-level mitigation efforts, and contribute to validation of security features for WTS products and related platforms
  • Serve as the technical point of contact for security topics related to WTS products, connectivity modules, and system interfaces
  • Contribute to the operational execution of the Product Security Program within the assigned portfolio, ensuring alignment with internal frameworks and regulatory requirements (e.g., FDA, MDR, IEC 81001-5-1)
  • Support vulnerability handling and coordinated disclosure processes, including triage, remediation tracking, and external communication preparation
  • Participate in post-market surveillance of cybersecurity issues, including analysis of incidents and integration of lessons learned into the development process
  • Maintain product-specific cybersecurity documentation, metrics, and audit-ready records
  • Develop and maintain cybersecurity plans (e.g., Cybersecurity Management Plan) throughout the product lifecycle
  • Perform or support threat modeling, attack surface analysis, and cybersecurity risk assessments in accordance with regulatory expectations and internal documentation
  • Assist in defining risk mitigations and evaluating residual risks to support design decisions and regulatory justifications
  • Contribute security input to product roadmaps, change impact assessments, and submission dossiers
  • Participation in medical device cybersecurity events/conferences
Desired Qualifications
  • Ideally experience in R&D in medical devices or other regulated industries (medical, automotive, defensive systems, nautical, avionics)
  • Experience in embedded systems development is an advantage
  • Knowledge of relevant software quality regulations and guidelines such as IEC 62403, IEC 82304 is an advantage
  • Knowledge of cybersecurity relevant tools (e.g. Microsoft Threat Modelling Tool, Binary Analysis Tools, Static code analyzers, system hardening tools, Kali Linux)
  • Knowledge of medical device field and application
Fresenius Medical Care

Fresenius Medical Care

View

Fresenius Medical Care North America runs a network of dialysis facilities and outpatient labs to deliver coordinated kidney care for hundreds of thousands of patients. It also offers specialty pharmacy and laboratory services and manufactures a wide range of dialysis equipment, disposables, and renal drugs. The company treats patients by providing dialysis and related care at its clinics, supported by the equipment, supplies, and medicines it develops and distributes. FMCNA differentiates itself through its size and integration as the world's largest fully integrated renal company, with a nationwide network covering care delivery, drugs, labs, and manufacturing, aiming to provide high-quality, convenient access to comprehensive services across North America.

Company Size

11-50

Company Stage

Late Stage VC

Total Funding

$40.2M

Headquarters

Waltham, Massachusetts

Founded

1996

Simplify Jobs

Simplify's Take

What believers are saying

  • $130k Mississippi grant funds VR for rural home dialysis patient education.
  • NxStage System One adopted by top U.S. hospitals for acute renal therapy.
  • Speedswap enables quick filter changes, reducing downtime and nursing workloads.

What critics are saying

  • NxStage Speedswap recall causes blood leaks, triggering lawsuits in 3-6 months.
  • DaVita expands low-cost home dialysis, eroding NxStage share in 12-18 months.
  • 6.4TB data breach on February 5, 2026, exposes patient records to 0APT.

What makes Fresenius Medical Care unique

  • FMCNA operates world's largest integrated renal care network with dialysis facilities.
  • FMCNA manufactures comprehensive dialysis equipment, disposables, and renal pharmaceuticals.
  • FMCNA provides specialty pharmacy and laboratory services for chronic conditions.

Help us improve and share your feedback! Did you find this helpful?

Benefits

Professional Development Budget

Conference Attendance Budget

Flexible Work Hours

Growth & Insights and Company News

Headcount

6 month growth

0%

1 year growth

0%

2 year growth

0%
Business Wire
Mar 28th, 2024
Compsych Corporation Announces 2023 Health At Work Award Winners

CHICAGO--(BUSINESS WIRE)--ComPsych® Corporation, the world’s largest provider of mental health services and GuidanceResources® for life, today announced the honorees of the 2023 Health at Work Awards. Now in its 19th year, the ComPsych Health at Work Awards recognize organizations across a variety of sizes, industries and locations who have prioritized the health and well-being of their employees by providing innovative, multi-platform programs. “We’re thrilled to honor these stellar organizations for the investment they’ve made in building cultures that value employee mental health and wellness,” said Dr. Richard A. Chaifetz, Founder, Chairman and CEO of ComPsych. “In recent years we’ve seen a rise in anxiety as well as people needing to take leaves of absence due to mental health challenges across the workforce

Securities and Exchange Commission
Feb 12th, 2024
SEC FORM D

The Securities and Exchange Commission has not necessarily reviewed the information in this filing and has not determined if it is accurate and complete.The reader should not assume that the information is accurate and complete.

Securities and Exchange Commission
Feb 12th, 2024
SEC FORM D

The Securities and Exchange Commission has not necessarily reviewed the information in this filing and has not determined if it is accurate and complete.The reader should not assume that the information is accurate and complete.

Securities and Exchange Commission
Dec 6th, 2023
SEC FORM D

The Securities and Exchange Commission has not necessarily reviewed the information in this filing and has not determined if it is accurate and complete.The reader should not assume that the information is accurate and complete.

Home Health Provider.com
Feb 17th, 2023
Improving Access & Timely Care For Vulnerable Patients Referred To Home Health Via Telehealth Physician Support

Royal Philips (NYSE: PHG AEX: PHIA), a global leader in health technology, today announced the debut of its eCareManager 4.1 enterprise telehealth software at the American Telemedicine...

INACTIVE