Cybersecurity Engineer, DiGA – Contract

Security EngineerSecurity EngineerContractRemoteTeam 51-200H1B No SponsorCompany SiteLinkedIn

Location

New York

Posted

47 days ago

Salary

$125 - $135 / hour

English

Job Description

• Requirement Engineering: Translate German regulatory requirements (SGB V, DiGAV Annex 1) into actionable technical security specifications for the development team. • Penetration Testing Coordination: Define the scope for mandatory white-box penetration tests and manual code reviews; manage the relationship with BSI-certified testing centers. • Risk Assessment: Conduct and document data protection impact assessments (DPIA) and security risk assessments tailored to high-protection health data. • Vulnerability Management: Establish a lifecycle process for vulnerability handling and incident reporting as required by the EU Cyber Resilience Act (CRA) and DiGA guidelines.

Job Requirements

  • DiGA Expertise: Proven experience in a successful DiGA submission process or deep familiarity with the BfArM Guide for Manufacturers.
  • Regulatory Knowledge: Deep understanding of German and EU regulations, including GDPR, DiGAV, and the Digital Healthcare Modernisation Act (DVPMG).
  • Technical Security: Strong background in OWASP Top 10 (Mobile/Web), secure API design, and cryptographic standards (AES-256, TLS 1.3).
  • Certifications: Professional certifications such as CISSP, CISA, or ISO 27001 Lead Implementer are highly preferred.
  • Fluency in English is required.

Benefits

  • Your choice of mac or linux equipment.

Related Categories

Related Job Pages

More Security Engineer Jobs

Information Security Member

Anchorage Digital

Trusted institutional partner in crypto and first federally chartered crypto bank

Security Engineer47 days ago
Full TimeRemoteTeam 201-500Since 2017H1B Sponsor

Member of Global Information & Security Team at Anchorage Digital

Cloud
United States

Security Architect

CrowdStrike

CrowdStrike has redefined security with the world’s most advanced cloud-native platform that protects and enables the people, processes and technologies that drive modern enterprise. Tested and proven, the world's largest organizations trust CrowdStrike to stop breaches with unparalleled protection against the most sophisticated cyberattacks. The CrowdStrike culture has been built upon our Core Values since the day we began. We are Fanatical About the Customer, Relentlessly Focused on Innovation and believe that our Limitless Passion drives Unlimited Potential for every CrowdStriker. As a purpose-built remote-first company, we believe cultivating a connected culture for every employee, no matter where they are in the world, is a key ingredient in building a high-performing, diverse team. We don’t have a mission statement. We’re on a mission—to stop breaches. Ready to join a mission that matters?

Security Engineer47 days ago
Full TimeRemoteTeam 5,001-10,000Since 2011H1B Sponsor

Security Architect improving cybersecurity for CrowdStrike's advanced platform

AWSCloudCyber SecurityGoogle Cloud Platform
United States

Security and GRC Manager

Bitcoin Depot

Bringing Bitcoin to the Masses

Security Engineer47 days ago
Full TimeRemoteTeam 51-200Since 2016H1B No Sponsor

Security and GRC Manager leading security policies at Bitcoin Depot

AWSCloudCyber SecurityFirewallsGoogle Cloud PlatformLinux
United States

Lead Penetration Tester

Rhymetec

Premium cybersecurity, compliance and privacy services for your business, because security is an essential.

Security Engineer47 days ago
Full TimeRemoteTeam 11-50Since 2015

The Lead Penetration Tester is an experienced offensive security professional who reports directly to the Director of Offensive Security. In this client-facing role, you will lead and execute penetration testing engagements for MSSP customers, serve as an escalation point for oth...

Penetration TestingWeb Application SecurityAPI SecurityNetwork SecurityManual ExploitationVulnerability AssessmentReport WritingAWSAzureGCP
United States