Manager/Sr. Manager - Application Security

Sunnyvale, California

Company Description

At Intuitive, we are united behind our mission: we believe that minimally invasive care is life-enhancing care. Through ingenuity and intelligent technology, we expand the potential of physicians to heal without constraints.

As a pioneer and market leader in robotic-assisted surgery, we strive to foster an inclusive and diverse team, committed to making a difference. For more than 25 years, we have worked with hospitals and care teams around the world to help solve some of healthcare's hardest challenges and advance what is possible.

Intuitive has been built by the efforts of great people from diverse backgrounds. We believe great ideas can come from anywhere. We strive to foster an inclusive culture built around diversity of thought and mutual respect. We lead with inclusion and empower our team members to do their best work as their most authentic selves.

Passionate people who want to make a difference drive our culture. Our team members are grounded in integrity, have a strong capacity to learn, the energy to get things done, and bring diverse, real world experiences to help us think in new ways. We actively invest in our team members to support their long-term growth so they can continue to advance our mission and achieve their highest potential.

Join a team committed to taking big leaps forward for a global community of healthcare professionals and their patients. Together, let's advance the world of minimally invasive care.

Job Description

Primary Function of Position:

The Product Security Operations Team is responsible for software products, infrastructure, cloud services, and IoMT solutions that collect and analyze medical device machine data from thousands of systems deployed world-wide.

The ideal candidate for the position of Manager/Sr. Manager- Application Security will have proven experience working in web and mobile application development, application security testing, threat modeling, vulnerability management, and product security management.

This position requires a candidate with strong cybersecurity, technical, and interpersonal skills. The ability to work effectively and collaboratively with the business, pre-market cybersecurity, peer Engineering teams, and across business units to deliver high quality solutions that ensure patient safety and data/system security.

Roles and Responsibilities:

  • Serves as a leader in Product Security team, manage team of application security engineers and support team's mission by performing application security testing, threat modeling and support engineering teams
  • Lead penetration testing, secure code reviews and threat modeling efforts for applications, support vulnerability management and incident response as required
  • Perform security assessment, risk analysis, and report findings and recommend corrective actions
  • Lead application security tools integration into CI/CD pipeline and development lifecycle
  • Perform vendor security assessments and conduct security trainings for development teams
  • Provide technical leadership in design of complex systems and contribute to technical directions and strategic decisions
  • Develop metrics to assess, track and communicate progress, risks, and trends
  • Work with key stakeholders to architect, select, and implement security-first tools for application security engineering function
  • Prepare business and technical analysis
  • Ensures comprehensive, real time status updates and report to key stakeholders
  • Staying current with new and evolving security topics and technologies via formal trainings and self-directed education
  • Other duties as assigned


Skills, Experience, Education, & Training:

  • Minimum Five or more years' experience in web / mobile application development / testing / security
  • Deep understanding of application security risks (XSS/CSRF, SQL injection, etc.)
  • Hands-on experience with AWS technologies (EC2, VPC, EBS, ALB, RDS, S3, EKS, etc...)
  • Hands-on experience with AWS Security, Identity & Compliance services (Amazon GuardDuty, Amazon Inspector, AWS Security Hub, etc...)

  • Experience with secure code review in languages such as: Java, Python, C#, NodeJS, JavaScript
  • Proficient with SQL, stored procedures, and general database interaction
  • Passion for understanding and researching new vulnerabilities and exploitation techniques
  • Proficient in complex network design (firewalls, load-balancing, TLS, switching and routing)
  • Experience with application debug and troubleshooting, security logs, log aggregation and SIEM technologies
  • Practical knowledge of OWASP Top Ten, how to discover, triage, verify and resolve the issues
  • Knowledge of common security flaws and resolution as published by SANS, CWE, CVE, CVSS etc.
  • Understanding of application threat modeling, secure coding principles and SDLC security best practices
  • Expert level knowledge of TCP/IP, SSL/TLS, HTTP, switching and routing, Windows & Linux OS, Relational SQL databases
  • Extensive experience with Splunk, Syslog, Nessus, nMap, Metasploit, Nexpose and Qualys guard
  • CISSP, GCIA, GIAC, GISF, GSEC, SSCP, OSCP, OSWE or equivalent certification preferred.
  • Work constructively with highly technical peers when security best practices and feature requests intersect
  • Familiarity with common web application testing tools for DAST, SAST, SCA and IAST analysis such as Burp Suite, Checkmarx etc.
  • BS/BA desirable along with demonstration of sophisticated and logical thought processes.
  • Strong analytic skills as proven by a track record of analyzing and fixing complex problems in products and processes.
  • Excellent judgment in the presence of competing priorities and incomplete data; proven ability to make difficult trade-offs with good judgment.
  • Strong written and verbal communication skills and experience in working effectively in cross-functional teams
  • Excellent judgement in the presence of competing priorities and incomplete data; proven ability to make difficult trade-offs with good judgement
  • B.S in Computer Science or related technical major, or commensurate experience
  • Ability to present and whiteboard technical architectures and workflows
  • A strong desire to make work fun.
  • Travel: 10~20%
  • Job location: Sunnyvale, CA

Additional Information

Due to the nature of our business and the role, please note that Intuitive and/or your customer(s) may require that you show current proof of vaccination against certain diseases including COVID-19. Details can vary by role.

Intuitive is an Equal Employment Opportunity Employer. We provide equal employment opportunities to all qualified applicants and employees, and prohibit discrimination and harassment of any type, without regard to race, sex, pregnancy, sexual orientation, gender identity, national origin, color, age, religion, protected veteran or disability status, genetic information or any other status protected under federal, state, or local applicable laws.

We will consider for employment qualified applicants with arrest and conviction records in accordance with fair chance laws.

Shift : Day

Travel : 10% of the time

Travel Requirements:10% of the time Shift:Day

Senior Inclusion Jobs

Gain Access

Add Your Resume

Add your resume to our resume database that can be searched by employers looking to hire!

Job Alerts

Stay up to date with job alerts! Customize your alerts based on a specific area, category and receive weekly updates!

Sign up now to gain access!

More Manufacturing and Production jobs

Asahi Kasei
Concord, North Carolina
Posted 29 minutes ago
Asahi Kasei
Owensboro, Kentucky
Posted 29 minutes ago
Houston, Texas
Posted 24 minutes ago
View Manufacturing and Production jobs ยป

Share Inclusion Job

Manager/Sr. Manager - Application Security is also posted to sites within our Inclusion Job Network.

Disability inclusion jobs logo
Asian inclusion jobs logo
Black inclusion jobs logo
Diversity inclusion jobs logo
LGBTQ inclusion jobs logo
Seniors inclusion jobs logo
Women inclusion jobs logo
Hispanic inclusion jobs logo