Product Cybersecurity Manager
📍 Staefa
Role and responsibilities
Integrate cybersecurity throughout the Secure Software Development Lifecycle (Secure SDLC) for connected medical devices, embedded software, mobile applications, and cloud services. Lead threat modeling activities, cybersecurity risk assessments, and mitigation planning together with global R&D teams. Partner with software engineering teams to embed security into development workflows, DevSecOps practices, and CI/CD pipelines. Coordinate product vulnerability management activities, including assessment, prioritization, remediation tracking, and post-market monitoring. Support regulatory submissions and quality processes by preparing cybersecurity documentation and evidence. Advise engineering, product management, quality, and regulatory teams on practical, risk-based cybersecurity decisions. Promote a security-first mindset by coaching teams, supporting security champions, and driving continuous improvement across R&D.
Team / description
At Sonova, we envision a world where everyone can enjoy the delight of hearing. This vision inspires us and fuels our commitment to developing innovative solutions that improve hearing health and human connection - from personal audio devices and wireless communication systems to hearing aids and cochlear implants. We're dedicated to providing outstanding customer experiences through our global audiological care services, ensuring that everyone has the opportunity to engage fully with the world around them. Guided by a culture of continuous improvement that fosters resilience and self-motivation, our team is united by a shared commitment to excellence and a deep sense of pride in our work, each of us playing a vital role in creating meaningful change. Here you’ll find a diverse range of opportunities that span both consumer and medical solutions and the freedom to shape your career while making an impact on the lives of others. Join us in our mission to create a more connected world, where every voice is heard and every story matters.
Qualifications and Skills
Bachelor's or Master's degree in Computer Science, Software Engineering, Engineering, or a related technical discipline (or equivalent practical experience).
5+ years of experience in software engineering, software architecture, product development, Secure SDLC, or a comparable software development environment.
At least 3 years of hands-on experience in product cybersecurity or application security.
Strong understanding of Secure Software Development Lifecycle (Secure SDLC) and how cybersecurity integrates into modern software development.
Experience working closely with software development teams throughout the product lifecycle.
Excellent communication skills with the ability to explain complex security topics to both technical and non-technical stakeholders.
Professional working proficiency in English.
Experience developing software for medical devices or other regulated industries (Nice to have).
Experience with DevSecOps and security integration into CI/CD pipelines (Nice to have).
Knowledge of cybersecurity standards and regulations such as IEC 81001-5-1, IEC 62304, ISO 14971, MDR, FDA, GDPR, CRA or similar frameworks (Nice to have).
Security certifications such as CISSP, CSSLP, GIAC, or equivalent (Nice to have).
Experience with cloud security, cryptography, authentication technologies, or software supply chain security (Nice to have).
Familiarity with Privacy by Design principles, AI agent security, and AI-supported development environments (Nice to have).