Cybersecurity Engineer

Guatemala, Guatemala (Hybrid)

At HTEC, we build innovative healthcare and medical technology solutions that improve lives and solve complex engineering challenges. We are looking for an experienced Cybersecurity Engineer to join our Infrastructure and DevOps organization and help ensure our products remain secure, compliant, and resilient throughout the entire software development lifecycle. 

This is a highly hands-on engineering role focused on DevSecOps practices, cloud security, container security, and secure software delivery. You will work closely with software engineers, DevOps specialists, architects, quality teams, and regulatory experts to implement and continuously improve security controls across development, deployment, and operational environments. 

The role operates within a Class II Medical Device environment, where cybersecurity is a critical product requirement. Practical experience applying FDA cybersecurity guidance, IEC 81001-5-1, and modern secure development practices to medical device products is highly valued. 

 

What you'll do

  • Design, implement, and maintain security controls across cloud infrastructure, applications, CI/CD pipelines, and deployment environments. 

  • Lead security initiatives throughout the medical device development lifecycle, ensuring alignment with regulatory and industry security requirements. 

  • Build and enhance DevSecOps practices by integrating security testing and validation into engineering workflows. 

  • Secure containerized workloads and Kubernetes environments through runtime protection, RBAC governance, image scanning, and secrets management. 

  • Perform threat modeling, vulnerability assessments, penetration testing, and security reviews to identify and mitigate risks. 

  • Implement security tooling and automation for continuous monitoring, vulnerability management, and compliance enforcement. 

  • Partner with engineering, DevOps, quality assurance, regulatory affairs, and product teams to address cybersecurity risks and requirements. 

  • Develop and maintain cybersecurity documentation, risk assessments, security reports, and regulatory support artifacts. 

  • Drive security best practices across engineering teams and foster a security-first mindset throughout product development. 

  • Support compliance initiatives related to security frameworks and regulated healthcare environments. 

 

What we're looking for

Required qualifications

  • 5+ years of experience in cybersecurity engineering, DevSecOps, cloud security, or related field. 

  • Hands-on experience securing cloud platforms, preferably AWS, Microsoft Azure experience, also considered highly relevant. 

  • Strong knowledge of cybersecurity principles, including:  

  • Cryptography 

  • Authentication and authorization 

  • Network security 

  • Secure communications 

  • Data protection and privacy 

  • Practical experience securing:  

  • Kubernetes environments 

  • Containerized applications 

  • Cloud-native platforms 

  • Experience implementing security controls across CI/CD pipelines, including:  

  • SAST 

  • SCA 

  • DAST 

  • Secret scanning 

  • Pipeline security controls 

  • Strong understanding of:  

  • Vulnerability management 

  • Security architecture 

  • Risk assessment 

  • Threat modeling 

  • Experience working with at least one recognized security framework such as:  

  • SOC 2 

  • ISO 27001 

  • NIST 800-53 

  • HITRUST 

  • Strong verbal and written English communication skills. 

 

Preferred qualifications

  • Experience with FedRAMP implementation programs

  • Hands-on experience with medical device cybersecurity and regulated healthcare environments. 

  • Practical knowledge of:  

  • FDA Premarket Cybersecurity Guidance 

  • FDA Postmarket Cybersecurity Guidance 

  • IEC 81001-5-1 

  • IEC 62304 

  • ISO 14971 

  • Experience creating and maintaining Software Bills of Materials (SBOMs)

  • Working knowledge of threat modeling methodologies such as:  

  • STRIDE 

  • PASTA 

  • OCTAVE 

  • Strong understanding of Android security architecture and mobile application security. 

 

Technologies and tools

Experience with one or more of the following technologies is highly desirable: 

  • Wiz 

  • Prisma Cloud 

  • Snyk 

  • Aqua Security 

  • Falco 

  • Trivy 

  • HashiCorp Vault 

  • CrowdStrike 

  • Kubernetes 

  • Docker 

  • Azure Security Services 

  • GitHub Actions 

  • Azure DevOps 

  • Terraform 

 

Nice to have

  • CISSP, CISA, OSCP, CSSLP, GIAC, or similar cybersecurity certifications. 

  • Experience securing connected healthcare, IoT, or embedded systems. 

  • Knowledge of secure boot, device identity management, OTA update security, and supply chain security practices. 

  • Experience supporting cybersecurity audits, regulatory submissions, and security compliance initiatives. 

  • Background in highly regulated industries such as healthcare, life sciences, medical devices, or digital health. 

 

Why join HTEC?

At HTEC, you'll work on meaningful healthcare technologies alongside world-class engineers, architects, and product teams. You'll have the opportunity to solve complex cybersecurity challenges in regulated environments, shape security practices across modern cloud-native platforms, and contribute to products that have a real-world impact on patient care and outcomes. 

 

Cybersecurity Engineer

Job description

Cybersecurity Engineer

Personal information