Cybersecurity and Compliance Lead
Boost your chances before you apply.
Myriad Genetics
Salt Lake City, UT, US
Summary
The role serves as a technical subject matter expert for product cybersecurity, leading threat modeling, risk assessments, and secure development framework activities. It also involves partnering with cross-functional teams to ensure regulatory compliance and support cybersecurity evidence generation for submissions.
Job Description
Overview
The Product Cybersecurity and Compliance Lead serves as the technical subject matter expert for product cybersecurity and regulatory cybersecurity compliance initiatives. The role partners with the Director of Information Security, Product Development, Engineering, Regulatory Affairs, and Quality teams to integrate cybersecurity into the product lifecycle and support regulatory submissions requiring cybersecurity evidence and documentation.
This role provides technical leadership for Secure Product Development Framework (SPDF) activities, threat modeling, architecture reviews, cybersecurity risk assessments, and compliance initiatives. The position also coordinates cybersecurity workstreams, supports regulatory and product teams, and helps establish sustainable cybersecurity practices across regulated product programs.
Responsibilities
Product Cybersecurity Leadership
- Provide cybersecurity guidance for FDA, PMDA, IVDR, and related regulatory requirements.
- Lead threat modeling, security architecture reviews, and SPDF activities.
- Promote security-by-design practices throughout the product lifecycle.
- Provide cybersecurity input for new products, enhancements, and regulatory submissions.
- Partner with the Director of Information Security to mature product cybersecurity capabilities.
Cybersecurity Compliance
-
Partner with Regulatory Affairs, Quality, Product, and Engineering teams on cybersecurity compliance initiatives.
- Support development of cybersecurity evidence and documentation for regulatory submissions.
- Translate cybersecurity regulations and standards into technical requirements.
- Participate in audits, assessments, and remediation activities.
- Maintain cybersecurity compliance documentation and supporting artifacts.
Security Assessments & Risk Management
- Conduct product cybersecurity risk assessments and threat analyses.
- Review software supply chain security controls and contribute to SBOM processes.
- Coordinate vulnerability assessments, penetration testing, and remediation efforts.
- Support cybersecurity risk management documentation and evidence generation.
- Review product architectures and designs for cybersecurity risks.
- Serve as a technical SME for product cybersecurity activities across regulated products.
Cross-Functional Coordination & Execution
- Coordinate cybersecurity workstreams across Product, Engineering, QA, Regulatory Affairs, IT, and Information Security.
- Track cybersecurity deliverables, dependencies, and regulatory milestones.
- Facilitate technical reviews, threat modeling sessions, and cybersecurity working meetings.
- Identify risks, blockers, and resource constraints affecting deliverables.
- Support cybersecurity roadmap planning and execution.
- Security Architecture & Consultation
- Advise teams on secure design principles and secure development practices.
- Review application, cloud, infrastructure, and system designs.
- Recommend cybersecurity controls aligned with regulatory and business requirements.
- Support implementation of secure development and data protection practices.
- Help establish repeatable cybersecurity practices across product development teams.
Required Qualifications
- 7+ years of cybersecurity, application security, or product security experience.
- Experience supporting software development or product engineering organizations.
- Experience with threat modeling, architecture reviews, and secure SDLC practices.
- Experience conducting product cybersecurity risk assessments.
- Experience supporting regulated products or regulated software development environments.
- Strong communication and stakeholder management skills.
- Ability to lead cross-functional initiatives without direct authority.
Preferred Qualifications
- Experience with medical device, diagnostics, biotechnology, healthcare, or other regulated products.
- Experience supporting cybersecurity components of regulatory submissions.
- Experience with SBOM management and software supply chain security.
- Experience with HITRUST, ISO 27001, NIST CSF, or similar security frameworks.
- CISSP, CCSP, CSSLP, CISM, AWS Security Specialty, GIAC, or equivalent cybersecurity certifications.
Required
- U.S. citizen or national
- Green Card holder
- Living full time in the USA
We take geographic location into account when determining base salary to ensure equitable and competitive compensation.
Physical Requirements
Use of equipment and tools necessary to perform essential job functions.
#LI-KO1
Ready to transform the future of patient care through the power of genetics?
For more than 30 years, Myriad Genetics has led the way in precision medicine by delivering important insights to help people make informed health decisions. As a leading molecular diagnostic testing and precision medicine company, we are dedicated to advancing health and well-being for all. Our innovative genetic tests are used across specialties including oncology, women’s health, and mental health, empowering clinicians to personalize treatment and help their patients take proactive steps toward better outcomes.
What inspires us – and you – is simple: Every test, every insight, and every patient story emphasizes our commitment to improving lives through science, innovation, and care. you’re ready to help shape the future of medicine. Your work will have meaningful impact, and your dedication can change lives. Learn more at https://www.myriad.com and follow Myriad Genetics on LinkedIn.
We are an equal opportunity employer and place high value on inclusion and belonging. We prohibit discrimination and harassment on the basis of any protected characteristic, including race, religion, color, national origin, gender, sexual orientation, gender identity, gender expression, age, marital or veteran status, pregnancy or disability, or any other basis protected under applicable law. In accordance with applicable law, we make reasonable accommodations for applicants’ and employees’ religious practices and beliefs, as well as any mental health or physical disability needs. If you need assistance submitting your application due to a disability, you can request an accommodation by contacting [email protected].
Please answer all questions completely. Please do not provide any information not specifically requested on this Employment Application form. To get the best candidate experience, please consider applying for a maximum of 3 roles within 12 months to ensure you are not duplicating efforts.
Myriad Genetics will never request payment, solicit personal financial information, or conduct interviews via informal channels (e.g., personal email, text messages). All opportunity-related communication with Myriad Genetics will come from our employees, whose e-mail addresses end with "@myriad.com."
Myriad Genetics is a leading molecular diagnostic testing and precision medicine company dedicated to advancing health and well-being for all. Myriad Genetics develops and offers molecular tests that help assess the risk of developing disease or disease progression and guide treatment decisions across medical specialties where molecular insights can significantly improve patient care and lower healthcare costs.
Founded
1991
Company size
1,001-5,000 employees
Industry
Biotechnology Research
Org type
Public Company
Headquarters
Salt Lake City, Utah
Myriad Genetics is a leading molecular diagnostic testing and precision medicine company dedicated to advancing health and well-being for all. Myriad Genetics develops and offers molecular tests that help assess the risk of developing disease or disease progression and guide treatment decisions across medical specialties where molecular insights can significantly improve patient care and lower healthcare costs.
Founded
1991
Company size
1,001-5,000 employees
Industry
Biotechnology Research
Org type
Public Company
Headquarters
Salt Lake City, Utah