Overview
A MedTech organization is seeking a Legal Counsel specializing in Product Security and Cybersecurity. This role provides legal support for enterprise cybersecurity, product security, and digital risk management. The position focuses on aligning legal strategy with cybersecurity regulations, secure product development, threat mitigation, and postmarket surveillance obligations. The Legal Counsel will collaborate closely with IT security, product development, compliance, and regulatory teams to ensure products and platforms meet legal and security standards.
Responsibilities
- Advise on cybersecurity laws, regulations, and frameworks including NIST standards (e.g., ISO 27001), FDA Premarket/Post-market Cybersecurity Guidance, and EU regulations such as the Cyber Resilience Act.
- Support incident and breach response protocols across enterprise and product environments.
- Provide legal guidance for secure product development, software bills of materials (SBOMs), penetration testing, and vulnerability disclosure programs.
- Counsel on global product launch compliance, particularly regarding cybersecurity requirements embedded in MDR and U.S. FDA regulations.
- Draft and negotiate security-related contract provisions, including third-party security diligence and data breach terms.
- Collaborate with Product Security, R&D, Engineering, and IT on governance, risk, and compliance issues.
- Advise on cyber risk, breach response, and vulnerability disclosure involving both enterprise and product environments.
- Evaluate legal risks of product design choices such as remote connectivity, open-source software, and AI/ML explainability.
- Provide contract language for cybersecurity obligations, indemnification, and incident reporting.
- Partner with Product Security to define cyber clauses in supplier/vendor agreements and manage vulnerability disclosure programs (e.g., PSIRT).
- Align with data governance and retention practices.
Requirements
- Juris Doctor (JD) degree with a license to practice law in at least one relevant jurisdiction.
- Minimum of 10 years of professional legal experience in a law firm or corporate legal department, preferably with exposure to cybersecurity or technology-related legal matters.
- Experience in medical device, pharmaceutical, or life sciences sectors is strongly preferred.
- Familiarity with global cybersecurity standards and regulations in healthcare or critical infrastructure environments.
- Experience advising on incident response, secure development practices, or regulatory product submissions.
- Strong collaboration skills with both technical and legal stakeholders.
Compensation & Benefits
- Salary range: $179,100 - $388,100 plus eligibility for bonuses.
- Generally eligible for short-term and long-term financial incentives.
- Comprehensive health benefits including medical, prescription drug, dental, vision, critical illness, accident, and hospital indemnity insurance.
- Personalized healthcare support, wellbeing programs, and tobacco cessation programs.
- Financial benefits including Health Savings Account (HSA), Flexible Spending Accounts (FSAs), 401(k) plan, Employee Stock Purchase Plan (ESPP), basic life and AD&D insurance, and short-term disability insurance.
Location
Additional Information
- This role will be posted for a minimum of 3 days.
- Equal opportunity employer committed to diversity and inclusion.
- Depending on customer requirements, employees in sales and field roles requiring access to customer accounts may need to obtain various vaccinations as an essential function of their role.
- Posted Date: 02/19/2026