Job Specifications
Title: Cybersecurity Specialist
Duration: 6 Months with a strong possibility of extension or full-time
Location: St. Paul, MN or Abbott Park (North Chicago)
Travel: Very limited, possibly 1–2 times during the 6‑month period, likely none.
Work Schedule: 8 hours/day, 5 days/week
Only W2 candidates are eligible for this position. Third-party or C2C candidates will not be considered
Role Overview
The role has a strong focus on medical devices, IoT/sensor-based products, mobile applications, and backend systems, including building security standards, guidance, dashboards, and validating the effectiveness of cybersecurity controls.
Description:
As a Senior Cyber Specialist – Digital Enablement, you will play an important role in ensuring that Client product technologies leveraged by healthcare providers and consumers are secure-by-design. These technologies range from regulated medical devices to e-commerce and customer loyalty solutions. You will evaluate the cybersecurity posture of new and existing product technologies, identify risks, recommend mitigation strategies, and ensure timely remediation and closure. You will bring deep expertise in security risks, controls, mitigations, and global cybersecurity standards to Client product teams.
This role is expert-driven and guidance-focused, requiring strong technical depth, excellent communication skills, and a proven ability to navigate a large, global environment. You will partner closely with internal product owners, developers, engineers, security architects, and external collaborators to evaluate solutions, strengthen governance, and guide secure product development. Your work will directly contribute to the delivery of scalable, compliant, and secure product technologies, cloud services, and connected applications.
The role focuses on consultative responsibilities rather than hands‑on development or cybersecurity operations.
Primary Responsibilities
Develop and maintain security guidance documentation, including standards and frameworks
Conduct full-stack architecture reviews of products and platforms, including consumer identity platforms
Perform cybersecurity threat modeling and prepare outputs for review by internal and external stakeholders
Establish, document, and monitor compliance with risk‑based and regulatory-informed cybersecurity requirements for individual products
Collaborate with product designers and developers to ensure security considerations are integrated early into product design discussions
Validate the security of product software supply chains and product deployment pipelines
Develop risk mitigation strategies and recommend appropriate security controls
Assess and prioritize product security risks through detailed evaluation of vulnerability assessments and penetration testing results
Evaluate the effectiveness of product cybersecurity controls
Identify and effectively communicate cyber risk trends
Ensure risk management plans are clearly documented, actionable, and accurately reflect the organization’s risk tolerance
Track and ensure product compliance with defined vulnerability remediation SLAs.
Participate in governance forums, architecture reviews, and technical discussions as a representative of Product Cybersecurity
Required:
At least 5 years of experience but typically 7 plus years of experience is required.
Possess expertise in valuing and implementing industry standards such as the ISO 27001/2, SOC 2, HITRUST and FedRAMP Information Security standard and the ISO 22301 Business Continuity Standard.
Experience with implementation and operational use of GRC toolsets (Governance Risk and Compliance).
Possess CISSP certification (or similar) and be knowledge of national and international regulatory compliances and frameworks such as ISO, SOX, BASEL II, EU DPD, HIPAA, and PCI DSS.
Ability to influence policy/standards for emerging tech (AI, quantum, cloud).
About You
7+ years of experience in cybersecurity or technology architecture, assessment, or consulting with a focus on the development of secure digital product technologies
Experience conducting risk assessments, control assessments, and governance reporting
Ability to clearly articulate cybersecurity risks and recommended mitigations to product development teams
Strong understanding of modern technology stacks, including cloud‑native architectures and API-driven services
Understanding of core concepts related to identity and access management, secure software development, network security, and cryptography
Familiar with device‑to‑device, service‑to‑service, and consumer identity and access management practices
Familiarity with modern phishing-resistant authentication technologies, including WebAuthn and Passkeys
Understanding of cybersecurity risks associated with emerging technologies, including quantum computing and artificial intelligence
Knowledge of global medical device regulatory frameworks
Excellent analytical, problem-solving, and communication skills
About the Company
DivIHN ('Divine') has served as a holistic Technology Consulting entity since 2002, committed to Client Success & Transformation. Our Clients' journey of transformation requires wise counsel, expert guidance, innovative design, execution, and capable delivery assistance. We provide these, aligning with their goals, and investing in the journey. In enablement of this, we pursue leadership in Strategy Alignment, Technology Vision, Solution Design, and Delivery Excellence. We deliver value in the following areas of specializati...
Know more