Senior Quality Engineer, Cybersecurity
Who We Are
Verily Health is a data platform and technology company purpose-built to power AI-enabled precision health solutions that accelerate research and improve care for individuals and communities. Uniquely positioned at the intersection of technology, data science, and healthcare, Verily transforms multimodal health data into insights, models, and actions that make healthcare more personalized, predictive, and precise.
Description
The Senior Quality Engineer, Cybersecurity is a hands-on individual contributor and subject matter expert who bridges quality engineering and cybersecurity across Verily's consumer, research, and medical device (SaMD) product portfolio. This role champions quality and security throughout the software development lifecycle — partnering closely with engineering, security, and product teams to ensure that cybersecurity processes are embedded in the QMS, meet applicable regulatory requirements, and scale across Verily's evolving product domains. The role proactively identifies risk, drives cross-functional initiatives, and brings deep technical fluency in both quality engineering and cybersecurity to protect the integrity of Verily's systems, data, and regulated products.
Responsibilities
Leads ongoing implementation and continuous improvement of the Software Quality Management System (QMS) across consumer, research, and SaMD product domains — in conformance with FDA QMSR, ISO 13485:2016 design controls, and SDLC processes — integrating internal best practices and medical device industry standards. Serves as the Quality Lead for the cybersecurity process, partnering closely with the Security team to embed security requirements, threat modeling, vulnerability management, and secure coding practices into the SDLC and QMS in alignment with FDA cybersecurity guidance and AAMI TIR57.
Guides software development teams in the creation and maintenance of Design and Development Files (DDFs), including software development plans, verification and validation plans, software requirements specifications, architecture and design documents, design and code reviews, Risk Management Files (RMF), test protocols and reports, and traceability matrices.
Supports integration of ISO 14971 risk management, IEC 62366 usability engineering, and FDA cybersecurity guidance into SDLC processes, ensuring a cohesive and compliant approach to product safety, security, and usability across the development lifecycle.
Supports post-market cybersecurity surveillance activities for SaMD and LLM-enabled products, including monitoring for emerging threats, coordinating vulnerability disclosures, and assessing the impact of security findings on regulated product safety and performance.
Provides CAPA, complaints, audit, and QMS support related to software and cybersecurity incidents, driving root cause analysis and effective corrective actions across product teams.
Qualifications
Minimum Qualifications
Bachelor's degree in Computer Science, Software Engineering, Informatics, Biomedical Engineering, or a related technical field; or equivalent practical experience with 5+ years in software quality engineering within the FDA QMSR / ISO 13485 medical device industry, with primary focus on Software as a Medical Device (SaMD).
Proven expertise in medical device cybersecurity, including working knowledge of FDA premarket and postmarket cybersecurity guidance and applicable standards (e.g., AAMI TIR57).
Demonstrated experience applying IEC 62304 (Medical Device Software Lifecycle Processes), ISO 14971 (Risk Management), IEC 62366 (Usability Engineering), and AAMI TIR57 within a regulated software development environment.
Experience collaborating directly with software development and security teams, with proficiency in Google Workspace, Jira, GitHub, and document control systems to operationalize quality and cybersecurity requirements within engineering workflows.
Preferred Qualifications
Experience with AI/ML-enabled medical device products, including familiarity with FDA AI/ML SaMD guidance, predetermined change control plans (PCCP), and post-market performance monitoring for generative AI applications; experience using generative AI tools (e.g., Gemini, Claude, ChatGPT) to enhance quality and compliance workflows is a plus.
Experience with digital health, Health IT, mobile medical applications, or consumer health products, with working knowledge of scalable QMS and SDLC approaches across wellness, low-risk, and high-risk software classifications.
Demonstrated ability to implement and continuously improve Software QMS and secure SDLC processes using agile/scrum methodologies, best-practice tooling, and iterative development frameworks in a fast-paced, innovative environment.
Relevant cybersecurity certification (e.g., AAMI Cybersecurity Certificate, CISSP, or equivalent) and/or quality certification (e.g., ASQ CQE); or advanced degree in a related technical or biomedical field.
Excellent cross-functional communication, organizational, and leadership skills, with a proven ability to drive quality and cybersecurity initiatives with minimal supervision across engineering, security, and product teams.
Qualified applicants must not require employer sponsored work authorization now or in the future for employment in the United States.
The US base salary range for this full-time position is $113,000 - $170,000 + bonus + equity + benefits. Our salary ranges are determined by role, level, and location. The range displayed on each job posting reflects the minimum and maximum target for new hire salaries for the position across all US locations. Within the range, individual pay is determined by work location and additional factors, including job-related skills, experience, and relevant education or training. Your recruiter can share more about the specific salary range for your preferred location during the hiring process.
Please note that the compensation details listed in US role postings reflect the base salary only, and do not include bonus, equity, or benefits.
Verily Health Inc. is an equal opportunity employer. Qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability or protected veteran status. For our EEO Policy Statement, please click here. If you'd like more information on your EEO rights under the law, please click here.
If you have a need that requires accommodation, please let us know by completing our Accommodations for Applicants form.