Job Description
Responsibilities
- Lead product security architecture and security-by-design practices across the full product lifecycle from concept through post‑market support.
- Embed security into the Secure Software Development Lifecycle (SSDLC) and DevSecOps pipelines establishing guardrails that balance risk reduction with engineering velocity.
- Perform and guide threat modeling security risk assessments and architecture reviews across products and enterprise‑connected systems.
- Define and enforce security controls for AI- and ML-enabled products including data protection model integrity access controls and secure pipelines.
- Manage and operate Product Security post-market surveillance activities across GRAIL products and services from intake through remediation and closure.
- Influence secure solution architectures for GRAIL ecosystems considering system integration access control (IAM) key management (KMS) secure data flows resilience patch management and recovery.
- Scope oversee and review penetration testing and advanced security testing activities across software systems and infrastructure.
- Serve as a product security subject matter expert during incident response root cause analysis and post‑incident improvements.
- Partner with Product Engineering Quality Legal and other stakeholders to ensure alignment with regulatory and industry cybersecurity requirements.
- Define track and report product security metrics and KPIs to provide visibility into security posture and risk trends.
- Mentor and coach engineers contributing to the growth of product security capabilities and future technical leaders at GRAIL.
Required Qualifications
- 8+ years of experience in product security cybersecurity application security or related technical security roles.
- Hands-on experience leading threat modeling security risk assessments and vulnerability management for complex software products.
- Experience embedding security into modern software development environments including CI/CD and DevSecOps practices.
- Experience supporting security incident response and conducting root cause analysis in production environments.
- Bachelor’s degree in Cybersecurity Computer Science Information Systems or a related field or equivalent practical experience.
Preferred Qualifications
- Experience working in regulated environments including medical devices healthcare life sciences or similarly regulated industries.
- Knowledge of relevant standards and frameworks such as IEC 62304 ISO 14971 ISO 80001-2 NIST and FDA pre‑ and post‑market cybersecurity guidance.
- Experience securing AI/ML systems including mitigating risks such as data poisoning model manipulation and unauthorized access.
- Demonstrated experience delivering cybersecurity programs including tabletop exercises and cross‑functional incident simulations.
- Professional security certifications such as OSCP GPEN GCIH GWAPT or equivalent.
- Strong ability to translate technical security risks into business and patient-impact considerations for senior stakeholders.
- Experience working with globally distributed teams or international stakeholders.
Physical Demands & Working Environment
- Ability to work in an office and remote environment under a flexible hybrid arrangement.
- Occasional travel may be required based on business needs.
GRAIL Values & Leadership Expectations
- This Staff-level role is expected to model GRAIL’s core values and LEAD leadership attributes by leading through influence collaborating across boundaries driving results with integrity and continuously improving how product security enables patient impact.
Top Skills
What the Team is Saying




What We Do
GRAIL is a healthcare company whose mission is to detect cancer early when it can be cured. GRAIL is using the power of high-intensity sequencing population-scale clinical studies and state-of-the-art computer science and data science to enhance the scientific understanding of cancer biology and to develop and commercialize pioneering products.
Why Work With Us
Everything we do is guided by our mission to detect cancer early when it can be cured. It’s the reason we’re here and it’s no small task. The right people make all the difference. That’s why we’re looking for those who strive to share their knowledge contribute their skills inspire each other and commit to something bigger than themselves.
Gallery
GRAIL Offices
Hybrid Workspace
Employees engage in a combination of remote and on-site work.
GRAIL has a variety of work types depending on the roles. Some are onsite like a lab role others are hybrid and still others are remote. Hybrid is typically Tuesday and Thursday but leaders may be flexible depending on the role.
Similar Jobs
GRAIL
Senior Clinical Data Manager (RWE/RWD) # 4426
GRAIL
Staff Software Engineer
GRAIL
Director Of Product Management
GRAIL
Senior Quality Engineer Complaint Handling # 4699
Explore More
Date Posted
03/26/2026
Views
0



