B. Braun Medical Inc., a leader in infusion therapy and pain management, develops, manufactures, and markets innovative medical products and services to the healthcare industry. Other key product areas include nutrition, pharmacy admixture and compounding, ostomy and wound care, and dialysis. The company is committed to eliminating preventable treatment errors and enhancing patient, clinician and environmental safety. B. Braun Medical is headquartered in Bethlehem, Pa., and is part of the B. Braun Group of Companies in the U.S., which includes B. Braun Interventional Systems, Aesculap® and CAPS®.
Globally, the B. Braun Group of Companies employs more than 64,000 employees in 64 countries. Guided by its Sharing Expertise® philosophy, B. Braun continuously exchanges knowledge with customers, partners and clinicians to address the critical issues of improving care and lowering costs. To learn more about B. Braun Medical, visit www.bbraunusa.com
Position Summary:
We are seeking a Senior Information Security Specialist to join our Information Security team. This individual will serve as a senior technical contributor responsible for designing, implementing, and continuously improving key components of our security program. They will independently lead complex security initiatives, influence security strategy, and serve as a trusted advisor across cross-functional teams. This is a unique opportunity to make an immediate and lasting impact, addressing the unique needs of our environment.
This position will be hands-on across multiple domains, including security operations, endpoint protection, cloud security, data loss prevention, and compliance, while also partnering closely with global business and technology teams to ensure that security is embedded across all functions.
This role reports into the Head of Security and sits within the technology department. The technology team manages a modern technology environment built around cloud and SaaS based applications.
Responsibilities: Essential Duties
-
Provides technical expertise and support in operational and implementation aspects of Information Security framework controls, activities, and products.
-
Assess and support Information Security controls, risk, and exposure for new and existing infrastructure and processes.
-
Reviews newly provisioned and existing systems to assure alignment with security architecture standards; meet security requirements; and identify potential exposure to risk.
-
Ensure that secure design principles, threat modeling, and OWASP Top 10 mitigations are systematically integrated into the applications, architecture and development lifecycle
-
Partner with global teams to champion the development, execution, monitoring and implementation of global policies, standards and controls, ensuring robust cyber risk management and governance across all business units
-
Maintains an awareness of existing and proposed security standards groups, state and federal legislation and regulations pertaining to information security and identify regulatory changes that will affect information security policy, standards and procedures.
-
Help drive external audits (SOC 2, HITRUST, HIPAA, etc.), automate evidence collection in GRC platforms, and maintain a risk register.
-
Champion the "Shift Left" philosophy by embedding automated security controls and practices within the Software Development Life Cycle (SDLC) using Agile methodologies
-
Work closely with technology, architecture and cyber operations teams to ensure alignment on policy and control implementation and effective risk mitigation
-
Define and track KPIs/KRIs (e.g., vulnerability age, scan coverage, incident MTTR, automation ROI, playbook effectiveness) and drive quarterly improvements
-
Cloud Security: Support security for AWS and Azure environments, working closely with cloud engineering teams to resolve vulnerabilities
-
Participate and provide expertise during third party assessments and customer assurance activities.
-
Partner with legal teams and provide assistance and review security controls requirements as applicable to the busines
Qualifications: Education/Experience/Training/Etc
-
Bachelor's degree required or equivalent combination of education and experience.
-
10-12 years related experience required.
-
Applicable industry/professional certification preferred.
-
Regular and predictable attendance
-
Ability to work non-standard schedule as needed, On-call hours as needed
Skills:
-
Deep understanding of cyber risk management frameworks (NIST, ISO 27001, CIS, HIPAA, HITRUST, GDPR, NIS2).
-
Experience with regulatory compliance and alignment across global jurisdictions.
-
Strong communication skills, capable of translating technical risk into clear, executive-level reporting.
-
Highly developed influencing skills, able to build buy-in and foster a positive cybersecurity culture.
-
Proven track record in cyber risk management, policy development, and audit readiness.
-
Demonstrable experience in cyber risk and compliance roles within regulated industries.
-
Experience in overseeing vendor and third-party risk management.
-
Proven ability to manage and deliver complex projects across multiple geographies
The job functions listed are not exhaustive and shall also include any responsibilities as assigned from time to time.
General: It shall be the duty of every employee while at work to take reasonable care for safety and health of himself/herself and other persons.
Expertise: Knowledge
-
Requires advanced knowledge of professional field and industry. Influences the development of and drives the application of principles, theories, concepts. Determines best course of action.
-
Work under minimal supervision. Relies on experience and judgement to plan and accomplish assigned goals. May periodically assist in orienting, training, and/or reviewing the work of peers.
-
Judgement is required in resolving complex problems based on experience.
-
Contacts are primarily with department supervisors, leads, subordinates, and peers. Occasional contact with external contractors/vendors.
The targeted range for this role takes into account a range of factors that are considered when making compensation and hiring decisions; included but not limited to: skill sets; experience and training; licensure and certifications; and other business and organizational needs. The disclosed range estimate has not been adjusted for the applicable geographic differential associated with the location at which the position may be filled. Compensation decisions are dependent on the facts and circumstances of each case. The range provided is a reasonable estimate.
Base Salary: $135k - $165k
While performing the duties of this job, the employee is regularly required to sit and talk or hear. The employee frequently is required to use hands to handle or feel and reach with hands and arms. The employee is occasionally required to stand and walk. The employee must occasionally lift and/or move up to 20 pounds.
The targeted range for this role takes into account a range of factors that are considered when making compensation and hiring decisions; included but not limited to: skill sets; experience and training; licensure and certifications; and other business and organizational needs. The disclosed range estimate has not been adjusted for the applicable geographic differential associated with the location at which the position may be filled. Compensation decisions are dependent on the facts and circumstances of each case. The range provided is a reasonable estimate.
B. Braun offers an excellent benefits package, which includes healthcare, a 401(k) plan, and tuition reimbursement. To learn more about B. Braun and our safety healthcare products or view a listing of our employment opportunities, please visit us on the internet at www.bbraunusa.com.
Through its “Sharing Expertise®” initiative, B. Braun promotes best practices for continuous improvement of healthcare products and services.
We are an equal opportunity employer. We evaluate applications without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, age, pregnancy, genetic information, disability, status as a protected veteran, or any other protected characteristic. Know Your Rights: Workplace Discrimination is Illegal, click here.