Product and application security for regulated medical software. I write the cybersecurity documentation that a medical device has to bring to a regulator.
I'm a QA/RA & Security Specialist at Hermes Medical Solutions, where I author the product cybersecurity evidence that goes into regulatory submissions — threat models, security risk assessments and the premarket security documentation itself — inside an ISO 13485 quality system, against IEC 81001-5-1 and FDA premarket cybersecurity requirements (FD&C Act section 524B). EU AI Act readiness is the other named half of the role, and the applicability and gap assessment has started. Article 15 asks for accuracy, robustness and cybersecurity in one sentence, which is where the Act extends work I already do rather than starting something separate.
Current focus areas
- Premarket cybersecurity for medical software (FDA 524B, IEC 81001-5-1)
- Security risk management and threat modeling across the product lifecycle
- Supporting market clearance for medical devices (FDA 510(k), EU MDR)
- Securing the AI now entering medical devices — an early EU AI Act gap analysis, underway
- Application security — secure SDLC, SAST/SCA and CI/CD hardening (OIDC workload identity) for regulated software
Technical skills
Windows Server, Unix/Linux, Docker, Kubernetes, PowerShell, Bash, Python and Git
I care about making healthcare technology safer and more trustworthy — protecting patients by making sure the software, and increasingly the AI, inside their care is secure by design.
This site is itself a work sample — its content-security policy, CI gates and supply-chain posture are documented in the repository.