
Hermes Medical Solutions
QA/RA & Security Specialist
Media
Outcomes
- Delivered the cybersecurity documentation that goes into FDA premarket submissions for regulated nuclear-medicine software
- Stood up secure development lifecycle processes aligned with IEC 81001-5-1 and EU MDR expectations
- Established DICOM protocol fuzzing for robustness testing of imaging interfaces, using a fuzzer built in this role
- Embedded security and quality requirements in the product itself by coordinating development, clinical, and regulatory teams
About Hermes Medical Solutions
Product security for regulated nuclear-medicine software: threat modeling, FDA premarket security documentation, IEC 81001-5-1 secure-lifecycle work, SBOM and vulnerability management — alongside QA/RA responsibility for V&V and market clearance.
The role
Hermes Medical Solutions is a healthcare technology company that develops software solutions for nuclear medicine, supporting medical professionals with diagnostic imaging and treatment planning tools.
As QA/RA & Security Specialist, I own the product security work for regulated nuclear-medicine software — threat modeling, premarket security documentation, and secure-lifecycle processes — alongside quality assurance and regulatory responsibility.
Product Security: I build and present threat models for our software, author the cybersecurity documentation that goes into FDA premarket submissions, and implement secure development lifecycle processes aligned with IEC 81001-5-1 and EU MDR expectations.
Security Tooling: I run artifact-level SBOM generation and vulnerability triage with Grype on demand, and maintain a DICOM protocol fuzzer built in this role for robustness testing of imaging interfaces.
Compliance & ISMS: I drive NIS 2 compliance work across the organization, conduct security assessments, and implement data protection measures for patient data in line with healthcare regulations.
Quality Assurance & Regulatory: I lead Verification and Validation (V&V) for nuclear-medicine software and support market clearance across multiple jurisdictions, keeping testing protocols rigorous for diagnostic accuracy and reliability.
Cross-Functional Collaboration: I coordinate across development, clinical, and regulatory teams so security and quality requirements land in the product rather than in documents.
Key responsibilities
- Build and present threat models for premarket security work
- Author cybersecurity documentation for FDA premarket submissions
- Implement IEC 81001-5-1 secure development lifecycle processes
- Run artifact-level SBOM generation and vulnerability triage with Grype
- Maintain a DICOM protocol fuzzer built in this role
- Drive NIS 2 compliance work across the organization
- Lead V&V and support market clearance for nuclear-medicine software