Hermes Medical Solutions

QA/RA & Security Specialist

Media

Hermes Medical Solutions - HERMIA Imaging Platform
Hermes Medical Solutions Location - Stockholm, Sweden

Outcomes

  • Delivered the cybersecurity documentation that goes into FDA premarket submissions for regulated nuclear-medicine software
  • Stood up secure development lifecycle processes aligned with IEC 81001-5-1 and EU MDR expectations
  • Established DICOM protocol fuzzing for robustness testing of imaging interfaces, using a fuzzer built in this role
  • Embedded security and quality requirements in the product itself by coordinating development, clinical, and regulatory teams

About Hermes Medical Solutions

Product security for regulated nuclear-medicine software: threat modeling, FDA premarket security documentation, IEC 81001-5-1 secure-lifecycle work, SBOM and vulnerability management — alongside QA/RA responsibility for V&V and market clearance.

The role

Hermes Medical Solutions is a healthcare technology company that develops software solutions for nuclear medicine, supporting medical professionals with diagnostic imaging and treatment planning tools.

As QA/RA & Security Specialist, I own the product security work for regulated nuclear-medicine software — threat modeling, premarket security documentation, and secure-lifecycle processes — alongside quality assurance and regulatory responsibility.

Product Security: I build and present threat models for our software, author the cybersecurity documentation that goes into FDA premarket submissions, and implement secure development lifecycle processes aligned with IEC 81001-5-1 and EU MDR expectations.

Security Tooling: I run artifact-level SBOM generation and vulnerability triage with Grype on demand, and maintain a DICOM protocol fuzzer built in this role for robustness testing of imaging interfaces.

Compliance & ISMS: I drive NIS 2 compliance work across the organization, conduct security assessments, and implement data protection measures for patient data in line with healthcare regulations.

Quality Assurance & Regulatory: I lead Verification and Validation (V&V) for nuclear-medicine software and support market clearance across multiple jurisdictions, keeping testing protocols rigorous for diagnostic accuracy and reliability.

Cross-Functional Collaboration: I coordinate across development, clinical, and regulatory teams so security and quality requirements land in the product rather than in documents.

Key responsibilities

  • Build and present threat models for premarket security work
  • Author cybersecurity documentation for FDA premarket submissions
  • Implement IEC 81001-5-1 secure development lifecycle processes
  • Run artifact-level SBOM generation and vulnerability triage with Grype
  • Maintain a DICOM protocol fuzzer built in this role
  • Drive NIS 2 compliance work across the organization
  • Lead V&V and support market clearance for nuclear-medicine software