2

Remote Pen Tester Jobs in California (NOW HIRING)

Remote Pen Tester information

What is a remote pen tester?

A Remote Pen Tester is a cybersecurity professional who assesses the security of systems, networks, and applications by simulating cyberattacks from an external location. They identify vulnerabilities, exploit weaknesses, and provide recommendations to strengthen security. This role requires expertise in ethical hacking, penetration testing tools, and security frameworks. Remote Pen Testers often work for cybersecurity firms, as freelancers, or in-house for organizations needing security assessments.

What does a remote pen tester do?

A typical day for a Remote Pen Tester involves conducting security assessments of networks, websites, or applications, identifying vulnerabilities, and documenting findings in detailed reports. You’ll often collaborate with IT teams or clients via video calls and chat platforms to discuss scope, methodologies, and results. In addition to hands-on testing, you may spend time updating your knowledge on the latest security threats and tools. The role offers autonomy and flexibility but also requires strong self-management skills to meet project deadlines and maintain clear communication with distributed teams. Over time, successful pen testers can progress to lead roles or broaden their expertise in specialized areas such as red teaming or security consulting.

What skills and qualifications are needed to thrive as a remote pen tester?

To thrive as a Remote Pen Tester, you need expertise in network and application security, vulnerability assessment, and penetration testing, often supported by a degree in information security or computer science. Familiarity with tools like Metasploit, Burp Suite, Nmap, and relevant certifications such as OSCP or CEH is highly valued. Excellent written communication, analytical thinking, and self-motivation are crucial soft skills, especially when working independently and with distributed teams. These skills and qualities are vital for effectively identifying security weaknesses, creating actionable reports, and collaborating remotely with clients or technical teams.

What job categories do people searching Remote Pen Tester jobs in California look for? The top searched job categories for Remote Pen Tester jobs in California are:
What cities in California are hiring for Remote Pen Tester jobs? Cities in California with the most Remote Pen Tester job openings:
Infographic showing various Remote Pen Tester job openings in California as of August 2026, with employment types broken down into 48% Full Time, 36% Part Time, and 16% Contract. Highlights an 100% Remote job distribution.

Product Security Manager

iRhythm Technologies, Inc.

San Francisco, CA • Remote

Full-time

This job post has expired today. Applications are no longer accepted.


Job description

Career-defining. Life-changing. 

At iRhythm, you’ll have the opportunity to grow your skills and your career while impacting the lives of people around the world. iRhythm is shaping a future where everyone, everywhere can access the best possible cardiac health solutions. Every day, we collaborate, create, and constantly reimagine what’s possible. We think big and move fast, driven by our commitment to put patients first and improve lives. We need builders like you. Curious and innovative problem solvers looking for the chance to meaningfully shape the future of cardiac health, our company, and your career

About This Role:

We are seeking a Product Security Manager with proven experience in the medical device industry. In this role, you will safeguard medical devices by identifying, assessing, and mitigating security risks unique to healthcare technology. You will collaborate with cybersecurity, development, product management, and regulatory teams to ensure that security is embedded across the product development lifecycle (PDLC) and the secure software development lifecycle (SDLC), in alignment with FDA cybersecurity requirements.

Key Responsibilities

  • FDA Cybersecurity Compliance: Ensure compliance with FDA cybersecurity guidance and regulations in collaboration with Cybersecurity, Regulatory, Quality, and Systems Development teams.
  • Risk Assessments & CSRAs: Conduct comprehensive security risk assessments, including Cybersecurity Risk Assessments (CSRAs), to identify vulnerabilities and threats across device hardware, firmware, software, and cloud components.
  • Threat Modeling: Develop and maintain device-specific cyber threat models, factoring in patient safety, data privacy, and operational continuity.
  • SBOM Management: Demonstrate familiarity with Software Bill of Materials (SBOM) and effectively communicate technical details.
  • Security Documentation: Create and maintain cybersecurity documentation for pre- and post-market activities, ensuring regulatory alignment.
  • Data Flow Diagrams: Produce detailed data flow diagrams to support the threat modeling process.
  • Security Design Reviews: Participate in design reviews of medical device architectures and implementations, providing actionable recommendations for system security requirements.
  • Vulnerability Analysis & Management: Perform and support vulnerability analysis and coordinate the vulnerability management program, including scanning, patching, and remediation for medical devices.
  • Threat Detection Tools: Leverage and maintain application and threat detection tools (Veracode, Snyk, GitLab, or equivalent) to identify security flaws early in the SDLC.
  • Incident Response: Support investigation and remediation of device-related security incidents, minimizing impact and preventing recurrence.
  • Data Privacy Compliance: Partner with the Privacy Team to ensure adherence to HIPAA, GDPR, and other data protection regulations.

Required Qualifications

  • Bachelor’s degree in Computer Science, Information Security, or related field.
  • 8+ years of experience in information security, with direct focus on product security for medical devices.
  • Strong understanding of security principles, methodologies, and tools within the PDLC and SDLC.
  • Demonstrated experience conducting Cybersecurity Risk Assessments (CSRAs), vulnerability analysis, and working with modern threat detection tools (Veracode, Snyk, GitLab, or similar).
  • Familiarity with NIST Cybersecurity Framework, NIST SP 800-171, and deeper controls/frameworks such as NIST SP 800-53 (Security and Privacy Controls), NIST SP 800-92 (Log Management), and NIST SP 800-63 (Digital Identity Guidelines).
  • Hands-on experience with vulnerability identification and threat modeling within healthcare using methodologies such as STRIDE.
  • Experience operating in a regulated environment (FDA, HIPAA, GDPR, international regulatory frameworks).
  • Experience with medical device hardware or Software as a Medical Device (SaMD).
  • Experience with medical device software development and regulatory processes.
  • Excellent problem-solving, analytical, and communication skills, able to take a multi-siloed approach.
  • Ability to understand intro dependencies of teams across; mobile applications, hardware and cloud environments.
  • Proven track record of 510k experience and completion.

Preferred Qualifications

  • Industry certifications such as CISSP, CISM, CISA, or medical device security–specific certifications.
  • Experience with international frameworks and standards (EU MDR, JIS T 2304 / IEC 62304).
  • Understanding penetration testing methodologies and tools, able to work with pen test teams independently with little guidance.
  • Proficiency with programming languages and technologies commonly used in medical device development.

Location:

Remote - US

Actual compensation may vary depending on job-related factors including knowledge, skills, experience, and work location.

Estimated Pay Range

$127,000.00 - $165,000.00

As a part of our core values, we ensure an inclusive workforce. We welcome and celebrate people of all backgrounds, experiences, skills, and perspectives. iRhythm Technologies, Inc. is an Equal Opportunity Employer. We will consider for employment all qualified applicants with arrest and conviction records in accordance with all applicable laws.

iRhythm provides reasonable accommodations for qualified individuals with disabilities in job application procedures, including those who may have any difficulty using our online system. If you need such an accommodation, you may contact us at taops@irhythmtech.com

About iRhythm Technologies
iRhythm is a leading digital healthcare company that creates trusted solutions that detect, predict, and prevent disease. Combining wearable biosensors and cloud-based data analytics with powerful proprietary algorithms, iRhythm distills data from millions of heartbeats into clinically actionable information. Through a relentless focus on patient care, iRhythm’s vision is to deliver better data, better insights, and better health for all.

Make iRhythm your path forward. Zio, the heart monitor that changed the game.

There have been instances where individuals not associated with iRhythm have impersonated iRhythm employees pretending to be involved in the iRhythm recruiting process, or created postings for positions that do not exist. Please note that all open positions will always be shown here on the iRhythm Careers page, and all communications regarding the application, interview and hiring process will come from a @irhythmtech.com email address. Please check any communications to be sure they come directly from @irhythmtech.com email address. If you believe you have been the victim of an imposter or want to confirm that the person you are communicating with is legitimate, please contact taops@irhythmtech.com. Written offers of employment will be extended in a formal offer letter from an @irhythmtech.com email address ONLY.

For more information, see https://www.ftc.gov/business-guidance/blog/2023/01/taking-ploy-out-employment-scams and https://www.ic3.gov/Media/Y2020/PSA200121