Blue Goat CyberBlue Goat CyberSMMedical Device Cybersecurity
    K
    Open role

    Sales Engineer, Medical Device Cybersecurity

    Run discovery calls, scope medical device cybersecurity projects accurately, and write proposals that the delivery team can actually execute.

    All open roles
    Reports to
    Chief Technology Officer
    Status
    Full-time employee, 40 hours per week
    Location
    Remote (United States), occasional client and event travel
    Compensation
    Competitive, commensurate with experience, paid every two weeks, plus benefits including health, dental, vision, 401(k), and an educational allowance
    Equipment
    Bring your own laptop and setup, and we cover the project-specific hardware and lab gear the work needs

    About the role

    Blue Goat Cyber is expanding, and we are looking for a Sales Engineer who can sit on a discovery call with a device manufacturer, understand the device and its submission timeline, and translate that into a scope and proposal that is accurate on the day it is signed and still accurate at delivery.

    This role sits between business development and delivery. You are the technical voice on sales calls: discovery, scoping, proposal review, and the follow-up questions that come from a client's engineering or regulatory team. You are not expected to run the penetration tests yourself, but you must understand testing, threat modeling, SBOM work, and FDA premarket expectations well enough to size the work honestly and explain it plainly.

    Bad scoping is the most expensive mistake a services firm makes. We would rather lose a deal than win one on a scope that hurts the client or the team delivering it, and this role is where that discipline lives.

    You are a fit if

    You are technical enough to be believed

    • You can discuss device architecture, interfaces, firmware, cloud backends, and threat modeling with an engineering team and hold your own.
    • You know what a penetration test, a threat model, an SBOM review, and a submission package each actually involve.
    • You can explain a technical recommendation to a non-technical executive without talking down to them.
    • You know the edge of your knowledge and bring in a specialist rather than guessing.

    You scope honestly

    • You size work from what the device and the submission actually require, not from what fits a budget.
    • You surface assumptions, exclusions, and dependencies in writing before anyone signs.
    • You say when a request is out of scope or when a timeline is not realistic.
    • You check your scopes against how the work actually went and adjust.

    You write well

    • You write proposals that a regulatory reader, a procurement reader, and an engineer all understand.
    • You are precise about deliverables, evidence, and what the client must provide.
    • You turn proposals around quickly without letting quality slip.

    You are calm on a call

    • You run a discovery call with structure and leave with the information needed to scope.
    • You handle pushback on price, scope, or timeline without becoming defensive or conceding what should not be conceded.
    • You partner with business development rather than competing with them.

    What you will own

    Discovery and technical sales support

    • Join sales calls as the technical voice for discovery and proposal review.
    • Run structured discovery on the device, its interfaces, its architecture, and its submission timeline.
    • Answer client engineering and regulatory questions during the sales cycle.
    • Advise business development on fit, risk, and whether we should pursue an opportunity.

    Scoping and proposals

    • Translate discovery into an accurate scope, level of effort, and timeline.
    • Write proposals and statements of work with clear deliverables, assumptions, exclusions, and client dependencies.
    • Validate scope with the delivery team before it goes out.
    • Maintain and improve proposal templates, scoping models, and reusable technical content.

    Handoff and feedback loop

    • Hand signed work to project management and delivery with full context and nothing lost.
    • Compare delivered effort to scoped effort and correct the model when it is wrong.
    • Feed recurring client questions into our guides, FAQs, and service pages.
    • Support security questionnaires and RFP responses.

    Required skills and experience

    • 4+ years in a sales engineering, solutions architect, technical consulting, or delivery role with direct client exposure.
    • Working knowledge of cybersecurity services such as penetration testing, vulnerability assessment, threat modeling, or secure development.
    • Demonstrated experience scoping and pricing technical services engagements.
    • Experience writing client-facing proposals, statements of work, or technical responses.
    • Ability to run discovery calls and technical conversations with engineering and regulatory stakeholders.
    • Excellent written communication, with precision about deliverables and assumptions.
    • Ability to work independently in a remote, high-trust environment.

    Preferred experience

    • Medical device, healthcare, or life sciences experience.
    • Familiarity with FDA Section 524B, premarket cybersecurity expectations, AAMI TIR57, or IEC 81001-5-1.
    • Hands-on testing background, even if you no longer test full time.
    • Experience responding to RFPs or security questionnaires.
    • Experience with proposal tooling and CRM-driven quoting workflows.

    Your first 90 days

    What success looks like early on, so you know what you are walking into.

    1. 1

      First 30 days

      • Learn our services, methodology, and the evidence each engagement produces.
      • Read recent proposals alongside how those projects actually ran.
      • Shadow discovery calls and draft scopes for review.
    2. 2

      Days 30 to 60

      • Run discovery independently and own proposals end to end with delivery review.
      • Handle technical questions on live opportunities without escalation.
      • Identify the two scoping assumptions that most often turn out wrong.
    3. 3

      Days 60 to 90

      • Own the scoping and proposal process for all active opportunities.
      • Improve the scoping model based on delivered-versus-scoped data.
      • Publish reusable technical answers that shorten the sales cycle.

    Tools we use

    • HubSpot
    • PandaDoc
    • Google Workspace
    • Slack
    • Zoom
    • Asana
    • Threat modeling and SBOM tooling

    About Blue Goat Cyber

    Blue Goat Cyber is a medical device cybersecurity company dedicated to protecting patient lives by securing the technologies that power modern healthcare. We support medical device manufacturers as they build, test, and launch secure devices that meet FDA expectations and operate safely in the real world.

    We are a remote, high-trust, high-ownership team that values clear communication, rigorous thinking, proactive problem solving, continuous learning, and attention to critical details. We expect every team member to own their work, communicate clearly, and support the mission without ego.

    Before you apply

    The terms every person here works under. Read them now rather than at offer stage, along with our core values and the honest list of who this is not for.

    Work authorization

    • You must be authorized to work in the United States. We do not sponsor visas for these roles.
    • All roles are performed from within the United States.

    Confidentiality and NDA

    • You will sign a mutual nondisclosure agreement before you see any client material, and client-specific NDAs where a client requires one.
    • You will see unreleased device designs, firmware, source code, vulnerabilities, and submission content. None of it is yours to discuss, publish, screenshot, or reference, during or after the engagement.
    • Client material stays in company systems. No personal cloud storage, personal email, personal repositories, or unvetted AI tools.
    • Anything we publish that draws on client work is anonymized and cleared with the client first.

    How we expect you to use AI

    • Use AI every day if it helps, on the company ChatGPT and Claude accounts we provide, and keep client material inside them: firmware, source code, submission documents, findings, and client names never go anywhere else.
    • You own the accuracy of anything you send out, because models get recognition numbers, clause references, and test conclusions wrong in ways that read perfectly well. The full policy is in the careers FAQ.

    Security and background

    • Offers are contingent on a background check and on reference checks.
    • You will use company-required security controls on any device that touches client data, including full-disk encryption, screen lock, and our password manager and multi-factor authentication.
    • Report a suspected compromise or data exposure immediately. We treat honest, fast reporting as the right behavior, not a fault.
    • Some client engagements require additional screening or training before you can be assigned.

    Equal opportunity

    • Blue Goat Cyber is an equal opportunity employer. We do not discriminate on the basis of race, color, religion, sex, sexual orientation, gender identity, national origin, age, disability, veteran status, or any other protected characteristic.
    • If you need an accommodation at any point in the hiring process, tell us and we will arrange it.

    Apply

    Send your resume, any links to your work, and a short note about why this role fits. It takes a few minutes and a real person on our team reads every application.

    If you do not hear back within two weeks, we have decided not to move forward for now. We keep applications on file for future openings.