Our client is looking for a Senior C++ Engineer to join a specialized team securing a large, mature desktop application that is a medical device software product. The mission is to identify, remediate, and prevent security vulnerabilities within legacy C++/Qt architecture, while ensuring the solution meets the security validation standards required for regulated medical device software. This work sits at the intersection of legacy systems engineering, secure coding, and medical device compliance — precision and traceability matter as much as the fix itself. Requirements * 7+ years of professional C++ development, including substantial hands-on work with C++98/03 codebases * Strong proficiency with the Qt framework (Widgets, signal/slot architecture, memory model, cross-platform desktop deployment) * Proven experience in large, legacy, mature codebases — not just modern greenfield C++17/20 projects * Solid grasp of secure coding practices in C++: memory safety, buffer/stack overflow prevention, safe pointer/reference handling, input validation * Experience with static analysis tools (Coverity, PVS-Studio, Clang Static Analyzer) and/or dynamic analysis (Valgrind, AddressSanitizer) * Prior experience in regulated software environments — medical device, automotive, aerospace, or similarly regulated domains — with an understanding of why traceability and documentation matter, not just the fix * Familiarity with (or strong willingness to quickly ramp up on) IEC 62304, ISO 13485, and ISO 14971 * Experience debugging and fixing issues in compiled, cross-platform desktop applications (Windows/Linux) * Strong Git/version control discipline; experience with legacy build systems (qmake, CMake, or similar) * Must be based in the EU * Fluent English (written and spoken) for technical and regulatory documentation
Would be a plus * Direct experience working on medical device software (Class IIa/IIb/III or FDA Class II/III equivalent) * Familiarity with FDA premarket cybersecurity guidance and/or IEC 81001-5-1(health software security) * Experience supporting a security risk assessment or penetration test remediation cycle for a regulated product * Exposure to CVE/CWE classification and vulnerability triage in a compliance context * Understanding of GDPR implications for medical software handling patient data, where applicable
Responsibilities * Identify and remediate security vulnerabilities in a large, mature C++/Qt desktop medical device application * Refactor and harden legacy C++98 code without introducing regressions * Conduct secure code reviews and static/dynamic analysis * Ensure remediation work aligns with IEC 62304 and supports required security validation standards * Document vulnerabilities and remediation work in an audit-ready, traceable manner * Collaborate with QA, security, and regulatory teams to verify fixes under formal validation testing