23 set
|
Medicilio
|
Milano
Quality & Regulatory Affairs (QARA)
About MedicilioAt Medicilio, we're building the bridge from remote patient monitoring to remote patient intelligence — software that doesn't just track healthcare operations, but actively improves clinical decisions and patient outcomes at scale.
We are a remote-first company with teams across multiple continents, building products for Italy today and expanding across Europe tomorrow.
You'll work closely with product, operations, clinical stakeholders, and external technical partners to solve complex real-world problems in a high-trust environment where ownership matters more than process.
We care about
- shipping meaningful products that work in production,
- building systems that remain maintainable over time,
- learning fast and adapting continuously,
- and enjoying the process of building together.
Remote-first within the EU. Optional offices in Milan and Sicily. Why this jobMedicilio builds remote patient monitoring software. Behind every process we run there is a patient at home, a nurse reading a dashboard, and a physician who has to trust what the screen says. The regulation — MDR, ISO 13485, ISO 27001, GDPR — is how that trust is written down. We take it seriously, and we refuse to treat it as paperwork.
Medicilio RPM is a Class IIa medical device going through MDR certification. The quality system exists and the certification path is set. What is missing is the part nobody can do from outside: making the processes the regulation asks for exist inside the teams, run as part of their daily work, and leave evidence on their own — without anyone reconstructing it the week before the audit.
That is the seat we are opening. It is the second person in a small GRC function, working next to a GRC Manager & Coordinator who brings the security and automation side. You bring the regulatory backbone and the quality practice. Two complementary halves; neither works alone.
This is for you if you have already taken a device through a regulatory or certification audit and remember exactly which finding kept you up at night; if you believe a procedure that lives in a drive and not in the team's tools is a procedure that does not exist; if you have used AI tools enough to know where they help and where they invent; and if you enjoy walking into a sales or HR team that never thought about ISO 13485 and leaving them with a process they actually use.
About the roleYou report to the GRC Manager & Coordinator. The department is small by design: a few internal seats, our DPO and legal lead, an external CISO, and specialised partners for regulatory advisory and internal audits. Day to day you also work with the PRRC, the engineering leadership and the QA team.
Two domains, two regimes. RPM is regulated medical device software (MDR, ISO 13485, IEC 62304). Not everything we build is a medical device. Same standards and tooling across products, deliberately different depth — and the judgement to keep that line is part of the job.
Where we are today. MDR certification is the priority until it is done. Behind it sits the work of bringing quality processes into every team, not only product,
and of putting quality review where it belongs — upstream, on requirements, before they become code.
This is not a documentation role. It is a process role with a regulatory backbone: you define what must exist, build it where the teams work, train them, and make sure the evidence falls out of the work.
What you'll doKeep the quality system in order
- Own document control, controlled procedures, change control, CAPA and non-conformities.
- Keep the QMS proportionate to a software company of our size — knowing what not to put in it is half the skill.
Package processes for each department
- Understand what each team must run under ISO 13485, ISO 27001 and GDPR.
- Design the process with them and build it on the workflow infrastructure we set up together — states, roles, gates and records.
- Ship it, explain what it means to them, and help them make it stick.
- Every process gets a named owner; a committee is not an owner.
Audit the departments — and automate the audit
- Check that people actually follow the processes; spot the missing pieces and the deviations.
- Turn them into next steps and feed the compliance backlog.
- Prepare the teams for internal and external audits and close the findings.
- With the technical side of GRC, work out which checks can run continuously as AI-assisted workflows instead of as a yearly exercise.
Review requirements upstream
- Run the quality review of requirements and design inputs: verifiable, with acceptance criteria, inputs and outputs kept apart.
- This sits before testing starts, and it is where quality is cheapest to get right.
Support the MDR side
- The GRC Manager & Coordinator owns the technical documentation, the Notified Body relationship and post-market surveillance.
- Know the file well enough to draft a PSUR section or a vigilance record, and to stand in when needed.
Decide together what to automate with AI, and where a human signs
- For each process you package, review with the technical side of GRC whether an AI-assisted step belongs: what the agent does, its inputs and outputs, where the human gate sits, how the step is validated.
- The audit trail must show that AI was used, what it recommended, and who approved.
- Building the integration is the GRC Manager's job; deciding where it is allowed is a joint call, and the quality judgement in it is yours.
ToolingShared workflow and evidence infrastructure, built together · eQMS · Google Workspace · AI-assisted workflows (LLM agents in the process, human gates by design) · read access to the engineering repositories What we're looking forMust-haves
- 3+ years in regulatory affairs or quality management for medical devices or another regulated software domain.
- At least one regulatory or certification audit taken to a successful outcome as a hands-on owner — an MDR or IVDR conformity assessment with a Notified Body, an FDA submission, or an ISO 13485 certification audit. You can name the body and the year, and you lived through the findings and the CAPA plan.
- Hands-on ownership of document control, CAPA and change control, and direct exposure to post-market surveillance — not oversight of someone else doing them.
- ISO 13485 and ISO 14971 as working tools, not as course certificates.
- Right-sizing judgement: you can say what does not belong in the QMS of a small software company, and defend it to an auditor.
- You model a process as a workflow — states, roles, gates, records — not as a narrative document, and you are at ease configuring structured tools yourself.
- You can specify an automation so that someone else can build it, and verify its output when it comes back.
- Hands-on with LLM and agentic tooling, with opinions from real use — including where it produces unverifiable output.
- Clear English, written and spoken, with technical and non-technical people.
Nice-to-havesQualifiable as PRRC under MDR Art. 15(1) · MDR experience with a European Notified Body specifically · IEC 62304 with a defended safety classification · MDCG 2019-11 and Rule 11 · IEC 62366-1 · ISO 27001 / ISO 27701 · MDCG 2019-16 cybersecurity · IEC 81001-5-1 · eQMS implementation · ISO 13485 Lead Auditor · remote patient monitoring or telemedicine · Italian. Not required: RAC certification. We value what you have shipped, not the acronym.
Skills that matter most in this role
- Right-sizing: Depth matched to actual risk, not applied uniformly
- Process thinking: You see a procedure and ask where it runs, who owns it, what record it leaves
- Evidence as a by-product: Proof of compliance falls out of the work, not reconstructed before the audit
- Knowing where the human gate goes: In a CAPA, a release, a vigilance report, a controlled document
- Influence without authority: You make departments run processes they did not ask for, and they thank you later
- Pragmatism: a compliant process this month beats a perfect one next year
Compensation€55–€65 depending on experience, plus equity discussed openly at offer stage.
LocationRemote-first within the EU, offices in Milan and Sicily available anytime. Two days on site per quarter (team sessions, planning); travel covered.
Our valuesTrustWe communicate directly, keep our word, and operate with high autonomy. Trust increases speed by reducing unnecessary process.
CareWe care about the people we work with and the problems we solve. We give honest feedback, support each other, and create space to learn from mistakes.
CuriosityWe stay open, ask questions, and continuously learn from systems, users, and each other.
ExpansionWe take on ambitious problems and grow through them. We value progress over perfection.
JoyWe build serious systems without losing enjoyment in the process. Strong morale improves both outcomes and quality of work.
ApplyMake sure to use the job reference 123ztrctyxr when applying:
https://forms.clickup.com/36224228/f/12hf74-59715/3SIE3QGAO14RDI75GP
📌 Medicilio | Quality & Regulatory Affairs (QARA) (Milano)
🏢 Medicilio
📍 Milano