Senior Product Security Engineer ensuring cybersecurity for Medtronic's medical device solutions. Integrating advanced cybersecurity measures and collaborating across teams for product lifecycle improvements.
Responsibilities
Stay abreast of emerging cybersecurity threats, technologies, and regulations specific to medical devices and health software.
Contribute to OU and enterprise-wide product security strategy and roadmap development.
Drive security integration into all stages of the product lifecycle, from concept and design to postmarket.
Work closely with system architects, software leads, and hardware engineers to embed secure design patterns in both embedded and cloud-connected environments.
Lead or contribute to threat modeling sessions, conduct security risk assessments, and identify mitigation strategies in accordance with IEC 81001-5-1, ISO 14971, and FDA premarket cybersecurity guidance.
Collaborate on the design and implementation of secure architectures, focusing on secure boot, secure communications, data protection, access control, secure software updates, and hardware-software integration.
Support and interpret results from vulnerability scans, penetration tests, and static/dynamic code analysis.
Coordinate with internal teams and third-party vendors to ensure timely and appropriate risk mitigation.
Promote a culture of security awareness within R&D and provide support to more junior engineers.
Ensure alignment with applicable standards (e.g., NIST, IEC 60601-4-5, IEC 81001-5-1) and support security documentation efforts for global regulatory submissions.
Review and assess the cybersecurity posture of third-party suppliers and open-source software components used within product designs.
Support technical investigation and resolution of postmarket security incidents or field issues.
Maintain comprehensive security documentation, including threat model diagrams, risk assessments, shared service inventories, design patterns, security guidelines, and product security plans/reports.
Requirements
Bachelor's degree and 4 years of relevant experience, or a Master’s degree with 2 years of relevant experience
Bachelor’s degree in a relevant engineering field of study (e.g., Computer Engineering, Software Engineering, or related discipline), completed and verified prior to start
Minimum 4 years of relevant experience, or 2 years with an advanced degree
Minimum 1 year of experience integrating security into embedded systems or connected medical devices in a regulated product development environment
Working knowledge of secure development lifecycle (SDLC), secure boot, cryptography, secure firmware update, secure communication, and hardware/software interface security
Master’s degree in a relevant engineering or cybersecurity field
Enterprise Services Manager leading the Technical Account Management team at Proofpoint. Responsible for maximizing customer value of products and services while ensuring high customer satisfaction.
Information Systems Security Engineer providing technical solutions and support for Department of Defense systems. Leveraging industry knowledge to increase operational efficiencies focusing on classified data systems.
Network Security Architect at Dell influencing security culture and designing secure network environments. Collaborating across teams and developing strategies for modern network security.
Senior Enterprise Security Engineer performing security assessments and threat modeling for Salesforce systems. Collaborating with teams and defining security standards across diverse technology environments.
Fullstack Software Engineer focusing on security to ensure resilience and data protection at health tech company Alan. Involved in building foundational security and authentication systems.
Security Engineer building trust foundations for bare - metal platforms at OpenAI. Designing and operating core security infrastructure for reliable compute platforms across global infrastructure.
Cybersecurity Consultant involved in deploying security tools and supporting compliance projects in Andorra. Working with cross - functional teams to enhance cybersecurity measures and documentation.
Microsoft Success Manager helping partners grow secure, scalable Microsoft practices across ANZ. Championing Microsoft security solutions and supporting partner success strategies in the region.
Assistant AVP overseeing a 5 - member team for Access Management services in Pune and Mumbai, ensuring high standards of service delivery and compliance.
Own global security systems infrastructure for QVC, managing access control and networked security systems across multiple regions. Collaborate with IT to ensure security and technology initiatives meet organizational needs.