Product Security Engineer II
Indexed description
A Day in the Life
The ideal candidate should have hands-on experience securing Class I, Class II, and Class III medical devices, connected care platforms, software applications, and cloud-connected healthcare systems while working closely with R&D, systems engineering, quality, regulatory, and product teams.
Responsibilities may include the following and other duties may be assigned:
Product Security Engineering
- Perform security risk assessments throughout the product development lifecycle.
- Conduct threat modeling exercises using methodologies such as:
- STRIDE, Attack Trees, MITRE ATT&CK, CVSS,
- Identify product security requirements and ensure implementation of appropriate security controls.
- Review system, software, cloud, and network architectures from a security perspective.
- Collaborate with development teams to design secure products and mitigate identified risks.
- Plan and execute security testing activities, including:
- Vulnerability assessments
- Penetration testing
- Secure code reviews
- Security regression testing
- Protocol and network security testing
- Analyze, prioritize, and track vulnerabilities through remediation and verification.
- Work with development teams to implement corrective actions and security improvements.
- Integrate cybersecurity activities into product development processes.
- Support security design reviews and security architecture assessments.
- Define and monitor security KPIs and product security metrics.
- Conduct security impact assessments for product enhancements and sustaining engineering activities.
- Support compliance activities related to:
- FDA Cybersecurity Guidance, AAMI TIR57, AAMI TIR97
- IEC 62304, ISO 14971, IEC 81001-5-1,
- NIST Cybersecurity Framework, NIST 800-53, NIST Secure Software Development Framework (SSDF)
- Participate in cybersecurity documentation for regulatory submissions and audits.
- Monitor vulnerabilities from: CVE, NVD, CISA Advisories, Third-party software suppliers
- Perform impact assessments and remediation planning.
- Support coordinated vulnerability disclosure and post-market cybersecurity activities.
- Develop scripts and automation tools using Python or similar scripting languages.
- Automate security analysis, vulnerability scanning, data collection, and reporting activities.
Required Knowledge And Experience
- Bachelor's or Master's degree in: Computer Science, Cybersecurity, Software Engineering, Electronics Engineering, Information Security, Related Engineering Discipline
- 5–7 years of experience in Product Security, Application Security, Cybersecurity Engineering, or Medical Device Security.
- Experience working with regulated medical devices or healthcare products is highly preferred.
- Experience securing connected products, embedded systems, desktop applications, cloud services, or IoT platforms.
- Security Risk & Threat Modeling
- Security Testing; Penetration Testing, Vulnerability Assessment, Secure Code Review
- Network Security Testing, Web and API Security Testing
- Security Tools: Experience with one or more of the following:
- Application Security: Burp Suite, OWASP ZAP, Checkmarx, Fortify, Veracode, SonarQube, Nessus, Nmap, Wireshark, Metasploit
- Container & Cloud Security: rivy, Snyk, Prisma Cloud, Microsoft Defender for Cloud, AWS Security Services
- SBOM & Dependency Analysis: Dependency-Track, CycloneDX Tools
- Python (Required); PowerShell or Bash (Preferred)
Recruitment Fraud Alert
We are aware of phishing scams targeting job seekers. Please keep the following in mind:
Apply only through official Medtronic channels. All legitimate Medtronic recruiting communications come from approved Medtronic platforms and official @medtronic.com email addresses.
Medtronic will never ask for payment or sensitive personal information (such as bank account or Social Security details) during early stages of the hiring process. Any such requests are not legitimate.
If you receive a suspicious message claiming to be from Medtronic, do not respond, click links, or open attachments.
If you have any questions, concerns regarding the authenticity of a communication alleged to have been made by or on behalf of Medtronic, please contact us immediately at [email protected].
Benefits & Compensation
Medtronic offers a competitive Salary and flexible Benefits Package
A commitment to our employees lives at the core of our values. We recognize their contributions. They share in the success they help to create. We offer a wide range of benefits, resources, and competitive compensation plans designed to support you at every career and life stage.
This position is eligible for a short-term incentive called the Medtronic Incentive Plan (MIP).
Create a free Caio profile to unlock more results and save your role and location preferences.
Unlock free search