You are viewing a preview of this job. Log in or register to view more details about this job.

Sr. Product Security Engineer

Senior Product Security Engineer - (Embedded/IoT) - Onsite

At Medtronic, we’re driven by our Mission to alleviate pain, restore health, and extend life for millions of people around the world through innovative biomedical devices and connected health solutions. As our products become increasingly connected, securing the medical device ecosystem at the product and system level is critical to ensuring patient safety and product integrity. The Senior Product Security Engineer will play a key role in securing connected and embedded medical devices across the full product lifecycle. This role is focused on device/product security engineering (not enterprise IT security) and partners closely with R&D, software, systems, and quality teams to design and implement robust, scalable security controls. 

 

The ideal candidate brings hands-on experience securing embedded or IoT products in regulated environments, with strong depth in threat modeling, secure architecture, cryptography, and device-level risk management. 

 

Key Responsibilities:

 

Product Security Engineering – Embed security requirements into the medical device development lifecycle, partnering with R&D and systems teams from architecture through release. 

Threat Modeling & Risk Assessment – Perform system-level threat modeling (e.g., STRIDE or similar), attack surface analysis, and vulnerability assessments for connected and embedded medical devices. 

Secure Architecture – Support and review implementation of device security capabilities, such as: 

  • Secure boot and root of trust 
  • Secure firmware/software update mechanisms 
  • Device identity and authentication 
  • Secure communications and protocol hardening 
  • Data protection at rest and in transit 
  • Key management and Hardware Security Module (HSM) concepts 

Standards & Compliance – Ensure alignment with medical device cybersecurity expectations, including: 

  • FDA premarket cybersecurity guidance 
  • IEC 81001-5-1 
  • ISO 14971 
  • NIST frameworks 
  • Relevant Medtronic quality processes 

 

Minimum Requirements 

Bachelor’s degree in Computer Science, Computer Engineering, Electrical Engineering, or related technical field 

4+ years of experience OR advanced degree with 2+ years of relevant experience   

 

Preferred:

  • Medical device cybersecurity experience 
  • Experience with IEC 81001-5-1 
  • Experience with FDA cybersecurity submissions 
  • Background in connected healthcare products 
  • Security certifications (Security+, CISSP, etc.) 
  • Embedded/device security 
  • IoT security 
  • Product security engineering