Principal Cyber Security Engineer
Listed on 2026-08-04
-
IT/Tech
Cybersecurity
Location
Additional Location(s): US-MN-Arden Hills
About the RoleBoston Scientific is seeking a Product Cybersecurity Engineer to operationalize and support various post-market cybersecurity activities within the Cardiac Rhythm Management (CRM) Research and Development (R&D) organization. The engineer will understand and document the security posture of the company’s products, applications, and supporting infrastructure, and ensure compliance with quality systems and processes. They will assist in implementing the individual CRM product cybersecurity plan and work collaboratively with internal staff and consultants.
Responsibilities- Support and manage applicable tools for pre and post market security testing; support integration of the tools into the quality processes.
- Support post-market activities to identify known/unknown vulnerabilities associated with Boston Scientific’s products, providing inputs/technical expertise to multiple teams to eliminate/mitigate identified cybersecurity risks.
- Monitor changes in security controls of products and update the product inventory and tracking database as needed and communicate to stakeholders.
- Support negotiations of hospital cybersecurity agreements by reviewing technical clauses with Legal and Research & Development subject matter experts.
- Support, as needed, security risk assessment and threat modelling services for CRM products businesses and product development life cycle.
- Support, as needed, application security reviews and vulnerability/penetration testing of Boston Scientific’s medical devices and software.
Required qualifications:
- Bachelor’s degree or higher.
- 10+ years in Research & Development and/or Information Technology experience, preferably in cybersecurity roles in medical device development or health care organizations.
- Drive for learning cybersecurity and a passion for securing products.
- Experience with vulnerability analysis of Windows and Linux operating systems as well as software.
- Experience across various OS platforms such as Windows, MacOS, Linux, and Mobile (iOS, Android).
- General understanding of cybersecurity techniques, controls, and methodologies from frameworks such as NIST Special Publications and ISO standards.
Preferred qualifications:
- Cybersecurity certifications (e.g. Network+, Security+, CSSLP, HCISPP, CEH, CISSP) a plus.
The anticipated annualized base amount or range for this full time position will be $ to $, plus variable compensation governed by the Sales Incentive Compensation Plan (which includes certain annual non-discretionary incentives based on predetermined objectives) as well as the value of core and optional benefits offered at BSC.
Legal StatementsFor MA positions:
It is unlawful to require or administer a lie detector test for employment. Violators are subject to criminal penalties and civil liability.
Boston Scientific maintains a prohibited substance free workplace. Pursuant to Va. Code § 2.2-4312 (2000), Boston Scientific is providing notification that the unlawful manufacture, sale, distribution, dispensation, possession, or use of a controlled substance or marijuana is prohibited in the workplace and that violations will result in disciplinary action up to and including termination.
Employees of the Company will be subject to a drug test as a pre-employment requirement for safety-sensitive positions.
COVID-19 vaccination status may be required for certain US based positions.
Requisition629892
#J-18808-Ljbffr(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).