Senior Product Security Engineer
Listed on 2026-05-15
-
IT/Tech
Cybersecurity, Systems Engineer
We anticipate the application window for this opening will close on 5 Jun 2026. At Medtronic you can begin a life-long career of exploration and innovation, while helping champion healthcare access and equity for all. You’ll lead with purpose, breaking down barriers to innovation in a more connected, compassionate world.
A Day in the LifeThis role focuses on cybersecurity for medical devices and embedded systems. It is not an IT security, compliance, or GRC-focused position. The ideal candidate will have deep experience working with engineering teams to integrate cybersecurity into real-time systems, embedded firmware, connected devices, or other product-level security contexts.
Responsibilities- Product Security Strategy & Continuous Learning: Stay abreast of emerging cybersecurity threats, technologies, and regulations specific to medical devices and health software. Contribute to OU and enterprise-wide product security strategy and roadmap development.
- Secure Product Development Lifecycle: Drive security integration into all stages of the product lifecycle, from concept and design to postmarket. Work closely with system architects, software leads, and hardware engineers to embed secure design patterns in both embedded and cloud-connected environments.
- Threat Modeling & Risk Assessment: Lead or contribute to threat modeling sessions, conduct security risk assessments, and identify mitigation strategies in accordance with IEC 81001-5-1, ISO 14971, and FDA premarket cybersecurity guidance.
- Security Architecture & Design: Collaborate on the design and implementation of secure architectures, focusing on secure boot, secure communications, data protection, access control, secure software updates, and hardware-software integration.
- Security Testing & Analysis: Support and interpret results from vulnerability scans, penetration tests, and static/dynamic code analysis. Coordinate with internal teams and third-party vendors to ensure timely and appropriate risk mitigation.
- Security Awareness & Mentorship: Promote a culture of security awareness within R&D and provide support to more junior engineers. Lead by example through documentation, review participation, and active knowledge sharing.
- Regulatory & Standards Compliance: Ensure alignment with applicable standards (e.g., NIST, IEC 60601-4-5, IEC 81001-5-1) and support security documentation efforts for global regulatory submissions.
- Vendor & Supply Chain Security: Review and assess the cybersecurity posture of third-party suppliers and open-source software components used within product designs.
- Incident Response Support: Support technical investigation and resolution of postmarket security incidents or field issues. Lead root cause investigations, containment strategies, and risk assessments.
- Security Documentation: Maintain comprehensive security documentation, including threat model diagrams, risk assessments, shared service inventories, design patterns, security guidelines, and product security plans/reports.
An individual contributor with responsibility in our technical functions to advance existing technology or introduce new technology and therapies. Formulates, delivers and/or manages projects assigned and works with other stakeholders to achieve desired results. May act as a mentor to colleagues or may direct the work of other lower level professionals. The majority of time is spent delivering R&D, systems or initiatives related to new technologies or therapies – from design to implementation - while adhering to policies, using specialized knowledge and skills.
DifferentiatingFactors
- Autonomy: Seasoned individual contributor. Works independently under limited supervision to determine and develop approach to solutions. Coaches and reviews the work of lower level specialists; may manage projects / processes.
- Organizational Impact: May be responsible for entire projects or processes within job area. Contributes to the completion of work group objectives, through building relationships and consensus to reach agreements on assignments.
- Innovation and Complexity: Problems and issues faced are difficult, and may require…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).