Product Security Engineer II
Listed on 2026-02-06
-
Engineering
Cybersecurity, Systems Engineer
Select how often (in days) to receive an alert:
Product Security Engineer IIDate: Feb 2, 2026
Location: Lakewood, CO, US
Requisition : 34620
At Terumo Blood and Cell Technologies, our 8,000+ global associates proud to come to work each day, knowing that what we do impacts the lives of patients around the world.
For Terumo, for Everyone, Everywhere.
We make medical devices and related products that are used to collect, separate, manufacture and process various components of blood and cells. With our innovative technologies and service offerings, we touch a patient’s life every second of every day and are committed to continuing to increase the number of patients we serve.
Advancing healthcare with heart.
With some of the best and brightest minds in the industry, an unmatched global footprint, comprehensive benefits and a distinct culture, Terumo Blood and Cell Technologies is a great place to work, grow and be part of a team that is focused on making a difference.
Join us and help shape wherever we go next. You create your future and ours.
Terumo Blood and Cell Technologies (TBCT) designs, engineers, and builds medical technology that helps save lives. TBCT integrates cybersecurity throughout the total product lifecycle to ensure our products are safe, secure, and effective.
The Product Security Engineer partners with R&D, Quality, Regulatory, and other cross‑functional stakeholders to define, implement, and support cybersecurity activities from initial concept through decommissioning. This role drives secure‑by‑design practices, facilitates product security risk management, and ensures compliance with TBCT’s Product Security Lifecycle Procedure and all associated procedures and work instructions.
ESSENTIAL DUTIES- Define, maintain, and evolve objective, testable, technology‑agnostic product security requirements, ensuring traceability to product security needs, risks, and regulatory expectations.
- Analyze complex technical issues, document findings, and partner with engineering and product teams to drive implementation of risk‑based, secure‑by‑design solutions.
- Lead the development and ongoing maintenance of Product Security Plans, Threat Models, Product Security Reports, and related lifecycle deliverables, ensuring accuracy and alignment throughout the product lifecycle.
- Guide engineering teams in vulnerability identification and analysis, assess post‑market risk, and lead post‑market activities, including threat intelligence integration, vulnerability management, coordinated disclosure, patch planning, and product incident response.
- Lead assessment of third‑party components and suppliers, oversee SBOM creation and maintenance, monitor component lifecycle risk, and proactively identify vulnerabilities or end‑of‑support concerns.
- Lead contributions to customer‑facing and regulatory documentation, including labeling content and cybersecurity documentation for submissions, clearly communicating complex technical findings verbally and in writing.
- Drive updates and continuous improvement of product security procedures, work instructions, and technical guidance documents, ensuring alignment with evolving regulatory and industry standards.
- Provide technical leadership and mentorship to engineering teams, and collaborate closely with R&D architects, Quality, Safety, and Regulatory partners to ensure a cohesive and consistent security posture across the product portfolio.
- Develop, maintain, and enhance the product security test lab environment.
- Actively participate in and influence regulatory, safety, and design reviews.
- Conduct penetration testing directly or manage and oversee third‑party penetration testing vendors, including scoping, execution, and review of findings.
- Play a key role in product incident response activities.
- Represent Product Security in customer, auditor, and regulatory discussions as a subject matter expert.
- Experience with PKI and certificate management for medical devices, including provisioning, rotation, secure storage, and certificate‑based authentication.
- Familiarity with Azure…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).