Remote; PST-Engineer Sr - Embedded Product Security
Santa Barbara, Santa Barbara County, California, 93190, USA
Listed on 2025-12-08
-
IT/Tech
Cybersecurity, Systems Engineer
Senior Embedded Product Security Engineer
Requisition
Division:
Arthrex, Inc. (US01)
Location:
Santa Barbara, CA and Remote/Hybrid (PST time zone preference)
Salary Range: $ – $
Secure the Future of Healthcare—One Device at a Time.
At Arthrex, we’re not just building medical devices—we’re shaping the future of healthcare. Our mission is simple yet powerful:
Helping Surgeons Treat Their Patients Better™. Now, we’re looking for a visionary engineer to help us secure the next generation of connected and IoT medical technology.
If you thrive on solving complex security challenges and want your work to make a real impact on lives worldwide, this is your moment.
Why This Role MattersAs our Sr. Embedded Product Security Engineer
, you’ll be a guardian of innovation—ensuring every device we create is secure, resilient, and trusted. You’ll collaborate with elite product design teams, dive deep into architecture reviews, and lead the charge in vulnerability testing. Your expertise will shape global regulatory submissions and protect cutting‑edge and legacy medical technology.
- Lead and take ownership of product security across a product line.
- Architect security solutions for embedded systems and IoT devices.
- Drive security initiatives for advanced technologies—including robotics and AI/ML‑driven systems.
- Hunt vulnerabilities, assess risk, and design countermeasures that keep attackers at bay.
- Drive Security‑by‑Design and Privacy‑by‑Design principles across development.
- Work closely with Legal, Compliance, Regulatory, and Enterprise IT to align product security with international regulations and organizational policies.
- Represent Arthrex at premier security events like DEF CON, Black Hat, and Health‑ISAC Conferences.
- Document and champion our Secure Product Development Framework.
- Experience: 5+ years in cybersecurity‑focused positions spanning software engineering, IoT and SCADA environments, regulated industries (medical device/pharma), or hardware security testing.
- Education: Bachelor’s in Software Engineering, Computer Science, Software‑focused Cybersecurity, or related field.
- Leadership & Ownership: A proven track record of leading and owning security for products, influencing design decisions and guiding teams through the full product lifecycle—from concept to global launch.
- Ensuring Security in a Dynamic, Evolving Landscape: Embrace change and ambiguity as opportunities, ensuring security remains a constant in an environment of rapid innovation.
- Strategic Mindset: Ability to embed security into every phase of development, ensuring compliance, resilience, and innovation.
- Bonus
Certifications:
CISSP, OSCP, OSWE, CSSLP, GIAC. - Technical
Skills:- Securing Embedded systems, firmware, real‑time OS (RTOS), IoT lifecycle.
- Proficiency in advanced application security methodologies (OWASP Top 10, MITRE CWEs and ATT&CK).
- Architecture design, threat modeling, and vulnerability mitigations.
- Demonstrated experience in SBOMs and third‑party software risk management, coupled with building automated CI/CD workflows for embedded systems in C/C++ and Python.
- Bonus
Skills:
Yocto Project, FDA/ISO guidelines, Robotics, Machine Learning, Computer Vision, HL7, PACS, FPGA.
- Work on technology designed to improve patient outcomes and enhance quality of life.
- Experience the stability and vision of a privately held organization with global reach.
- Access world‑class training and certifications.
- Network with the best minds in medical device cybersecurity and compliance.
- Be part of a culture that values innovation, collaboration, speed, and impact.
Apply now and become the force that keeps our technology—and our patients—safe.
Essential Duties and Responsibilities- Designs security architecture of components or functional systems and modifies existing designs to develop or improve products.
- Recommends alterations to development and design to improve the security of products and/or procedures.
- Contributes to a broader design perspective and considers how an application interacts with the underlying infrastructure or external resources.
- Develops threat scenarios and designs responses…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).