Lead Product Security Engineer safeguarding cybersecurity for medical devices within Medtronic's Surgical Operating Unit. Collaborate across teams to mitigate vulnerabilities and improve security posture.
Responsibilities
Engage in continuous professional development to stay updated with the latest cybersecurity trends and threats specific to medical devices and health software products.
Contribute to OU and enterprise product security strategy that aligns with industry best practices and regulatory requirements
Lead efforts to embed security into the product development lifecycle, ensuring that security considerations are integrated from design through deployment.
Systematically perform threat modeling, security risk evaluations, and vulnerability assessments to highlight and mitigate potential security threats throughout the product lifecycle.
Aid in devising and deploying secure medical device solution architectures and product designs, considering factors such as secure boot, secure communications, data protection, secure updates, secure integration, and access controls
Maintain and enforce security standards, policies, and procedures for medical device systems and product development.
Oversee security testing activities, including penetration testing, vulnerability scanning, and code reviews
Drive and promote security awareness and training across cross-functional product development teams to foster a security-conscious culture
Ensure compliance with industry standards and regulations related to medical device and health software product security, such as NIST, IEC 60601-4-5, IEC 81001-5-1, and others.
Evaluate third-party vendors and suppliers for their security practices and ensure they meet our security requirements
Lead and support the effective response to security incidents, ensuring swift resolution, proper mitigation, and clear communication to stakeholders, including customers when needed.
Maintain detailed documentation of security best practices, guidance, configurations, design patterns, shared service designs, inventories, incident response plans, security architectures, and reports
Requirements
Bachelor’s degree or higher (completed and verified prior to start)
Minimum 10 years of relevant experience or advanced degree with a minimum of 8 years of relevant experience.
Minimum 5 years of embedded device product security experience in a regulated industry
Ability to adapt to the fast-evolving cybersecurity landscape and implement proactive strategies.
Demonstrated aptitude in identifying challenges and providing innovative solutions.
Experience in mentoring and leading junior security engineers, fostering growth within the team.
Demonstrated experience in staying updated with evolving regulations in the medical device sector.
Industry-recognized certifications such as [CISSP, CSSLP, CISM] are highly desirable
Proficiency in secure coding methodologies and standards
Benefits
Health, Dental and vision insurance
Health Savings Account
Healthcare Flexible Spending Account
Life insurance
Long-term disability leave
Dependent daycare spending account
Tuition assistance/reimbursement
Simple Steps (global well-being program)
Incentive plans
401(k) plan plus employer contribution and match
Short-term disability
Paid time off
Paid holidays
Employee Stock Purchase Plan
Employee Assistance Program
Non-qualified Retirement Plan Supplement (subject to IRS earning minimums)
Capital Accumulation Plan (available to Vice Presidents and above, or subject to IRS earning minimums)
CISO managing corporate - wide information security strategy for Duisburger Versorgungs - und Verkehrsgesellschaft mbH. Overseeing risk management and compliance with legal standards in information security.
Security Specialist focusing on creating and enforcing security policies for EDGE Group in Abu Dhabi. Conducting security assessments and overseeing the security team's daily operations.
Personal Security Advisor responsible for securing the CEO and other Senior Officers at PG&E. Conducting threat assessments, providing protection, and coordinating travel security.
IAM Info Security Controls Specialist at Bank of America analyzing and securing identity access systems. Collaborating with teams to enhance compliance and governance across IAM practices.
Director of Information Security overseeing LATAM operations for BCD Travel. Leading cybersecurity strategy, risk management and collaboration with regional leadership teams.
Trainee in Offensive Security with a focus on hands - on training and real projects. Develop skills in vulnerability detection, cybersecurity, and offensive tools within a specialized team.
Physical Security Shift Supervisor ensuring safety and administering security measures at Broadridge's Edgewood location. Overseeing a team and coordinating security operations during scheduled shifts.
Connected Vehicle Cybersecurity Manager securing automotive products against cyber threats. Lead engineering team to ensure compliance and drive security strategies in connected vehicle ecosystem.
Senior Information Security Engineer supporting advanced cybersecurity operations in AWS environment. Leading security measures and risk assessments to protect organizations from cyber threats.
Senior SAP Security IAM Consultant at Wavestone shaping digital security for clients in Switzerland. Engaging in holistic security architecture and innovative solutions with a strong team spirit.