Senior Product Security Engineer at Medtronic focusing on cybersecurity for medical device products. Leading vulnerability assessments and coordinating responses to security incidents.
Responsibilities
Act as Senior Product Security Engineer, reporting to the Senior Engineering Director.
Act as a member of the PSIRT (Product Security Incident Response Team).
Support ongoing assessment of product security related “signals” pertaining to potential vulnerabilities and/or incidents regarding Medtronic connected products.
Provide both planned and on-demand support for vulnerability assessments for Medtronic businesses in support of regulatory activities.
Readiness for meeting forthcoming cybersecurity reporting requirements in CY 2026 from US Cyber Incident Reporting for Critical Infrastructure Act (CIRCIA) and EU Cyber Resilience Act.
Support identification, documentation, and assessment of technology, tools, and associated processes in use by the PSO.
Assist in developing an appropriate architecture framework in alignment with the key strategic pillars of Security by Design and Vulnerability Vigilance.
Participate in conducting an industry assessment for appropriate tooling/solution selection.
Implement proposed framework to improve PSO visibility, reporting, metrics, and overall maturity in the PSO strategy.
Support enterprise quality program for SBOMs (“Software Bill of Materials”) with adherence to industry defined standards such as CycloneDX, SPDX (“Software Package Data Exchange”), VEX (“Vulnerability Exploitability eXchange”).
Enable creation of high-quality SBOMs and dissemination of best practices for SBOM generation in support of internal teams and external partners.
Requirements
Requires a Bachelors degree and minimum of 4 years of relevant experience OR Master's degree with a minimum of 2 years relevant experience OR PhD with 0 years relevant experience.
5-10 years of program management/development experience with a bachelor’s degree
Experience in Product Security and Cyber Security
Excellent written and verbal communication skills including demonstrated influence of stakeholders across an organization
Occasional after-hours availability to accommodate different regional and global partners.
Experience working in a regulated environment and/or a formal quality system
Some technical and troubleshooting skills.
Strong capability to research and evaluate emerging technologies.
Preference is given to those with relevant product security or engineering experience.
Strong in interpersonal communication and demonstrate a collaborative work style.
Comfortable working in an ambiguous environment.
Innovative thinker; ability to think outside of the current norms and processes
Independent self-starter
Strong communication and collaboration skills
Solid writing and presentation skills
Interest in novel applications of technology
Experience integrating Shift-left security tools and practices
Familiarity with Git-based workflows and foundational python skills
Work with outside vendors, and support product teams that work with vendors.
Strengthen relationships with critical Engineering, Quality, Regulatory Affairs, Global Security office, Global IT, and Leadership stakeholders in Operating Units.
Benefits
Health, Dental and vision insurance
Health Savings Account
Healthcare Flexible Spending Account
Life insurance
Long-term disability leave
Dependent daycare spending account
Tuition assistance/reimbursement
Simple Steps (global well-being program)
Incentive plans
401(k) plan plus employer contribution and match
Short-term disability
Paid time off
Paid holidays
Employee Stock Purchase Plan
Employee Assistance Program
Non-qualified Retirement Plan Supplement (subject to IRS earning minimums)
Capital Accumulation Plan (available to Vice Presidents and above, or subject to IRS earning minimums)
Security Architect for developing hybrid security architectures and ensuring compliance within IT team at LUZA Group, Portugal. Requires solid architecture and security experience with health sector preference.
Cybersecurity Threat Detection Engineer optimizing detection logic for CMA CGM's global cybersecurity operations. Collaborating with SOC and threat intelligence to improve threat detection capabilities.
Supervisor of Regional Security responsible for overseeing security at ATC Nigeria sites. Ensuring safety, conducting investigations, and managing security initiatives.
Security Officer providing services and maintaining safety for guests at United Security. Requires Florida Class D Security License and willingness to work all shifts and weekends.
Cloud Security Engineer responsible for deploying and securing cloud solutions across AWS, Azure, and Google Cloud platforms. Collaborates with IT and external stakeholders on cloud security initiatives.
IT Analyst for Cyber Security analyzing IT systems and networks for vulnerabilities. Working on securing systems and applications with a hands - on approach in a collaborative team.
Associate Manager responsible for leading security solutions delivery. Overseeing project design and management, while building trust with clients and teams.
Security Team Leader contributing to the safety of PTB facilities in Germany. Leading personnel and coordinating with internal and external security providers in a shift system.