5 days ago

Logo of Medtronic

Sr Principal Product Security Engineer

$178k - $267k

Medtronic

USBoston, MARemote

We anticipate the application window for this opening will close on - 20 Dec 2024


 

At Medtronic you can begin a life-long career of exploration and innovation, while helping champion healthcare access and equity for all. You’ll lead with purpose, breaking down barriers to innovation in a more connected, compassionate world.

A Day in the Life

Careers that Change Lives

​​​​​​​In this role, you will join a world class team of systems, mechanical, electrical, software, and quality engineers within the Medtronic’s Surgical Operating Unit (OU). This is one new, powerful operating unit bringing together the people and product portfolio of Surgical Robotics and Surgical Innovations. ​​​​​​​​​​​​​​With the Medtronic Mission as our North Star, we will build on our legacy of proven surgical solutions and advance the promise of robotics and digital solutions for the benefit of the customers and patients we serve. 

Make your impact by exploring a career with the world’s leading Medical Device company, striving “to alleviate pain, restore health, and extend life.” 

                                                                                                                                             

A Day in The Life

The Senior Principal Product Security Engineer is instrumental in ensuring the robust security of our Surgical OU medical device products and solutions. Reporting directly to the Director of Product Security, this pivotal role spearheads the integration of state-of-the-art security measures, identifies potential vulnerabilities, and champions initiatives to bolster cyber-resiliency throughout the products life cycle. A profound understanding of regulated embedded devices, environments that underpin client-facing medical device solutions, and adherence to product security compliance frameworks is essential.

Key Responsibilities:

  • Product Security Strategy & Continuous Learning - Engage in continuous professional development to stay updated with the latest cybersecurity trends and threats specific to medical devices and health software products. Contribute to OU and enterprise product security strategy that aligns with industry best practices and regulatory requirements
  • Product Security - Lead efforts to embed security into the product development lifecycle, ensuring that security considerations are integrated from design through deployment. This includes medical device, OT, ICS, IoT, and enterprise security processes / standards
  • Risk Assessment - Systematically perform threat modeling, security risk evaluations, and vulnerability assessments to highlight and mitigate potential security threats throughout the product lifecycle.
  • Security Architecture - Aid in devising and deploying secure medical device solution architectures and product designs, considering factors such as secure boot, secure communications, data protection, secure updates, secure integration, and access controls
  • Security Standards & Testing - Maintain and enforce security standards, policies, and procedures for medical device systems and product development. Oversee security testing activities, including penetration testing, vulnerability scanning, and code reviews
  • Security Awareness - Drive and promote security awareness and training across cross-functional product development teams to foster a security-conscious culture
  • Compliance - Ensure compliance with industry standards and regulations related to medical device and health software product security, such as NIST, IEC 60601-4-5, IEC 81001-5-1, and others.
  • Vendor Assessment - Evaluate third-party vendors and suppliers for their security practices and ensure they meet our security requirements
  • Incident Management - Lead and support the effective response to security incidents, ensuring swift resolution, proper mitigation, and clear communication to stakeholders, including customers when needed.
  • Documentation - Maintain detailed documentation of security best practices, guidance, configurations, design patterns, shared service designs, inventories, incident response plans, security architectures, and reports

Must Have: Minimum Requirements

  • Bachelor’s degree or higher (completed and verified prior to start)
  • Minimum 10 years of relevant experience or advanced degree with a minimum of 8 years of relevant experience.
  • Minimum 5 years of embedded device product security experience in a regulated industry

Nice to Have

  • Master’s degree in related engineering or cybersecurity from an accredited institution
  • Ability to adapt to the fast-evolving cybersecurity landscape and implement proactive strategies.
  • Demonstrated aptitude in identifying challenges and providing innovative solutions.
  • Experience in mentoring and leading junior security engineers, fostering growth within the team.
  • Demonstrated experience in staying updated with evolving regulations in the medical device sector.
  • Industry-recognized certifications such as [CISSP, CSSLP, CISM] are highly desirable
  • Proficiency in secure coding methodologies and standards

About Medtronic
Together, we can change healthcare worldwide. At Medtronic, we push the limits of what technology, therapies and services can do to help alleviate pain, restore health, and extend life.  We challenge ourselves and each other to make tomorrow better than yesterday. It is what makes this an exciting and rewarding place to be.

We want to accelerate and advance our ability to create meaningful innovations - but we will only succeed with the right people on our team. Let’s work together to address universal healthcare needs and improve patients’ lives. Help us shape the future.

Benefits & Compensation

A commitment to our employees lives at the core of our values. We recognize their contributions. They share in the success they help to create.  We offer a wide range of benefits, resources, and competitive compensation plans designed to support you at every career and life stage. This position is eligible for a short-term incentive called the Medtronic Incentive Plan (MIP).  Learn more about MIP and benefits here.

The provided base salary range is used nationally (except in certain CA locations). The rate offered is compliant with federal/local regulations and may vary by experience, certification/education, market conditions, location, etc. 

Physical Job Requirements
The physical demands described within the Responsibilities section of this job description are representative of those that must be met by an employee to successfully perform the essential functions of this job. Reasonable accommodations may be made to enable individuals with disabilities to perform the essential functions.

Physical Job Requirements

The above statements are intended to describe the general nature and level of work being performed by employees assigned to this position, but they are not an exhaustive list of all the required responsibilities and skills of this position. 

The physical demands described within the Responsibilities section of this job description are representative of those that must be met by an employee to successfully perform the essential functions of this job. Reasonable accommodations may be made to enable individuals with disabilities to perform the essential functions. For Office Roles: While performing the duties of this job, the employee is regularly required to be independently mobile. The employee is also required to interact with a computer, and communicate with peers and co-workers. Contact your manager or local HR to understand the Work Conditions and Physical requirements that may be specific to each role.

Benefits & Compensation
 

Medtronic offers a competitive Salary and flexible Benefits Package
A commitment to our employees lives at the core of our values. We recognize their contributions. They share in the success they help to create.  We offer a wide range of benefits, resources, and competitive compensation plans designed to support you at every career and life stage.
 

Salary ranges for U.S (excl. PR) locations (USD):$178,400.00 - $267,600.00

This position is eligible for a short-term incentive called the Medtronic Incentive Plan (MIP).

The base salary range is applicable across the United States, excluding Puerto Rico and specific locations in California. The offered rate complies with federal and local regulations and may vary based on factors such as experience, certification/education, market conditions, and location. Compensation and benefits information pertains solely to candidates hired within the United States (local market compensation and benefits will apply for others).

Medtronic benefits and compensation plans

About Medtronic

We lead global healthcare technology and boldly attack the most challenging health problems facing humanity by searching out and finding solutions.
Our Mission — to alleviate pain, restore health, and extend life — unites a global team of 90,000+ passionate people. 
We are engineers at heart— putting ambitious ideas to work to generate real solutions for real people. From the R&D lab, to the factory floor, to the conference room, every one of us experiments, creates, builds, improves and solves. We have the talent, diverse perspectives, and guts to engineer the extraordinary.

Learn more about our business, mission, and our commitment to diversity here.

It is the policy of Medtronic to provide equal employment opportunity (EEO) to all persons regardless of age, color, national origin, citizenship status, physical or mental disability, race, religion, creed, gender, sex, sexual orientation, gender identity and/or expression, genetic information, marital status, status with regard to public assistance, veteran status, or any other characteristic protected by federal, state or local law. In addition, Medtronic will provide reasonable accommodations for qualified individuals with disabilities.