Logo
Medtronic

-Principal Product Security Engineer

Medtronic, North Haven, Connecticut, us, 06473

Save Job

We anticipate the application window for this opening will close on - 27 Aug 2025. At Medtronic, you can begin a lifelong career of exploration and innovation, helping champion healthcare access and equity for all. You’ll lead with purpose, breaking down barriers to innovation in a more connected, compassionate world. A Day in the Life

The Principal Product Security Engineer plays a critical role in ensuring the security of Medtronic Surgical Operating Unit medical device solutions. Reporting to the Director of Product Security, this role drives the integration of advanced cybersecurity measures, identifies and mitigates potential vulnerabilities, and supports initiatives that improve cyber-resiliency throughout the product lifecycle. You will serve as a technical subject matter expert and mentor, collaborating across teams and contributing to long-term improvements in our security posture. Careers that Change Lives

In this engineering-focused role, you will join a world-class team of systems, mechanical, electrical, software, and quality engineers within Medtronic’s Surgical Operating Unit (OU). The Surgical OU advances surgical care through robotics, surgical energy technologies, and digital solutions. This role focuses on cybersecurity for medical devices and embedded systems. It is not an IT security, compliance, or GRC-focused position. The ideal candidate will have deep experience working with engineering teams to integrate cybersecurity into real-time systems, embedded firmware, connected devices, or other product-level security contexts. With the Medtronic Mission as our North Star, we build on our legacy of proven surgical solutions and continue advancing robotics and digital technologies to improve outcomes for our customers and patients. Make your impact by exploring a career with the world’s leading Medical Device company, striving “to alleviate pain, restore health, and extend life.” A Day in The Life

The Principal Product Security Engineer plays a critical role in ensuring the security of Medtronic Surgical Operating Unit medical device solutions. Reporting to the Director of Product Security, this role drives the integration of advanced cybersecurity measures, identifies and mitigates potential vulnerabilities, and supports initiatives that improve cyber-resiliency throughout the product lifecycle. You will serve as a technical subject matter expert and mentor, collaborating across teams and contributing to long-term improvements in our security posture. Key Responsibilities

Product Security Strategy & Continuous Learning

- Stay abreast of emerging cybersecurity threats, technologies, and regulations specific to medical devices and health software. Contribute to OU and enterprise-wide product security strategy and roadmap development. Secure Product Development Lifecycle

- Drive security integration into all stages of the product lifecycle, from concept and design to postmarket. Work closely with system architects, software leads, and hardware engineers to embed secure design patterns in both embedded and cloud-connected environments. Threat Modeling & Risk Assessment

- Lead threat modeling sessions, conduct security risk assessments, and identify mitigation strategies in accordance with IEC 81001-5-1, ISO 14971, and FDA premarket cybersecurity guidance. Security Architecture & Design

- Collaborate on the design and implementation of secure architectures, focusing on secure boot, secure communications, data protection, access control, secure software updates, and hardware-software integration. Security Testing & Analysis

- Support and interpret results from vulnerability scans, penetration tests, and static/dynamic code analysis. Coordinate with internal teams and third-party vendors to ensure timely and appropriate risk mitigation. Security Awareness & Mentorship

- Promote a culture of security awareness within R&D and provide mentorship to junior engineers. Lead by example through documentation, review participation, and active knowledge sharing. Regulatory & Standards Compliance

- Ensure alignment with applicable standards (e.g., NIST, IEC 60601-4-5, IEC 81001-5-1) and support security documentation efforts for global regulatory submissions. Vendor & Supply Chain Security

- Review and assess the cybersecurity posture of third-party suppliers and open-source software components used within product designs. Incident Response Support

- Provide technical leadership during postmarket security incidents or field issues. Lead root cause investigations, containment strategies, and risk assessments. Security Documentation

- Maintain comprehensive security documentation, including threat model diagrams, risk assessments, shared service inventories, design patterns, security guidelines, and product security plans/reports. Must Have Requirements

Bachelor’s degree with 7 years of experience Or advanced degree with 5 years of technical experience Nice to Have

Bachelor’s degree in a relevant engineering field (e.g., Computer Engineering, Software Engineering), completed and verified prior to start Minimum 3 years of experience integrating security into embedded systems or connected medical devices in a regulated environment Strong understanding of SDLC, secure boot, cryptography, secure firmware update, secure communication, and hardware/software interface security Master’s degree in engineering or cybersecurity Industry-recognized certifications (e.g., CISSP, CSSLP, CISM, CEH) Experience mentoring or guiding junior security engineers Ability to implement secure architecture in embedded and connected device ecosystems Knowledge of FDA and MDR cybersecurity submission requirements Knowledge of secure coding practices and vulnerabilities (e.g., OWASP, CWE, CVSS) Experience with design reviews or design assurance processes Working knowledge of secure boot chains, cryptography, and device authentication protocols Physical Job Requirements

Describes the general nature of work and physical demands, including mobility, interaction with computers, and communication. Reasonable accommodations may be provided. Benefits & Compensation

Medtronic offers a competitive salary and benefits package.

We recognize contributions and support employees at every stage of their careers and lives. Benefits include health, dental, vision, HSA, FSA, life insurance, disability, tuition reimbursement, and well-being programs. Salary range for U.S. locations: $152,800 - $229,200. This position is eligible for a short-term incentive plan. Compensation varies based on experience, education, market, and location. Benefits for employees working 20+ hours per week include insurance, savings accounts, and more. Further details are available at the link below: Medtronic benefits and compensation plans About Medtronic

We lead global healthcare technology, aiming to solve challenging health problems. Our mission is to alleviate pain, restore health, and extend life, driven by a passionate team of over 95,000 people. We innovate across R&D, manufacturing, and more, with a commitment to diversity and inclusion. Learn more about our business, mission, and diversity efforts

here . Medtronic is an equal opportunity employer, providing accommodations for disabilities. For jobs involving work in Los Angeles County, see the detailed job duties and fair chance policies

here .

#J-18808-Ljbffr