BioCT Innovation Commons
Sr Principal Product Security Engineer
BioCT Innovation Commons, California, Missouri, United States, 65018
We anticipate the application window for this opening will close on - 6 Dec 2025
At Medtronic you can begin a life-long career of exploration and innovation, while helping champion healthcare access and equity for all. You’ll lead with purpose, breaking down barriers to innovation in a more connected, compassionate world.
A Day in the Life The Sr Principal Product Security Engineer plays a critical role in ensuring the security of Medtronic Surgical Operating Unit medical device solutions. Reporting to the Director of Product Security, this role drives the integration of advanced cybersecurity measures, identifies and mitigates potential vulnerabilities, and supports initiatives that improve cyber-resiliency throughout the product lifecycle. You will serve as a technical subject matter expert and mentor, collaborating across teams and contributing to long-term improvements in our security posture.
In this engineering‑focused role, you will join a world‑class team of systems, mechanical, electrical, software, and quality engineers within Medtronic’s Surgical Operating Unit (OU). The Surgical OU brings together the people and portfolios of Surgical Robotics and Surgical Innovations to advance surgical care through robotics, surgical energy technologies, and digital solutions.
This role focuses on cybersecurity for medical devices and embedded systems. It is not an IT security, compliance, or GRC‑focused position. The ideal candidate will have deep experience working with engineering teams to integrate cybersecurity into real‑time systems, embedded firmware, connected devices, or other product‑level security contexts.
With the Medtronic Mission as our North Star, we build on our legacy of proven surgical solutions and continue advancing the promise of robotics and digital technologies to improve outcomes for our customers and patients.
This is an onsite role and can be located in our London office or one of these US based office locations: Boston, MA, Lafayette, CO, Minneapolis, MN, or North Haven, CT with a strong preference of Boston or Lafayette.
Make your impact by exploring a career with the world’s leading Medical Device company, striving “to alleviate pain, restore health, and extend life.”
Key Responsibilities
Product Security Strategy & Continuous Learning - Engage in continuous professional development to stay updated with the latest cybersecurity trends and threats specific to medical devices and health software products. Contribute to OU and enterprise product security strategy that aligns with industry best practices and regulatory requirements.
Product Security - Lead efforts to embed security into the product development lifecycle, ensuring that security considerations are integrated from design through deployment. This includes medical device, OT, ICs, IoT, and enterprise security processes / standards.
Risk Assessment - Systematically perform threat modeling, security risk evaluations, and vulnerability assessments to highlight and mitigate potential security threats throughout the product lifecycle.
Security Architecture - Aid in devising and deploying secure medical device solution architectures and product designs, considering factors such as secure boot, secure communications, data protection, secure updates, secure integration, and access controls.
Security Standards & Testing - Maintain and enforce security standards, policies, and procedures for medical device systems and product development. Oversee security testing activities, including penetration testing, vulnerability scanning, and code reviews.
Security Awareness - Drive and promote security awareness and training across cross‑functional product development teams to foster a security‑conscious culture.
Compliance - Ensure compliance with industry standards and regulations related to medical device and health software product security, such as NIST, IEC 60601‑4‑5, IEC 81001‑5‑1, and others.
Vendor Assessment - Evaluate third‑party vendors and suppliers for their security practices and ensure they meet our security requirements.
Incident Management - Lead and support the effective response to security incidents, ensuring swift resolution, proper mitigation, and clear communication to stakeholders, including customers when needed.
Documentation - Maintain detailed documentation of security best practices, guidance, configurations, design patterns, shared service designs, inventories, incident response plans, security architectures, and reports.
Must Have: Minimum Requirements
Bachelor’s degree or higher (completed and verified prior to start)
Minimum 10 years of relevant experience or advanced degree with a minimum of 8 years of relevant experience.
Minimum 5 years of embedded device product security experience in a regulated industry.
Nice to Have
Master’s degree in related engineering or cybersecurity from an accredited institution.
Ability to adapt to the fast‑evolving cybersecurity landscape and implement proactive strategies.
Demonstrated aptitude in identifying challenges and providing innovative solutions.
Experience in mentoring and leading junior security engineers, fostering growth within the team.
Demonstrated experience in staying updated with evolving regulations in the medical device sector.
Industry‑recognized certifications such as CISSP, CSSLP, CISM are highly desirable.
Proficiency in secure coding methodologies and standards.
Physical Job Requirements The above statements describe the general nature and level of work. Physical demands are described within the Responsibilities section. Reasonable accommodations may be made. For Office Roles: regularly required to be independently mobile, use computer, communicate with peers and co‑workers. Contact your manager or local HR to understand specific conditions.
Benefits & Compensation Medtronic offers a competitive salary and flexible benefits package. A commitment to our employees’ lives is at the core of our values. We recognize their contributions and share in their success. We offer a wide range of benefits, resources, and competitive compensation plans designed to support you at every career and life stage.
Salary ranges for U.S. (excluding Puerto Rico) are $187,200.00 – $280,800.00. This base salary range is applicable across the U.S., excluding Puerto Rico and specific locations in California. The offered rate complies with federal and local regulations and may vary based on factors such as experience, certification/education, market conditions, and location. Compensation and benefits information pertains solely to candidates hired within the United States.
Benefits for regular employees working 20+ hours per week include Health, Dental, and Vision insurance, Health Savings Account, Healthcare Flexible Spending Account, Life insurance, Long‑term disability leave, Dependent daycare spending account, Tuition assistance/reimbursement, and Simple Steps (global well‑being program).
Benefits for all regular employees include Incentive plans, 401(k) plan plus employer contribution and match, Short‑term disability, Paid time off, Paid holidays, Employee Stock Purchase Plan, Employee Assistance Program, Non‑qualified Retirement Plan Supplement, and Capital Accumulation Plan (for VP and above, or subject to IRS earning minimums).
Regular employees are those who are not temporary, such as interns. Temporary employees are eligible for paid sick time as required by state law and the Employee Stock Purchase Plan. Notices may not apply to workers in Puerto Rico.
Further details are available at Medtronic benefits and compensation plans.
About Medtronic We lead global healthcare technology and boldly attack the most challenging health problems facing humanity by searching out and finding solutions. Our Mission — to alleviate pain, restore health, and extend life — unites a global team of 95,000+ passionate people. We are engineers at heart— putting ambitious ideas to work to generate real solutions for real people. From the R&D lab, to the factory floor, to the conference room, every one of us experiments, creates, builds, improves and solves. We have the talent, diverse perspectives, and guts to engineer the extraordinary.
Learn more about our business, mission, and our commitment to diversity.
It is the policy of Medtronic to provide equal employment opportunity (EEO) to all persons regardless of age, color, national origin, citizenship status, physical or mental disability, race, religion, creed, gender, sex, sexual orientation, gender identity, and/or expression, genetic information, marital status, status with regard to public assistance, veteran status, or any other characteristic protected by federal, state or local law. In addition, Medtronic will provide reasonable accommodations for qualified individuals with disabilities.
If you are applying to perform work for Medtronic, Inc. in any position which will involve performing at least two hours of work on average each week within the unincorporated areas of Los Angeles County, you can find a list of all material job duties at the Medtronic website. Medtronic will consider for employment qualified job applicants with arrest or conviction records in accordance with the Los Angeles County Fair Chance Ordinance for Employers and the California Fair Chance Act.
#J-18808-Ljbffr
At Medtronic you can begin a life-long career of exploration and innovation, while helping champion healthcare access and equity for all. You’ll lead with purpose, breaking down barriers to innovation in a more connected, compassionate world.
A Day in the Life The Sr Principal Product Security Engineer plays a critical role in ensuring the security of Medtronic Surgical Operating Unit medical device solutions. Reporting to the Director of Product Security, this role drives the integration of advanced cybersecurity measures, identifies and mitigates potential vulnerabilities, and supports initiatives that improve cyber-resiliency throughout the product lifecycle. You will serve as a technical subject matter expert and mentor, collaborating across teams and contributing to long-term improvements in our security posture.
In this engineering‑focused role, you will join a world‑class team of systems, mechanical, electrical, software, and quality engineers within Medtronic’s Surgical Operating Unit (OU). The Surgical OU brings together the people and portfolios of Surgical Robotics and Surgical Innovations to advance surgical care through robotics, surgical energy technologies, and digital solutions.
This role focuses on cybersecurity for medical devices and embedded systems. It is not an IT security, compliance, or GRC‑focused position. The ideal candidate will have deep experience working with engineering teams to integrate cybersecurity into real‑time systems, embedded firmware, connected devices, or other product‑level security contexts.
With the Medtronic Mission as our North Star, we build on our legacy of proven surgical solutions and continue advancing the promise of robotics and digital technologies to improve outcomes for our customers and patients.
This is an onsite role and can be located in our London office or one of these US based office locations: Boston, MA, Lafayette, CO, Minneapolis, MN, or North Haven, CT with a strong preference of Boston or Lafayette.
Make your impact by exploring a career with the world’s leading Medical Device company, striving “to alleviate pain, restore health, and extend life.”
Key Responsibilities
Product Security Strategy & Continuous Learning - Engage in continuous professional development to stay updated with the latest cybersecurity trends and threats specific to medical devices and health software products. Contribute to OU and enterprise product security strategy that aligns with industry best practices and regulatory requirements.
Product Security - Lead efforts to embed security into the product development lifecycle, ensuring that security considerations are integrated from design through deployment. This includes medical device, OT, ICs, IoT, and enterprise security processes / standards.
Risk Assessment - Systematically perform threat modeling, security risk evaluations, and vulnerability assessments to highlight and mitigate potential security threats throughout the product lifecycle.
Security Architecture - Aid in devising and deploying secure medical device solution architectures and product designs, considering factors such as secure boot, secure communications, data protection, secure updates, secure integration, and access controls.
Security Standards & Testing - Maintain and enforce security standards, policies, and procedures for medical device systems and product development. Oversee security testing activities, including penetration testing, vulnerability scanning, and code reviews.
Security Awareness - Drive and promote security awareness and training across cross‑functional product development teams to foster a security‑conscious culture.
Compliance - Ensure compliance with industry standards and regulations related to medical device and health software product security, such as NIST, IEC 60601‑4‑5, IEC 81001‑5‑1, and others.
Vendor Assessment - Evaluate third‑party vendors and suppliers for their security practices and ensure they meet our security requirements.
Incident Management - Lead and support the effective response to security incidents, ensuring swift resolution, proper mitigation, and clear communication to stakeholders, including customers when needed.
Documentation - Maintain detailed documentation of security best practices, guidance, configurations, design patterns, shared service designs, inventories, incident response plans, security architectures, and reports.
Must Have: Minimum Requirements
Bachelor’s degree or higher (completed and verified prior to start)
Minimum 10 years of relevant experience or advanced degree with a minimum of 8 years of relevant experience.
Minimum 5 years of embedded device product security experience in a regulated industry.
Nice to Have
Master’s degree in related engineering or cybersecurity from an accredited institution.
Ability to adapt to the fast‑evolving cybersecurity landscape and implement proactive strategies.
Demonstrated aptitude in identifying challenges and providing innovative solutions.
Experience in mentoring and leading junior security engineers, fostering growth within the team.
Demonstrated experience in staying updated with evolving regulations in the medical device sector.
Industry‑recognized certifications such as CISSP, CSSLP, CISM are highly desirable.
Proficiency in secure coding methodologies and standards.
Physical Job Requirements The above statements describe the general nature and level of work. Physical demands are described within the Responsibilities section. Reasonable accommodations may be made. For Office Roles: regularly required to be independently mobile, use computer, communicate with peers and co‑workers. Contact your manager or local HR to understand specific conditions.
Benefits & Compensation Medtronic offers a competitive salary and flexible benefits package. A commitment to our employees’ lives is at the core of our values. We recognize their contributions and share in their success. We offer a wide range of benefits, resources, and competitive compensation plans designed to support you at every career and life stage.
Salary ranges for U.S. (excluding Puerto Rico) are $187,200.00 – $280,800.00. This base salary range is applicable across the U.S., excluding Puerto Rico and specific locations in California. The offered rate complies with federal and local regulations and may vary based on factors such as experience, certification/education, market conditions, and location. Compensation and benefits information pertains solely to candidates hired within the United States.
Benefits for regular employees working 20+ hours per week include Health, Dental, and Vision insurance, Health Savings Account, Healthcare Flexible Spending Account, Life insurance, Long‑term disability leave, Dependent daycare spending account, Tuition assistance/reimbursement, and Simple Steps (global well‑being program).
Benefits for all regular employees include Incentive plans, 401(k) plan plus employer contribution and match, Short‑term disability, Paid time off, Paid holidays, Employee Stock Purchase Plan, Employee Assistance Program, Non‑qualified Retirement Plan Supplement, and Capital Accumulation Plan (for VP and above, or subject to IRS earning minimums).
Regular employees are those who are not temporary, such as interns. Temporary employees are eligible for paid sick time as required by state law and the Employee Stock Purchase Plan. Notices may not apply to workers in Puerto Rico.
Further details are available at Medtronic benefits and compensation plans.
About Medtronic We lead global healthcare technology and boldly attack the most challenging health problems facing humanity by searching out and finding solutions. Our Mission — to alleviate pain, restore health, and extend life — unites a global team of 95,000+ passionate people. We are engineers at heart— putting ambitious ideas to work to generate real solutions for real people. From the R&D lab, to the factory floor, to the conference room, every one of us experiments, creates, builds, improves and solves. We have the talent, diverse perspectives, and guts to engineer the extraordinary.
Learn more about our business, mission, and our commitment to diversity.
It is the policy of Medtronic to provide equal employment opportunity (EEO) to all persons regardless of age, color, national origin, citizenship status, physical or mental disability, race, religion, creed, gender, sex, sexual orientation, gender identity, and/or expression, genetic information, marital status, status with regard to public assistance, veteran status, or any other characteristic protected by federal, state or local law. In addition, Medtronic will provide reasonable accommodations for qualified individuals with disabilities.
If you are applying to perform work for Medtronic, Inc. in any position which will involve performing at least two hours of work on average each week within the unincorporated areas of Los Angeles County, you can find a list of all material job duties at the Medtronic website. Medtronic will consider for employment qualified job applicants with arrest or conviction records in accordance with the Los Angeles County Fair Chance Ordinance for Employers and the California Fair Chance Act.
#J-18808-Ljbffr