Sr. Product Security Engineer - (Embedded/IoT)
Role details
Job location
Tech stack
Job description
Product Security Engineering - Embed security requirements into the medical device development lifecycle, partnering with R&D and systems teams from architecture through release.
Threat Modeling & Risk Assessment - Perform system-level threat modeling (e.g., STRIDE or similar), attack surface analysis, and vulnerability assessments for connected and embedded medical devices.
Secure Architecture - Support and review implementation of device security capabilities such as:
- Securebootandrootof trust
- Secure firmware/software update mechanisms
- Device identity and authentication
- Secure communications and protocol hardening
- Data protection at rest and in transit
- Key management and Hardware Security Module (HSM) concepts
Cryptography & Post-Quantum Readiness - Apply modern cryptographic principles and support forward-looking strategies including quantum-resistant approaches where applicable.
Secure SDLC Integration - Partner with agile development teams to embed security into design reviews, code reviews, CI/CD pipelines, and verification activities.
Verification & Validation - Define and support security V&V activities including penetration testing, static/dynamic analysis, fuzz testing, and vulnerability management.
Standards & Compliance - Ensure alignment with medical device cybersecurity expectations including:
- FDA premarket cybersecurity guidance
- IEC 81001-5-1
- ISO 14971
- NIST frameworks
- Relevant Medtronic quality processes
Incident & Vulnerability Management - Support coordinated vulnerability disclosure, post-market monitoring, and security issue response for released products.
Cross-Functional Partnership - Work closely with R&D, systems, software, quality, and regulatory teams to drive secure product development.
Industry Awareness - Maintain awareness of evolving threats, healthcare cybersecurity trends, and regulatory expectations for connected medical devices.
Requirements
Bachelor's degree in Computer Science, Computer Engineering, Electrical Engineering, or related technical field and 4+ years of experience in:
- Embedded/device security
- IoT security
- Product security engineering
- OR advanced degree with 2+ years of relevant experience
To Be Successful in This Role :
Device/Product Security Depth - Demonstrated hands-on experience securing embedded or connected products (medical device experience strongly preferred).
Threat Modeling Expertise - Practical experience performing system or device-level threat modeling and risk assessments.
Embedded/IoT Security Knowledge - Strong understanding of:
- Embedded systems
- Firmware/software interactions
- Device communications
- Hardware-software security boundaries
Cryptography Fundamentals - Working knowledge of:
- Modern cryptographic primitives
- Key management
- PKI concepts
- Secure protocol implementation
Regulatory Awareness - Familiarity with medical device cybersecurity expectations and regulated product environments.
Secure Development Practices - Experience working with agile teams and integrating security into SDLC/DevSecOps workflows.
Collaboration Skills - Strong ability to influence cross-functional engineering teams.
Technical Skills
- Embedded or IoT security
- Threat modeling methodologies (STRIDE or similar)
- Secure boot / root of trust concepts
- Secure firmware update mechanisms
- Network and device protocol security
- Cryptography and key management
- Vulnerability assessment and penetration testing
- Familiarity with NIST, MITRE, OWASP (device context)
Preferred:
- Medical device cybersecurity experience
- Experience with IEC 81001-5-1
- Experience with FDA cybersecurity submissions
- Background in connected healthcare products
- Security certifications (Security+, CISSP, etc.)
For Baccalaureate degrees earned outside of the United States, a degree that satisfies the requirements of 8 C.F.R. § 214.2(h)(4)(iii)(A) is required.
Benefits & conditions
At Medtronic, we are committed to fostering an environment where employees can thrive and make a meaningful impact. In alignment with our enterprise-wide workforce planning approach, U.S. work authorization sponsorship (H-1B, TN, J, etc.) is offered exclusively for Principal-level roles and above, where specialized expertise aligns with long-term business needs. Roles below the Principal level require candidates to possess unrestricted U.S. work authorization at the time of hire and for the duration of employment.
Join us in our mission to alleviate pain, restore health, and extend life-where your unique background and perspective are valued.
Benefits & Compensation
Medtronic offers a competitive Salary and flexible Benefits Package
A commitment to our employees lives at the core of our values. We recognize their contributions. They share in the success they help to create. We offer a wide range of benefits, resources, and competitive compensation plans designed to support you at every career and life stage.
Salary ranges for U.S (excl. PR) locations (USD):$98,400.00 - $147,600.00
This position is eligible for a short-term incentive called the Medtronic Incentive Plan (MIP).
The base salary range is applicable across the United States, excluding Puerto Rico and specific locations in California. The offered rate complies with federal and local regulations and may vary based on factors such as experience, certification/education, market conditions, and location. Compensation and benefits information pertains solely to candidates hired within the United States (local market compensation and benefits will apply for others).
The following benefits and additional compensation are available to those regular employees who work 20+ hours per week: Health, Dental and vision insurance, Health Savings Account, Healthcare Flexible Spending Account, Life insurance, Long-term disability leave, Dependent daycare spending account, Tuition assistance/reimbursement, and Simple Steps (global well-being program).
The following benefits and additional compensation are available to all regular employees: Incentive plans, 401(k) plan plus employer contribution and match, Short-term disability, Paid time off, Paid holidays, Employee Stock Purchase Plan, Employee Assistance Program, Non-qualified Retirement Plan Supplement (subject to IRS earning minimums), and Capital Accumulation Plan (available to Vice Presidents and above, or subject to IRS earning minimums).
Regular employees are those who are not temporary, such as interns. Temporary employees are eligible for paid sick time, as required under applicable state law, and the Employee Stock Purchase Plan. Please note some of the above benefits may not apply to workers in Puerto Rico.
Further details are available at the link below