> Markdown version of [/jobs/ext/1956016-principal-engineer-product-cybersecurity](https://www.wearedevelopers.com/jobs/ext/1956016-principal-engineer-product-cybersecurity). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Principal Engineer, Product Cybersecurity - **Company:** Baxter - **Location:** Springfield, IL, United States - **Experience:** Experienced - **Salary:** $120,000.0 - $165,000.0 - **Contract:** Permanent contract - **Skills:** Software Applications, Software System Penetration Testing, Cyber Security, Federal Information Processing Standards (FIPS), Fuzz Testing, Information Management, Secure Coding, Software Requirements Analysis, Cyber Threat Analysis, Information Technology, Synopsys Black Duck, Vulnerability Analysis - **Published:** August 6, 2026 - **Apply:** https://diversityjobs.com/main/sendform/8/8/28176/1/17822519?backUrl=%2Fcareer%2F17822519%2FPrincipal-Engineer-Product-Cybersecurity-Illinois-Round-Lake ## About the Role * BS in computer science, engineering, mathematics, information management, or related field with 5+ years of industry experience or Masters with 3+ years. * Experience with threat modeling, penetration testing, fuzz testing, vulnerability scanning, secure code analysis. * Experience with cybersecurity related software such as Blackduck, Coverity, etc. * Experience dealing with threat intelligence, CWEs and CVEs. * Familiarity with cybersecurity related organizations and certifications such as UL (UL-2900), ICS-CERT, FIPS 140, etc. * Experience with cybersecurity functionality on embedded systems and hosted software applications. * Requires strong organization and communication skills, with the ability to interface with both technical and non-technical personnel. * Ability to convince management on courses of action with minimal assistance using both written and verbal methods., This is where your well-being matters. Baxter offers comprehensive compensation and benefits packages for eligible roles. Our health and well-being benefits include medical and dental coverage that start on day one, as well as insurance coverage for basic life, accident, short-term and long-term disability, and business travel accident insurance. Financial and retirement benefits include the Employee Stock Purchase Plan (ESPP), with the ability to purchase company stock at a discount, and the 401(k) Retirement Savings Plan (RSP), with options for employee contributions and company matching. We also offer Flexible Spending Accounts, educational assistance programs, and time-off benefits such as paid holidays, paid time off ranging from 20 to 35 days based on length of service, family and medical leaves of absence, and paid parental leave. Additional benefits include commuting benefits, the Employee Discount Program, the Employee Assistance Program (EAP), and childcare ## Description As Principal Engineer, own and direct the cybersecurity design and analysis of multiple medical devices. Demonstrate subject matter expert knowledge in state-of-the-art security principles. Resolve difficult problems, from conception to final design with team input. Plan, lead, and deliver project assignments in the evaluation, selection and adaptation of various cybersecurity engineering techniques, procedures, and criteria with minimal guidance. Contributes to a cybersecurity vision that aligns with the organization's vision and strategic plan. Utilizes solid understanding of device and system connectivity concepts in a medical device domain. Provides direction to technical team members that are accountable for implementing cybersecurity, integration, and connectivity deliverables. Exhibits creativity and innovation in completing divisional and cross-functional/business unit goals and objectives. What you'll be doing: * Implement proof of concept project to define innovative solutions on platforms/server platforms. Lead implementation of medical device cybersecurity principles as part of an overall security architecture. * Create, own, and maintain system requirements, architectures, risk analysis and other specifications that define the cybersecurity functionality of medical device systems both embedded and hosted. * Create threat models of medical device systems and the interfaces between medical devices. * Perform vulnerability scanning of medical device systems and analyze results. * Monitor threat intelligence and analyze CWEs and CVEs that affect medical device systems and propose solutions. * Drive cybersecurity improvements through product the cross functional teams, primarily software. * Lead discussions to resolve competing constraints between interrelated functions (Engineering, Risk Management, Compliance, Clinical, Human Factors, Regulatory, Marketing, Service). * Ensure compliance to the product development process and Quality System and Design Control requirements. Interface with regulatory bodies, representing Baxter and Baxter products, and ensure that regional cybersecurity needs are met., Baxter is committed to supporting the needs for flexibility in the workplace. We do so through our flexible workplace policy which includes a minimum of 3 days a week onsite. This policy provides the benefits of connecting and collaborating in-person in support of our Mission. ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [How to Cause (or Prevent) a Massive Data Breach- Secure Coding and IDOR](https://www.wearedevelopers.com/videos/39-how-to-cause-or-prevent-a-massive-data-breach-secure-coding-and-idor) - [How will artificial intelligence change the future of software testing?](https://www.wearedevelopers.com/videos/85-how-will-artificial-intelligence-change-the-future-of-software-testing) - [Why Security-First Development Helps You Ship Better Software Faster](https://www.wearedevelopers.com/videos/1568-why-security-first-development-helps-you-ship-better-software-faster) - [What makes Cybersecurity different for critical infrastructure?](https://www.wearedevelopers.com/videos/571-what-makes-cybersecurity-different-for-critical-infrastructure) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Highest Paying Tech Companies for Developers](https://www.wearedevelopers.com/magazine/220-highest-paying-tech-companies-for-developers) - [Best Countries for Software Engineers](https://www.wearedevelopers.com/magazine/267-best-countries-for-software-engineers) - [The Best X (Twitter) Accounts for Developers](https://www.wearedevelopers.com/magazine/294-the-best-x-twitter-accounts-for-developers) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [The Best Software Developer Blogs to Read](https://www.wearedevelopers.com/magazine/156-the-best-software-developer-blogs-to-read)