> Markdown version of [/jobs/ext/2998583-principal-engineer-product-cybersecurity](https://www.wearedevelopers.com/jobs/ext/2998583-principal-engineer-product-cybersecurity). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Principal Engineer, Product Cybersecurity - **Company:** REASONABLE, LLC - **Location:** United States - **Experience:** Experienced - **Salary:** $120,000.0 - $165,000.0 - **Contract:** Permanent contract - **Skills:** Software Applications, Software System Penetration Testing, Cyber Security, Federal Information Processing Standards (FIPS), Fuzz Testing, Information Management, Systems Analysis, Internet Security, Secure Coding, Software Requirements Analysis, Systems Architecture, Cyber Threat Analysis, Information Technology, Synopsys Black Duck, Vulnerability Analysis - **Published:** September 19, 2026 - **Apply:** https://www.careerbuilder.com/job-details/principal-engineer-product-cybersecurity-round-lake-il--00ef76cf-f793-48d9-b1ce-87cef0167a61 ## About the Role * BS in computer science, engineering, mathematics, information management, or related field with 5+ years of industry experience or Masters with 3+ years. * Experience with threat modeling, penetration testing, fuzz testing, vulnerability scanning, secure code analysis. * Experience with cybersecurity related software such as Blackduck, Coverity, etc. * Experience dealing with threat intelligence, CWEs and CVEs. * Familiarity with cybersecurity related organizations and certifications such as UL (UL-2900), ICS-CERT, FIPS 140, etc. * Experience with cybersecurity functionality on embedded systems and hosted software applications. * Requires strong organization and communication skills, with the ability to interface with both technical and non-technical personnel. * Ability to convince management on courses of action with minimal assistance using both written and verbal methods., Analysis Skills, Architectural Analysis, Communication Skills, Computer Science, Cross-Functional, Embedded Systems, Employee Benefits, FIPS (Federal Information Processing Standards) 140, Healthcare, Human Factors, Internet Security, Maintain Compliance, Marketing, Mathematics, Medical Equipment, Medical Protocols, Organizational Skills, Problem Solving Skills, Process Improvement, Product Development, Proof of Concept, Regulations, Retirement Plan, Risk Analysis, Risk Management, Security Architecture, Stock Purchase Plans, Strategic Planning, System Architecture, Systems Analysis, Systems Maintenance, Threat Modeling, Vision Plan, Vulnerability Scanners ## Description As Principal Engineer, own and direct the cybersecurity design and analysis of multiple medical devices. Demonstrate subject matter expert knowledge in state-of-the-art security principles.Resolve difficult problems, from conception to final design with team input. Plan, lead, and deliver project assignments in the evaluation, selection and adaptation of various cybersecurity engineering techniques, procedures, and criteria with minimal guidance. Contributes to a cybersecurity vision that aligns with the organization's vision and strategic plan. Utilizes solid understanding of device and system connectivity concepts in a medical device domain. Provides direction to technical team members that are accountable for implementing cybersecurity, integration, and connectivity deliverables. Exhibits creativity and innovation in completing divisional and cross-functional/business unit goals and objectives. What you'll be doing: * Implement proof of concept project to define innovative solutions on platforms/server platforms. Lead implementation of medical device cybersecurity principles as part of an overall security architecture. * Create, own, and maintain system requirements, architectures, risk analysis and other specifications that define the cybersecurity functionality of medical device systems both embedded and hosted. * Create threat models of medical device systems and the interfaces between medical devices. * Perform vulnerability scanning of medical device systems and analyze results. * Monitor threat intelligence and analyze CWEs and CVEs that affect medical device systems and propose solutions. * Drive cybersecurity improvements through product the cross functional teams, primarily software. * Lead discussions to resolve competing constraints between interrelated functions (Engineering, Risk Management, Compliance, Clinical, Human Factors, Regulatory, Marketing, Service). * Ensure compliance to the product development process and Quality System and Design Control requirements. Interface with regulatory bodies, representing Baxter and Baxter products, and ensure that regional cybersecurity needs are met., Baxter is committed to supporting the needs for flexibility in the workplace. We do so through our flexible workplace policy which includes a minimum of 3 days a week onsite. This policy provides the benefits of connecting and collaborating in-person in support of our Mission. ## Related Videos - [How to Cause (or Prevent) a Massive Data Breach- Secure Coding and IDOR](https://www.wearedevelopers.com/videos/39-how-to-cause-or-prevent-a-massive-data-breach-secure-coding-and-idor) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [How will artificial intelligence change the future of software testing?](https://www.wearedevelopers.com/videos/85-how-will-artificial-intelligence-change-the-future-of-software-testing) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Unleashing the Power of Developers: Why Cybersecurity is the Missing Piece?!?](https://www.wearedevelopers.com/videos/712-unleashing-the-power-of-developers-why-cybersecurity-is-the-missing-piece) - [Cyber Security: Small, and Large!](https://www.wearedevelopers.com/videos/259-cyber-security-small-and-large) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again](https://www.wearedevelopers.com/magazine/751-how-we-built-a-worry-free-system-that-runs-for-10-years-and-what-we-d-do-again) - [What is Software Engineering?](https://www.wearedevelopers.com/magazine/289-what-is-software-engineering)