> Markdown version of [/jobs/ext/3044886-sr-cybersecurity-engineer](https://www.wearedevelopers.com/jobs/ext/3044886-sr-cybersecurity-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Sr. Cybersecurity Engineer - **Company:** Boston, Inc. - **Location:** Arden Hills, MN, United States - **Experience:** Expert - **Salary:** $85,000.0 - $161,500.0 - **Contract:** Permanent contract - **Skills:** Microsoft Windows, Active Directory, Amazon Web Services, Software System Penetration Testing, Microsoft Azure, Configuration Management, Cyber Security, Computer Engineering, Continuous Integration, Linux, Hardware Security Module, Identity and Access Management, Information Systems Security Architecture Professional, Information Systems Security Engineering Professional, Network Security, Maple Software, Network Protocols, Public Key Infrastructure, Cloud Services, Secure Coding, Single Sign-On, Software Engineering, Verification and Validation (Software), DevOps Tools - Open-source, Yocto, Information Technology, Software Coding, Devsecops, Vulnerability Analysis - **Published:** September 24, 2026 - **Apply:** https://jobs.localjobnetwork.com/apply/add/88433202/1 ## About the Role * Bachelor's or master's degree in Cybersecurity, Computer Science, Computer Engineering, or a related field. * Mininum of 5 years of experience in cybersecurity engineering, with a recent focus on product security as it extends to the IoT cloud. * Knowledge of DevSecOps tools. * Proven experience in design and architecture reviews for complex, embedded medical devices or similar technologies. * Demonstrated history of creating and executing security risk assessments and mitigation strategies. * In-depth understanding of cybersecurity frameworks (e.g., NIST Cybersecurity Framework) including best practices for defense in depth. * Excellent written and verbal communication skills for interfacing technical teams, stakeholders, and executive leadership. * Ability to work collaboratively across multidisciplinary teams, bridging gaps between technical, regulatory, and business functions., * 4+ years of experience working in the medical device industry or a similarly regulated environment; security architecture or medical device administration experience in healthcare settings is also a plus. * Development experience in securing Yocto and desktop Linux, Windows IoT, or Android * Deep knowledge of the deployment environment for medical devices into health delivery organizations, including Active Directory (AD) or Single Sign On (SSO) integrations. * Hands-on experience with IoT cloud deployments such as Azure or AWS. * Experience writing code, with secure coding practices, vulnerability scanning tools, and penetration testing methodologies. * Knowledge of embedded systems security, network security, endpoint protections, wireless communications, network protocols, HSM and PKI. * Experience supporting VA Handbook 6500 compliance. * Relevant certifications (e.g., GIAC, ISSEP, ISSAP, CRISC) are a plus. * Experience with vulnerability and risk assessments including use of CVSS. ## Description Boston Scientific is seeking a Senior Cybersecurity Engineer with a background in DevSecOps and the design, development, and testing of cybersecurity features and controls in a regulated industry. This individual will be responsible for driving the cybersecurity strategy and DevSecOps throughout the product lifecycle, ensuring compliance with relevant standards and regulations. Be a part of the Interventional Cardiology team, one of Boston Scientific's most product-diverse divisions, supporting R&D in the design of exciting products and business development activities. Work Mode: At Boston Scientific, we value collaboration. This role follows a hybrid or onsite work model, requiring employees to be in our Maple Grove (Arbor Lakes), MN office at least three days per week., * Integrate security into the product development lifecycle of multiple product lines. * Foster a collaborative security culture from conception to decommission. * Collaborate with product development teams to embed security controls throughout the CI/CD pipeline. * Lead threat modeling using STRIDE and security risk assessments, identifying, and evaluating potential threats and safety issues. * Elicit and define product security needs and requirements; define product security requirements, design specifications, and verification and validation strategies. * Establish best practices and automate processes for vulnerability detection, secure coding, configuration management, and patching. * Implement risk mitigation strategies and maintain risk management documentation. * Oversee and enhance incident response plans and processes, ensuring rapid and effective resolution of security incidents. * Manage secrets, identity and access management to ensure least privilege access. * Stay current with emerging regulations and standards related to medical device security (e.g., FDA Premarket Guidance, Post-market Cybersecurity Guidance, TIR 57). * Collaborate closely with internal stakeholders (Software Development, Quality, Regulatory, IT) to align security goals and requirements. * Model resiliency and show leadership by presenting topics to the Security Champions program. ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [DevSecOps: Injecting Security into Mobile CI/CD Pipelines](https://www.wearedevelopers.com/videos/273-devsecops-injecting-security-into-mobile-ci-cd-pipelines) - [Docker network without Docker](https://www.wearedevelopers.com/videos/1418-docker-network-without-docker) - [DevSecOps culture](https://www.wearedevelopers.com/videos/783-devsecops-culture) - [You can’t hack what you can’t see](https://www.wearedevelopers.com/videos/41-you-can-t-hack-what-you-can-t-see) - [DevSecOps: Security in DevOps](https://www.wearedevelopers.com/videos/36-devsecops-security-in-devops) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Top-Paying Tech Jobs (with Salaries)](https://www.wearedevelopers.com/magazine/372-top-paying-tech-jobs-with-salaries) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks)