> Markdown version of [/jobs/ext/3547863-principal-product-security-engineer-medical-device](https://www.wearedevelopers.com/jobs/ext/3547863-principal-product-security-engineer-medical-device). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Principal Product Security Engineer - Medical Device - **Company:** Medtronic Inc. - **Location:** Newton, MA, United States - **Experience:** Experienced - **Salary:** $160,800.0 - $241,200.0 - **Contract:** Temporary contract - **Skills:** CompTIA Security+, Cyber Security, Embedded Software, Open Web Application Security, Software Engineering, Systems Integration, Real Time Systems, Software Security, U-Boot, Vulnerability Analysis - **Published:** October 1, 2026 - **Apply:** https://dejobs.org/x/x/320BB694DFAF4F0ABC83A313810A76A9/job/ ## About the Role * Bachelor's degree and a minimum of 7 years of relevant experience * OR Master's degree with a minimum of 5 years of relevant experience * OR PhD with 3 years relevant experience * Strong experience in embedded device security within a regulated industry. * Strong understanding of cybersecurity concepts and frameworks such as NIST and OWASP., * Deep knowledge of secure software development lifecycle principles and security-by-design practices. * Experience collaborating with engineering teams to identify and address product security risks. * Familiarity with medical device cybersecurity standards and guidance, including IEC 81001-5-1, ISO 14971, and FDA premarket and post-market cybersecurity guidance. * Experience supporting FDA and other regulatory cybersecurity submissions. * Experience with connected healthcare systems or cloud-connected medical devices. * Security certifications such as CompTIA Security+, CISSP, or similar. #LI-MDT, For Baccalaureate degrees earned outside of the United States, a degree that satisfies the requirements of 8 C.F.R. ยง 214.2(h)(4)(iii)(A) is required. ## Description Medtronic Cardiac Ablation Solutions (CAS) is seeking a Principal Product Security Engineer to join our R&D organization and help secure cardiac ablation medical device solutions. This role focuses on cybersecurity for medical devices and embedded systems. It is not an IT security, compliance, or GRC-focused position. The ideal candidate will bring strong experience partnering with engineering teams to integrate cybersecurity into real-time systems, embedded firmware, connected devices, and other product security contexts. This position is located in either Mounds View, Minnesota or Newton, Massachusetts and follows an onsite work model with a minimum of four days per week in the office. The selected candidate will support the integration of advanced cybersecurity controls, identify and mitigate vulnerabilities, and contribute to initiatives that improve cyber resilience across the product lifecycle. This person will serve as a technical subject matter expert, mentor others, collaborate across functions, and help drive long-term improvements in product security posture. Primary Responsibilities * Product Security - Implement security requirements across the medical device development lifecycle by partnering with cross-functional teams and applying best practices from design through deployment. * Risk Assessment - Conduct threat modeling and vulnerability assessments to identify, prioritize, and help mitigate security risks throughout the product lifecycle. * Security Architecture - Support the design and delivery of secure medical devices through implementation of capabilities such as secure boot, secure communications, data protection, software update mechanisms, system integration protections, and access controls. * Security Standards - Apply medical device cybersecurity standards and guidance, including NIST, OWASP, and IEC 81001-5-1, and partner with development teams to strengthen security practices. * Technical Leadership - Stay current on cybersecurity trends affecting medical devices and health software, share best practices, and help advance long-term product security strategy.