> Markdown version of [/jobs/ext/3579100-principal-product-security-engineer](https://www.wearedevelopers.com/jobs/ext/3579100-principal-product-security-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Principal Product Security Engineer - **Company:** Smith & Nephew plc - **Location:** Memphis, TN, United States - **Experience:** Expert - **Salary:** $125,500.0 - $198,000.0 - **Contract:** Permanent contract - **Skills:** Software Applications, Software System Penetration Testing, Cloud Computing Security, Static Program Analysis, Cyber Security, Information Systems, Network Architecture, Open Web Application Security, Software Engineering, Software Vulnerability Management, EndPointSecurity, Software Security, National Institute of Standards and Technology Cybersecurity Framework, Information Technology, Vulnerability Analysis - **Published:** October 4, 2026 - **Apply:** https://diversityjobs.com/main/sendform/8/8/28176/1/18528611?backUrl=%2Fcareer%2F18528611%2FPrincipal-Product-Security-Engineer-Tennessee-Memphis ## About the Role * A bachelor's degree in life science, computer science, information systems, or equivalent formal training or professional experience * At least five years of hands on experience in product security, device security, application security, or information technology security * Experience with vulnerability management, penetration testing, code security, security governance, risk assessments, network infrastructure, and cloud security * Knowledge of medical device regulations and cybersecurity frameworks, including HIPAA, FDA requirements, ISO 27001 and 27002, NIST CSF, and OWASP * The ability to design and guide the implementation of innovative security solutions while working independently across multiple teams and business areas * Excellent written and verbal communication, prioritization, customer service, and problem resolution skills * A current CISM, CISSP, CRISC, or equivalent certification is preferred You. Unlimited. ## Description * Lead the definition and implementation of cybersecurity requirements and controls across technologies, capital devices, digital accessories, connected infrastructure, and software applications * Create and maintain product cybersecurity risk registers and threat models, identifying and addressing security risks throughout the development lifecycle * Lead security testing and assessment activities, including vulnerability testing, penetration testing, code analysis, software composition analysis, and endpoint protection * Recommend technical solutions and support the integration of automated tools and processes that reduce security vulnerabilities * Help develop and mature the Global Product Security Strategy and Secure Software Development Life Cycle * Support product cybersecurity incident response activities in line with relevant industry practices and standards * Provide technical leadership when engaging with regulators, customers, auditors, industry groups, and security researchers