> Markdown version of [/jobs/ext/596568-senior-principal-engineer-product-security](https://www.wearedevelopers.com/jobs/ext/596568-senior-principal-engineer-product-security). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Senior Principal Engineer, Product Security - **Company:** Vantive US Healthcare LLC - **Location:** Plymouth, MN, United States - **Experience:** Expert - **Salary:** $136,000.0 - $175,000.0 - **Contract:** Permanent contract - **Skills:** Adobe Flash, Agile Methodology, Software System Penetration Testing, Authentication Protocols, C++ (Programming Language), Cipher, Computer Engineering, Software Design Patterns, Linux, Embedded Software, OSI Models, Python (Programming Language), Open Web Application Security, Public Key Infrastructure, Real-Time Operating Systems, Secure Coding, Software Engineering, Software Vulnerability Management, Privacy Controls, Network Routers, Software Security, Firewalls (Computer Science), Information Technology, U-Boot, Static Application Security Testing, Programming Languages, Dynamic Application Security Testing - **Published:** June 20, 2026 - **Apply:** https://www.juju.com/job/00000000g9hda2 ## About the Role Experienced security developer able to interpret and guide software development teams on secure coding practices and application security test report interpretation for various coding languages and operating environments Strong knowledge of secure software development lifecycle and practices including SAFe/ Agile methodologies for software development Understanding of security by design principles and architecture level security concepts Sound understanding and experience in implementing security technologies/techniques such as, Cryptographic Algorithms/Cipher Suites, Public key Infrastructure (PKI), Hardware/embedded authentication protocols, Secure Boot, and data-at-rest encryption methods Experience implementing OWASP Top10 application security guidelines in embedded systems Knowledge of embedded system architecture and security controls (e.g., firewall and border router configurations, wireless communication architectures, messaging authentication protocols Experienced in generating, defining, and reviewing penetration test results through knowledge standard methodologies and tools including environmental configuration definition, security analysis, threat modeling, and system security audits Knowledge of current and emerging security threats and techniques for exploiting security vulnerabilities Exposure to international privacy requirements & cross-industry trends Qualifications and Skills Bachelor's degree in Computer Science, Computer Engineering, a related field or equivalent demonstrated experience and knowledge Minimum 8+ years of experience in software development or related fields. Minimum 5 years technical experience working with product security design/development for embedded systems 3 years working with each of the following: Experience with C/C++, Python, Linux and/or security design within real-time operating systems Experience analyzing, interpreting, and mitigating security findings from multiple sources including SAST, DAST, SCA and penetration tests Embedded data at rest security implementations including Code Signing, Secure boot, and flash encryption implementations Embedded/IoT wired and wireless secure networking implementations within multiple layers of the OSI stack IoT/Embedded PKI solutions and implementation, Bachelor Degree ## Description As the Sr. Principal Product Security Engineer you will be responsible for designing, building, testing and implementing systems with the primary goal of product security across Vantive's medical device product portfolio in various operating environments. Prevention of breach of Intellectual Property (IP), Attack surface minimization, preventive security and privacy controls, incident/vulnerability management are some of the focus areas for this position. This role requires deep knowledge of security by design, IoT secure code principles, physical security hardening, and embedded system development. Candidates should have experience in embedded software development with a desire to secure products to be able to protect our customers and patients using our life-sustaining products each day. Success in this role requires a strong understanding and interest in the latest security standards, protocols, products, and systems. What you will be doing: Work directly with embedded software developers in building a security by design mindset by defining implementations and coding inline with the Application Security Program mandates Implement embedded secure code solutions, design patterns, and coding guidelines that meet security and privacy requirements defined in the security plans, risk assessments, policies, and procedures Support security project governance through scheduling activities, planning and prioritization Proactively drive security solutions implementation in-alignment with the development leads, security architects and product owner(s) Drive feature implementations in line with the architecture via designs, coding, reviews and tests. Perform Proof of Concept (POC) activities as necessary Review, Analyze and mitigate SAST, DAST, SCA and penetration test findings in collaboration with the developers for various electromechanical medical devices product lifecycles Review current software security control measures and implement security enhancements across multiple medical devices Participate in post-market product analysis to support vulnerability investigations as required as well as be engaged in continuous security monitoring, Vantive is committed to supporting the needs for flexibility in the workplace. We do so through our flexible workplace policy which includes a minimum of 3 days a week onsite. This policy provides the benefits of connecting and collaborating in-person in support of our Mission. ## Related Videos - [Docker network without Docker](https://www.wearedevelopers.com/videos/1418-docker-network-without-docker) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Docker exec without Docker](https://www.wearedevelopers.com/videos/1094-docker-exec-without-docker) - [Software Security 101: Secure Coding Basics](https://www.wearedevelopers.com/videos/220-software-security-101-secure-coding-basics) - [Why Security-First Development Helps You Ship Better Software Faster](https://www.wearedevelopers.com/videos/1568-why-security-first-development-helps-you-ship-better-software-faster) - [Discover the open source trio you didn’t expect: .NET and PostgreSQL on Linux](https://www.wearedevelopers.com/videos/2042-discover-the-open-source-trio-you-didn-t-expect-net-and-postgresql-on-linux) ## Related Articles - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [The Overflow: Security and Privacy](https://www.wearedevelopers.com/magazine/715-the-overflow-security-and-privacy)