Jobs and Careers
BD

Sr. Engineer, Product Cyber Security

BD
United Statesfull_timeVerifiedPosted 26 Mar 2026
💰 $152,900/yr($92,700/yr$152,900/yr)

About the role

Job Description Summary

The Product Cyber Security Engineer is a hands‑on, execution‑focused role responsible for strengthening and scaling Product Security capabilities across software‑enabled and connected products. This role partners closely with R&D, Software Engineering, DevOps, Quality, Systems Engineering, and Regulatory teams to ensure cybersecurity risks are proactively identified, documented, mitigated, and tracked throughout the product lifecycle.
The engineer owns and delivers core Product Security artifacts required by Product Security procedures, including threat models, cybersecurity risk assessments, vulnerability management evidence, SBOMs, and patch verification documentation. The role plays a critical part in sustaining regulatory compliance, enabling secure product releases, and maintaining customer trust by integrating cybersecurity into design controls, risk management, and release readiness processes.
This position is ideal for a security engineer who thrives in regulated, documentation‑heavy environments, brings strong execution discipline, and is motivated to standardize, streamline, and scale repeatable Product Security activities across multiple products while maintaining high quality and audit readiness.

Job Description

We are the makers of possible 

 

BD is one of the largest global medical technology companies in the world. Advancing the world of health™ is our Purpose, and it’s no small feat. It takes the imagination and passion of all of us—from design and engineering to the manufacturing and marketing of our billions of MedTech products per year—to look at the impossible and find transformative solutions that turn dreams into possibilities. 

 

We believe that the human element, across our global teams, is what allows us to continually evolve. Join us and discover an environment in which you’ll be supported to learn, grow and become your best self. Become a maker of possible with us. 

We are seeking a Product Cyber Security Engineer to strengthen and scale our Product Security capabilities across software enabled and connected products. This role will directly supplement and partner with existing Product Security ‑engineers, and will assume ownership of core cybersecurity deliverables required by our Product Security procedures.

The successful candidate will work closely with R&D, Software Engineering, DevOps, DevSecOps, Systems Engineering, Quality, and Regulatory teams to ensure that cybersecurity risks are identified, documented, mitigated, and tracked throughout the product lifecycle. This role is hands-on, execution‑ focused‑, and critical to sustaining regulatory compliance, product readiness, and customer trust.

Key Responsibilities

Product Cybersecurity Planning & Execution

  • Partner with product teams to define, execute, and maintain Product Security activities and deliverables for new development, major releases, and sustaining changes, in alignment with Product Security procedures.

  • Contribute to and maintain Product Security Management Plans and associated Product Security Management Files, ensuring all required cybersecurity activities are planned, traceable, and audit ready‑.

  • Support integration of Product Security activities into design control, risk management, and release readiness processes.

Threat Modeling & Risk Assessment

  • Lead or support creation and maintenance of product threat models, including identification of assets, data flows, trust boundaries, threats, and mitigations.

  • Perform or support cybersecurity risk assessments, including requirements gap analysis, CVSS-based‑ vulnerability scoring, and residual risk evaluation.

  • Document unresolved or accepted cybersecurity risks in Product Cybersecurity Risk Summary Reports for release decisions.

Vulnerability Management & Security Testing

  • Coordinate and support security testing activities, including:

    • Static code analysis

    • Open source and third‑-‑party dependency analysis

    • Vulnerability scanning and third-party‑ security assessments

  • Review vulnerability findings, work with engineering teams on remediation strategies, and ensure results are properly documented and tracked.

  • Support incident and vulnerability management workflows, including evidence generation for audits and regulatory reviews.

Patch Management & Verification

  • Support development and maintenance of product specific‑ patch management approaches, aligned with Product Security guidance.

  • Author or review Security Patch Verificatio

Apply for this role

Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.

Apply Now →Generate Application Kit

Free account required — sign up in 30s

Company

BD

View company profile →