Product Security Engineer II - Neuro
MedtronicAbout the role
At Medtronic you can begin a life-long career of exploration and innovation, while helping champion healthcare access and equity for all. You’ll lead with purpose, breaking down barriers to innovation in a more connected, compassionate world.
A Day in the Life
At Medtronic, we’re driven by our Mission to alleviate pain, restore health, and extend life for millions of people around the world, with our innovative Biomedical devices and solutions. Our people are the foundation of our mission, together with Medtronic mindset, we pursue continuous innovation to breach new frontiers of Biomedical research.
As the world is getting more connected, complexity and security challenges increase many folds to protect the devices, the patients and sensitive data. The Product Security Engineer II will be acting at the frontline of these emerging challenges to proactively find actionable and measurable cyber security solutions while ensuring uninterrupted functionality and patient safety.
The primary responsibilities include overseeing all phases of the cyber security life cycle of medical devices. These include proactive initiates to identify, model, and evaluate cyber security threats, define security measures to mitigate the threats, develop robust implementation strategies and rigorous verification and validation mechanisms. Proactively engage with cross-functional development teams, prepare reports meeting quality and regulatory requirements.
The ideal candidate has a strong technical understanding of cyber security frameworks and architectures for connected systems. Experience in medical devices, or similar regulated industries is highly desired.
Key Responsibilities:
Product Security Specification and Design:
- Performs security assessments of company products that may include vulnerability and risk assessments, threat analysis, and security code reviews to identify potential design and implementation vulnerabilities.
- Designs and develop security features for products including systems, applications and/or solutions.
- Define security architecture supporting advanced cryptographic algorithms, embedded code standard, hardware security modules, network topologies
- Integrates new security features and updates into existing products and ensures the security of all products is maintained throughout the product lifecycle.
- Develops verification plans for security functions, code/design review, penetration testing to ensure robust security measures.
- Ensure processes are aligned with industry standards, regulatory requirements, and internal compliance policies.
- Collaborate with cross-functional teams, including product development, IT, security, and quality assurance, to ensure seamless security asset deployment and lifecycle management.
- Provide hands-on support for security asset provisioning and troubleshooting for medical devices and mobile applications across the product lifecycle.
Process Improvement:
- Continuously evaluate and improve product security risk management processes to enhance efficiency, security, and scalability.
- Implement automation tools and workflows to streamline security activities where possible.
Compliance and Governance:
- Ensure that security asset management procedures adhere to relevant regulatory frameworks such as NIST, ISO 27001, or HITRUST and other applicable standards.
- Prepare and maintain audit-ready documentation and evidence related to product security.
Minimum Requirements:
- Bachelor’s degree in Computer Science, or a related field with 2 years of experience in cyber security, embedded systems security, IoT security, IT security, or an Advance Degree in Computer Science, or related field with 0 years of experience
Technical Skills:
- Working knowledge of secure software development lifecycle (SDLC) principles, DevSecOps
- Understanding of computer networks, protocols, hardware/software architecture
- Hands-on experience in at least one programming language like Python or C/C++, Java, Javascript
- Good understanding of cyber security concepts and frameworks (e.g.: NIST, OWASP, MITRE)
- Familiarity with security standards such as ISO 27001, ISO 14971 or HITRUST
Soft Skills:
- Strong problem-solving and analytical skills
- Ability to collaborate effectively in cross-functional teams
- Certifications (Preferred):
- CompTIA Security+, CISSP, CISM, or similar security certifications.
- ITIL Certification or other process-orien
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s