Jobs and Careers
BO

Principal Cybersecurity Engineer

Boston Scientific
Maple Grove, United Statesfull_timeVerifiedPosted 28 Jan 2025
💰 $599,465/yr($99,100/yr$599,465/yr)

About the role

Additional Location(s):  N/A

Diversity - Innovation - Caring - Global Collaboration - Winning Spirit - High Performance

At Boston Scientific, we’ll give you the opportunity to harness all that’s within you by working in teams of diverse and high-performing employees, tackling some of the most important health industry challenges. With access to the latest tools, information and training, we’ll help you in advancing your skills and career. Here, you’ll be supported in progressing – whatever your ambitions.           

 

About the role:

Boston Scientific is seeking an experienced Principal Cybersecurity Engineer with a strong background in the design, development, and testing of cybersecurity features and controls in a regulated industry. This individual will be responsible for overseeing and guiding the cybersecurity strategy throughout the product lifecycle, ensuring compliance with relevant standards and regulations. 

 

Be a part of the Interventional Cardiology team, one of Boston Scientific’s most product-diverse divisions, supporting R&D in the design of exciting new products and business development activities. These products adhere to industry standards and include computing devices, single-use devices, and support devices. 

 

Work Mode:
At Boston Scientific, we value collaboration and synergy. This role follows a hybrid work model requiring employees to be in our local office at least three days per week.

 

Your responsibilities will include: 

  • Interpret and apply relevant cybersecurity standards and regulations (e.g., FDA/CMDE/MDCG Cybersecurity Guidance, IEC 62443, ISO 14971, HIPAA, GDPR) to ensure product compliance. 
  • Stay current with emerging regulations and standards related to medical device security (e.g., FDA Premarket Guidance, Post-market Cybersecurity Guidance). 
  • Collaborate with product development teams to embed security controls throughout the design, development, and maintenance phases. 
  • Lead threat modeling and security risk assessments across the organization, identifying and evaluating potential threats and vulnerabilities. 
  • Elicit and define product security needs and requirements; define product security architectures and design specifications, and verification and validation strategies.  
  • Conduct vulnerability assessments, fuzzing and penetration testing to identify and mitigate risks. 
  • Establish best practices and processes for secure coding, configuration management, and patching. 
  • Develop and implement risk mitigation strategies and maintain risk management documentation. 
  • Oversee and enhance incident response plans and processes, ensuring rapid and effective resolution of security incidents. 
  • Drive continuous improvement of vulnerability management, including the evaluation and deployment of necessary patches or updates. 
  • Work closely with internal stakeholders (Software Development, Quality, Regulatory, IT, etc.) to align on security goals and requirements. 
  • Present cybersecurity findings, reports, and recommendations to senior leadership, regulators, and external auditors. 

 

Required qualifications: 

  • Bachelor’s or Master’s degree in Cybersecurity, Computer Science, Computer Engineering, or a related field. 
  • 9+ years of experience in cybersecurity engineering, with a focus on product development and risk management. 
  • Proven experience leading security design and architecture reviews for complex, embedded medical devices or similar technologies. 
  • Demonstrated track record of creating and executing security risk assessments and mitigation strategies. 
  • In-depth understanding of cybersecurity frameworks (e.g., NIST Cybersecurity Framework). 
  • Understanding of privacy regulations (HIPAA, GDPR) and their intersection with medical device cybersecurity. 
  • Strong leadership, decision-making, and team-building capabilities. 
  • Excellent written and verbal communication skills for interfacing with technical teams, stakeholders, and executive l

Apply for this role

Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.

Apply Now →Generate Application Kit

Free account required — sign up in 30s

Company

Boston Scientific

View company profile →