Sr. Product Security Engineer - (Embedded/IoT)
MedtronicAbout the role
At Medtronic you can begin a life-long career of exploration and innovation, while helping champion healthcare access and equity for all. You’ll lead with purpose, breaking down barriers to innovation in a more connected, compassionate world.
A Day in the Life
Onsite
We’re working onsite 4 days a week to drive performance, foster an environment of belonging, and collaborate to inspire as we engineer the extraordinary.
At Medtronic, we’re driven by our Mission to alleviate pain, restore health, and extend life for millions of people around the world through innovative biomedical devices and connected health solutions. As our products become increasingly connected, securing the medical device ecosystem at the product and system level is critical to ensuring patient safety and product integrity. The Senior Product Security Engineer will play a key role in securing connected and embedded medical devices across the full product lifecycle. This role is focused on device/product security engineering (not enterprise IT security) and partners closely with R&D, software, systems, and quality teams to design and implement robust, scalable security controls.
The ideal candidate brings hands-on experience securing embedded or IoT products in regulated environments, with strong depth in threat modeling, secure architecture, cryptography, and device-level risk management.
Key Responsibilities:
Product Security Engineering – Embed security requirements into the medical device development lifecycle, partnering with R&D and systems teams from architecture through release.
Threat Modeling & Risk Assessment – Perform system-level threat modeling (e.g., STRIDE or similar), attack surface analysis, and vulnerability assessments for connected and embedded medical devices.
Secure Architecture – Support and review implementation of device security capabilities such as:
Secure boot and root of trust
Secure firmware/software update mechanisms
Device identity and authentication
Secure communications and protocol hardening
Data protection at rest and in transit
Key management and Hardware Security Module (HSM) concepts
Cryptography & Post-Quantum Readiness – Apply modern cryptographic principles and support forward-looking strategies including quantum-resistant approaches where applicable.
Secure SDLC Integration – Partner with agile development teams to embed security into design reviews, code reviews, CI/CD pipelines, and verification activities.
Verification & Validation – Define and support security V&V activities including penetration testing, static/dynamic analysis, fuzz testing, and vulnerability management.
Standards & Compliance – Ensure alignment with medical device cybersecurity expectations including:
FDA premarket cybersecurity guidance
IEC 81001-5-1
ISO 14971
NIST frameworks
Relevant Medtronic quality processes
Incident & Vulnerability Management – Support coordinated vulnerability disclosure, post-mar
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s