Senior Product Security Engineer, Security Tooling Architecture
MedtronicAbout the role
At Medtronic you can begin a life-long career of exploration and innovation, while helping champion healthcare access and equity for all. You’ll lead with purpose, breaking down barriers to innovation in a more connected, compassionate world.
A Day in the Life
We look for leaders who have a clear vision of where we are going and how to get there, bold inclusive thinkers who create new ideas and bring our best solutions forward to benefit our patients, business partners, and customers. Join a Culture of Collaboration and Innovation.
The Medtronic Product Security Office (PSO), within the Enterprise Quality organization, provides corporate-level oversight, services, strategy, and collaboration across the Medtronic Operating Units to safeguard medical devices.
In this critical role you will act as Senior Product Security Engineer, reporting to the Senior Product Security Manager within the Product Security Office (PSO) in Corporate Quality. This position is responsible for developing an overarching security tool architecture for Security by Design and Vulnerability Vigilance workstreams. We look for leaders who have a clear vision of where we are going and how to get there, bold inclusive thinkers who create new ideas and bring our best solutions forward to benefit our patients, business partners, and customers.
Position Responsibilities:
Identify, document, and assess technology, tools, and associated processes in use by the PSO
Develop an appropriate architecture framework in alignment with the key strategic pillars of Security by Design and Vulnerability Vigilance
Lead industry assessment for appropriate tooling/solution selection if necessary
Implement proposed framework to improve PSO visibility, reporting, metrics, and overall maturity in the PSO strategy
Support enterprise quality program for SBOMs (“Software Bill of Materials”) with adherence to industry defined standards such as CycloneDX, SPDX (“Software Package Data Exchange”), VEX (“Vulnerability Exploitability eXchange”), and the evolving needs of the SBOM program.
Support enterprise creation and exchange of SBOMs to meet the needs for both internal teams inside Medtronic and outside partners such as HDOs, regulators, and customers
Apply technical understanding of vulnerability management, security controls/threat modeling, penetration testing/DAST (“Dynamic Application Security Testing”)
Support product developers, security engineers, project managers for technical needs, i.e., artifact generation, build process steps, validation steps
Work with outside vendors, and support product teams that work with vendors
Strengthen relationships with critical Engineering, Quality, Regulatory Affairs, Global Security office, Global IT, and Leadership stakeholders in Operating Units.
Specific responsibilities include:
Strong familiarization with SBOM authoring, i.e., making an SBOM (generation, augmentation, enrichment, signing, etc.)
Experience with DevSecOps, SDLC, Scrum framework, Agile/waterfall methodology, and related software design principles to support SBOM efforts in premarket products
Advise on best practices for CI/CD security processes across relevant platforms such as Jenkins, GitHub, GitLab, Bitbucket, and Azure DevOps
Experience with SCA (“Software Composition Analysis”), binary analysis, SAST (“Static Application Security Testing”), limited reverse engineering skills to support SBOM efforts in post market/legacy products
Understand principles of risk management between supplier and customer, as well as Medtronic’s position in both roles
Familiarity with FOSS (“Free and Open-Source Software”) ecosystems, package management, and differences with proprietary/closed-source software distribution
Must have experience and knowledge working with regulated medical devices and cybersecurity requirements.
Leveraging the Product Security strategy and roadmap to drive maturity.
Remain informed on Regulatory requirements for Product Security.
Create energy and enthusiasm at all levels of the product security organization.
Enable strong partnerships across the organization to drive best-in-class product security mechanisms.
Continuously anticipate and be prepared for audits.
Proactively engage with third party stakeholders such as researchers, industry peers, regulators, and potentially Medtronic customers.
Benchmark with external or
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s