Jobs and Careers
ME

Senior Product Security Engineer, Security Tooling Architecture

Medtronic
USA-MN Mounds View South, United States, United Statesfull_timeVerifiedPosted 16 Apr 2025
💰 $184,800/yr

About the role

We anticipate the application window for this opening will close on - 28 Apr 2025


 

At Medtronic you can begin a life-long career of exploration and innovation, while helping champion healthcare access and equity for all. You’ll lead with purpose, breaking down barriers to innovation in a more connected, compassionate world.

A Day in the Life

We look for leaders who have a clear vision of where we are going and how to get there, bold inclusive thinkers who create new ideas and bring our best solutions forward to benefit our patients, business partners, and customers. Join a Culture of Collaboration and Innovation.


The Medtronic Product Security Office (PSO), within the Enterprise Quality organization, provides corporate-level oversight, services, strategy, and collaboration across the Medtronic Operating Units to safeguard medical devices.

In this critical role you will act as Senior Product Security Engineer, reporting to the Senior Product Security Manager within the Product Security Office (PSO) in Corporate Quality. This position is responsible for developing an overarching security tool architecture for Security by Design and Vulnerability Vigilance workstreams. We look for leaders who have a clear vision of where we are going and how to get there, bold inclusive thinkers who create new ideas and bring our best solutions forward to benefit our patients, business partners, and customers.  

Position Responsibilities:

  • Identify, document, and assess technology, tools, and associated processes in use by the PSO 

  • Develop an appropriate architecture framework in alignment with the key strategic pillars of Security by Design and Vulnerability Vigilance 

  • Lead industry assessment for appropriate tooling/solution selection if necessary 

  • Implement proposed framework to improve PSO visibility, reporting, metrics, and overall maturity in the PSO strategy 

  • Support enterprise quality program for SBOMs (“Software Bill of Materials”) with adherence to industry defined standards such as CycloneDX, SPDX (“Software Package Data Exchange”), VEX (“Vulnerability Exploitability eXchange”), and the evolving needs of the SBOM program. 

  • Support enterprise creation and exchange of SBOMs to meet the needs for both internal teams inside Medtronic and outside partners such as HDOs, regulators, and customers 

  • Apply technical understanding of vulnerability management, security controls/threat modeling, penetration testing/DAST (“Dynamic Application Security Testing”) 

  • Support product developers, security engineers, project managers for technical needs, i.e., artifact generation, build process steps, validation steps 

  • Work with outside vendors, and support product teams that work with vendors 

  • Strengthen relationships with critical Engineering, Quality, Regulatory Affairs, Global Security office, Global IT, and Leadership stakeholders in Operating Units. 

Specific responsibilities include: 

  • Strong familiarization with SBOM authoring, i.e., making an SBOM (generation, augmentation, enrichment, signing, etc.) 

  • Experience with DevSecOps, SDLC, Scrum framework, Agile/waterfall methodology, and related software design principles to support SBOM efforts in premarket products 

  • Advise on best practices for CI/CD security processes across relevant platforms such as Jenkins, GitHub, GitLab, Bitbucket, and Azure DevOps 

  • Experience with SCA (“Software Composition Analysis”), binary analysis, SAST (“Static Application Security Testing”), limited reverse engineering skills to support SBOM efforts in post market/legacy products 

  • Understand principles of risk management between supplier and customer, as well as Medtronic’s position in both roles 

  • Familiarity with FOSS (“Free and Open-Source Software”) ecosystems, package management, and differences with proprietary/closed-source software distribution 

  • Must have experience and knowledge working with regulated medical devices and cybersecurity requirements. 

  • Leveraging the Product Security strategy and roadmap to drive maturity. 

  • Remain informed on Regulatory requirements for Product Security.  

  • Create energy and enthusiasm at all levels of the product security organization.

  • Enable strong partnerships across the organization to drive best-in-class product security mechanisms.

  • Continuously anticipate and be prepared for audits.

  • Proactively engage with third party stakeholders such as researchers, industry peers, regulators, and potentially Medtronic customers.   

  • Benchmark with external or

Apply for this role

Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.

Apply Now →Generate Application Kit

Free account required — sign up in 30s

Company

Medtronic

View company profile →