Principal Design Quality Cybersecurity Engineer
Boston ScientificAbout the role
Additional Location(s): N/A
Diversity - Innovation - Caring - Global Collaboration - Winning Spirit - High Performance
At Boston Scientific, we’ll give you the opportunity to harness all that’s within you by working in teams of diverse and high-performing employees, tackling some of the most important health industry challenges. With access to the latest tools, information and training, we’ll help you in advancing your skills and career. Here, you’ll be supported in progressing – whatever your ambitions.
About the role:
Boston Scientific is seeking an experienced Principal Design Quality Cybersecurity Engineer with a strong background in the design, development, and testing of cybersecurity features and controls within the Interventional Cardiology division. This individual will be responsible for overseeing and guiding the cybersecurity strategy throughout the product lifecycle, ensuring compliance with relevant standards and regulations.
The Interventional Cardiology team is one of Boston Scientific’s most product-diverse divisions, supporting in the design of exciting new products and business development activities. These products adhere to industry standards and include computing devices, single-use devices, and support devices. Seeking an individual with a strong desire to analyze and drive solutions that are adaptable in communication to all levels within the organization.
At Boston Scientific, we value collaboration and synergy. This role follows a hybrid work model requiring employees to be in our local office three days per week.
Relocation assistance is available for this position at this time.
Boston Scientific will not offer sponsorship or take over sponsorship of an employment visa for this position at this time.
Your responsibilities will include:
- Interpret and apply relevant cybersecurity standards and regulations (e.g., FDA/CMDE/MDCG Cybersecurity Guidance, IEC 62443, ISO 14971, HIPAA, GDPR) to ensure product compliance.
- Stay current with emerging regulations and standards related to medical device security (e.g., FDA Premarket Guidance, Post-market Cybersecurity Guidance).
- Collaborate with product development teams to embed security controls throughout the design, development, and maintenance phases.
- Self-motivated with a passion for solving problems and a bias for action.
- Ensure that medical device security engineering activities and deliverables (e.g., threat models, security risk assessments, security requirements, security test plans/protocols/reports, SBOM, post-market vulnerability management plans and reports, and cybersecurity labeling) comply with Boston Scientific's global quality system requirements and procedures.
- Collaborate with team on product security needs and requirements; review product security architectures and design specifications.
- Collaborate in planning of software verification and validation strategies.
- Review vulnerability assessments, fuzzing and penetration testing to identify and mitigate risks.
- Ensure continued consistent best practices and processes for secure coding, configuration management, and patching.
- Develop and implement risk mitigation strategies and maintain risk management documentation consistent across the ICTx portfolio.
- Oversee and enhance incident response plans and processes, ensuring rapid and effective resolution of security incidents.
- Drive continuous improvement of vulnerability management, including the evaluation and deployment of necessary patches or updates.
- Work closely with internal stakeholders (Software Development, R&D, Regulatory, IT, etc.) to align on security goals and requirements.
- Participate in internal and external audits, and address findings related to cybersecurity design and risk management processes.
What we’re looking for in you:
Required qualifications
- Bachelor’s degree in Cybersecurity, Computer Science, Computer Engineering, or a related field and 9+ years of experience in cybersecurity engineering, with a focus on product development and risk management or Master’s degree in Cybersecurity, Computer Science, Computer Engineering, or a related field and 7+ years of experience in cybersecurity engineering, with a focus on product devel
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s