Jobs and Careers
ME

Senior Product Security Engineer - (Embedded/IoT) - Onsite

Medtronic
USA-MN Rice Creek East, United States, United Statesfull_timeVerifiedPosted 28 Jul 2026
💰 $198,000/yr($132,000/yr$198,000/yr)

About the role

We anticipate the application window for this opening will close on - 30 Jul 2026


 

Careers that change lives start here. Medtronic is a global leader in healthcare technology with a Mission to alleviate pain, restore health, and extend life. Our 95,000 employees work across more than 150 countries to put patients first — developing innovative medical technologies that improve the lives of 72+ million patients each year. Your unique talents will help shape the future of healthcare while building a career grounded in purpose, growth, and impact.

A Day in the Life

         

         

Across our global Neuroscience organization, we advance care for some of medicine’s most complex neurological and spinal conditions. By combining innovative technology, data-driven insights, and deep clinical expertise, we partner with physicians and health systems to improve how patients are treated and supported throughout their care journey.

Pelvic Health

Our Pelvic Health Operating Unit advances care for patients living with bladder and bowel control conditions through targeted, minimally invasive neuromodulation therapies, including sacral and tibial solutions. Designed to modulate nerve pathways and restore communication between the brain and pelvic floor, these programmable therapies deliver personalized treatment supported by strong clinical evidence and long-term outcomes—helping improve confidence, independence, and quality of life.

Check us out on LinkedIn: Medtronic Pelvic Health

We’re working onsite 4 days a week at our Minnesota Rice Creek East facility, to drive performance, foster an environment of belonging, and collaborate to inspire as we engineer the extraordinary. 

The Senior Product Security Engineer will play a key role in securing connected and embedded medical devices across the full product lifecycle. This role is focused on device/product security engineering (not enterprise IT security) and partners closely with R&D, software, systems, and quality teams to design and implement robust, scalable security controls. 

The ideal candidate brings hands-on experience securing embedded or IoT products in regulated environments, with strong depth in threat modeling, secure architecture, cryptography, and device-level risk management. 

Key Responsibilities:

Product Security Engineering – Embed security requirements into the medical device development lifecycle, partnering with R&D and systems teams from architecture through release. 

Threat Modeling & Risk Assessment – Perform system-level threat modeling (e.g., STRIDE or similar), attack surface analysis, and vulnerability assessments for connected and embedded medical devices. 

Secure Architecture – Support and review implementation of device security capabilities, such as: 

  • Secure boot and root of trust 
  • Secure firmware/software update mechanisms 
  • Device identity and authentication 
  • Secure communications and protocol hardening 
  • Data protection at rest and in transit 
  • Key management and Hardware Security Module (HSM) concepts 

Cryptography & Post-Quantum Readiness – Apply modern cryptographic principles and support forward-looking strategies, including quantum-resistant approaches where applicable. 

Secure SDLC Integration – Partner with agile development teams to embed security into design reviews, code reviews, CI/CD pipelines, and verification activities. 

Verification & Validation – Define and support security V&V activities, including penetration testing, static/dynamic analysis, fuzz testing, and vulnerability management. 

Standards & Compliance – Ensure alignment with medical device cybersecurity expectations, including: 

  • FDA premarket cybersecurity guidance 
  • IEC 81001-5-1 
  • ISO 14971 
  • NIST frameworks 
  • Relevant Medtronic quality processes 

Minimum Requirements 

  • Bachelor’s degree in Computer Science, Computer Engineering, Electrical Engineering, or related technical field 

  • 4+ years of experience OR advanced degree with 2+ years of relevant experience   

Preferred:

  • Medical device cybersecurity experience 
  • Experience with IEC 81001-5-1 
  • Experience with FDA cybersecurity submissions 
  • Background in connected healthcare products 
  • Security certifications (Security+, CISSP, etc.) 
  • Embedded/device security 

Apply for this role

Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.

Apply Now →Generate Application Kit

Free account required — sign up in 30s

Company

Medtronic

View company profile →