Prin Product Security Engineer, Mounds View, MN
MedtronicAbout the role
At Medtronic you can begin a life-long career of exploration and innovation, while helping champion healthcare access and equity for all. You’ll lead with purpose, breaking down barriers to innovation in a more connected, compassionate world.
A Day in the Life
We value what makes you unique. Be a part of a company that thinks differently to solve problems, make progress, and deliver meaningful innovations.The Cardiac and Vascular Group brings all of our cardiac and vascular businesses together into one cross-functional, collaborative operating unit to employ the full breadth of our talent, technologies, products, services, and solutions to address the needs of customers and patients across the globe. Cardiac Rhythm Management offers devices and therapies to treat abnormal heart rhythms, as well as cardiac monitoring solutions.
Be on the frontlines of the emerging area of medical device cybersecurity as an integral member and technical leader within a team responsible for creating, deploying, and monitoring cybersecurity and information security solutions for
Medtronic’s medical devices and supporting IT infrastructure. Interact with external and internal cybersecurity researchers to identify and remediate vulnerabilities within Medtronic products and systems. Work directly with R&D teams to ensure all relevant security risks are identified and evaluated, and appropriate and well-balanced solutions are implemented. Develop project security management deliverables for regulatory bodies to comply with standards / guidance documents, and successfully communicate cybersecurity technology to customers, regulatory bodies, and other stakeholders.
At Medtronic, we bring bold ideas forward with speed and decisiveness to put patients first in everything we do. In-person exchanges are invaluable to our work. We are working onsite 4 days per week as part of our commitment to fostering a culture of professional growth and cross-functional collaboration as we work together to engineer the extraordinary. This role will require less than 10% of travel to enhance collaboration and ensure successful completion of projects.
Responsibilities may include the following and other duties may be assigned.
Performs security assessments of company products that may include vulnerability and risk assessments, threat analysis, and security code reviews to identify potential design and implementation vulnerabilities.
Designs and develops security features for products including systems, applications and/or solutions.
Integrates new security features and updates into existing products and ensures the security of all products is maintained throughout the product lifecycle.
Provides product security engineering recommendations and resolves integration and testing issues.
Builds a standardized set of security product requirements and produces metrics to report performance against those requirements.
Reviews and defines security diagnostics and tools to facilitate the analysis and reporting of security events.
Detects and mitigates security risks, responds to product security incidents, and works with customers regarding product security related issues.
Leads or participates in security architecture and design review meetings.
Performs the post-market security activities for medical devices, including vulnerability assessments, threat modeling, and risk analysis.
Develops and implements security strategies and best practices to protect medical device systems from emerging threats.
Collaborates with cross-functional teams, including R&D, Quality, Regulatory, and IT, to ensure security requirements are maintained and improved upon for released systems.
Monitors and analyzes security incidents, vulnerabilities, and threats related to medical devices in the field.
Conducts root cause analysis and develops corrective and preventive actions for security-related issues.
Provides technical guidance and mentorship to junior engineers and other team members.
Prepares and presents security metrics, reports, and recommendations to senior leadership and regulatory bodies.
Participates in external security forums, working groups, and industry conferences to represent the company and share knowledge.
Must Have: Minimum Requirements- To be considered for this role, please ensure the minimum requirements are evident in your applicant profile.
Bachelors degree required
Minimum of 7 years of relevant experience, or advanced degree with a minimum of 5 years relevant experience
Nice to Have:
Industry-recognized cert
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s