Principal Product Security Penetration Testing Engineer
MedtronicAbout the role
At Medtronic you can begin a life-long career of exploration and innovation, while helping champion healthcare access and equity for all. You’ll lead with purpose, breaking down barriers to innovation in a more connected, compassionate world.
A Day in the Life
Act boldly. Compete to win. Move with speed and decisiveness. Foster belonging. Deliver results…the right way. That’s the Medtronic Mindset — our cultural norms. Our brand is rooted in action, not just words. The Medtronic Mindset defines the expectations of our culture. Every person here plays a role in bringing it to life. We recognize your extraordinary potential to ensure future generations live better, healthier lives.
The Medtronic Product Security Office (PSO), within the Enterprise Quality organization, provides corporate-level oversight, services, strategy, and collaboration across the Medtronic Operating Units to safeguard medical devices.
The Penetration Testing team within the Product Security Office is responsible for providing attacker-like testing, product assessments, and other feedback on the security of devices for Medtronic’s products to the distributed Operating Units across the organization.
The Principal Product Security Penetration Testing Engineer will execute complex testing to identify vulnerabilities in Medtronic products and assist with the identification of mitigation strategies. This testing will occur throughout a product’s lifecycle for new product development and market-released products. This person will report to Enterprise Quality, members of this team will consult with product development and support organizations, scope assessments, conduct testing, summarize results, and report findings; all with a high degree of quality, autonomy, and speed.
Position Responsibilities:
Scope, conduct, and report results of product security penetration tests to key stakeholders
Contribute ideas to the team to help design test scenarios and improve penetration testing processes
Coach junior members on the team and review testing results to ensure accuracy and completeness
Rate the severity of vulnerabilities that are identified through testing
Stay up to date on current security knowledge
Employ a variety of test methods to perform comprehensive vulnerability assessment and penetration testing of products
Identify and leverage appropriate tools and techniques to accomplish testing
Coordinate with product development engineers to ensure understanding of findings
Document, communicate, and summarize the results of testing to relevant stakeholders, including formal test reports
Maintain awareness of existing and emerging security research and leverage that knowledge during internal testing activities (an “attacker-like” approach to testing)
Analyze, triage and recreate vulnerabilities submitted to Medtronic by 3rd party security researchers
Understand current regulations and utilize that knowledge to inform internal testing activities
Show creativity and innovation in all aspects of your responsibilities
Operate with a high level of independence
Contribute to Product Security Office Fiscal Year Initiatives and strategic plans
Support ad hoc Product Security Office campaigns and initiatives
Must Have: Minimum Requirements:
To be considered for this role, please ensure the minimum requirements are evident on your resume.
Bachelors degree required
Minimum of 7 years of cybersecurity and/or secure software engineering experience or advanced degree with 5 years of cybersecurity and/or secure software engineering experience.
Nice to Have:
Experience in Product Security
Penetration Testing Certifications (e.g. CEH, OSCP, OSWA, GPEN, GMOB, Pentest+, etc.).
Other Information Security Certifications (e.g. Security+, CISSP, CISM, GSEC, etc.).
Experience assessing and testing the embedded security of regulated or safety critical devices.
Knowledge of the medical device industry.
Experience performing hardware and software penetration testing.
Experience working as an engineer or developer for embedded device hardware or firmware, mobile applications, web applications, or desktop applications.
Understanding of the security development process and product development process.
Ability to be creative to think “outside the box”.
Experience facilitating working sessions.
Knowle
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s