Product Security Engineer
BDAbout the role
We are the people who give possibilities purpose
BD is one of the largest global medical technology companies in the world. Advancing the world of health™ is our Purpose, and it’s no small feat. It takes the imagination and passion of all of us—from design and engineering to the manufacturing and marketing of our billions of MedTech products per year—to look at the impossible and find transformative solutions that turn dreams into possibilities.
Job Description
Summary:
The Product Security Engineer is responsible for supporting the security of a BD product or subset of features within the product across the development lifecycle. This individual contributes to the delivery of secure products consistent with global regulatory requirements by executing product security program activities under the guidance of senior team members.
This role works in partnership with R&D and other stakeholders to support compliance with security technical requirements and reduce security risks within the product or feature set. This includes hands-on execution of product security activities such as threat modeling, vulnerability scanning and remediation, and security risk assessments. The successful candidate will apply developing technical expertise to evaluate security vulnerabilities and contribute to maintainable technical solutions. Collaboration with software engineers and R&D team members in a dynamic and agile development environment is essential. Having demonstrated positive work ethic and commitment to achieving project goals with strong collaboration and communication skills - both written and verbal - is key for success in this role.
The Product Security Office (PSO) ensures product security risks for BD’s software-based products and solutions are managed well over the lifecycle as they make a difference for our patients and customers. In the PSO, we offer flexibility so you can successfully balance your work and personal responsibilities. We care about our associates and ensure we have servant leaders to help you grow your career, provide feedback and recognition, and empower you to show up every day as your authentic self. We are passionate about improving patient outcomes and enabling our R&D teams to create and maintain innovative solutions in a secure manner. Armed with a growth mindset and a desire to want to do more, learn more, impact more, you are in a great position to join us and help BD advance the world of health in ways you may never have imagined in your career.
Responsibilities:
Security Requirements & Implementation: Support project teams in defining and implementing security requirements and technologies for a product or set of features in accordance with industry standards for medical devices, including encryption, authentication, audit logging, hardening measures, SBOM creation and composition, patch management, vulnerability monitoring, and antivirus/antimalware as applicable.
Cryptography & PKI: Support the selection and implementation of appropriate cryptographic algorithms, key management practices, and certificate lifecycle management (issuance, renewal, revocation) for devices and cloud-connected components.
Secure Communications: Evaluate and support secure communication implementations across device interfaces and network protocols relevant to the product, including validation of TLS/mTLS configurations and medical or proprietary protocols as applicable.
Cloud & API Security: Assist in identifying and addressing security risks in cloud-connected device backends and associated APIs, including authentication, authorization, and protection of data in transit and at rest.
Design Reviews: Participate in technical design reviews and code inspections, providing feedback to project team members and following proper coding practices.
Security Assessments: Support execution of product security risk assessments, hazard analysis, and vulnerability remediation activities in coordination with product development software engineers.
Process & Documentation: Assist product development teams in complying with product security framework activities and contributing to security documentation, including Incident and Vulnerability Management Plans and Product Security White Papers.
Incident Response: Participate in product security incident response activities as appropriate.
Training & Procedures: Where applicable, support the deployment of software engineering procedures and training related to vulnerability scanning a
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s