At Medtronic you can begin a life-long career of exploration and innovation while helping champion healthcare access and equity for all. Youll lead with purpose breaking down barriers to innovation in a more connected compassionate world.
In this critical role you will act as Senior Product Security Engineer reporting to the Senior Engineering Director within the Product Security Office (PSO) in Corporate Quality. This role is a member of the PSIRT (Product Security Incident Response Team) which is responsible for monitoring assessing impact and coordinating Medtronics response to security vulnerabilities that could impact our medical device team owns the Coordinated Vulnerability Disclosure Program.
We believe that when people from different cultures genders and points of view come together innovation is the result and everyone wins. Medtronic walks the walk creating an inclusive culture where you can unwavering commitment to inclusion diversity and equity (ID&E) means zero barriers to opportunity within Medtronic and a culture where all employees belong are respected and feel valued for who they are and the life experiences they know equity starts beyond our workplace and we must play a role in addressing systemic inequities in our communications if we hope to have long-term sustainable impact.
Anchored in our Mission we continue to drive ID&E forward both to enhance the well-being of Medtronic employees and to accelerate innovation that brings our lifesaving technologies to more people in more places around the world.
At Medtronic we bring bold ideas forward with speed and decisiveness to put patients first in everything we -person exchanges are invaluable to our work. Were working a minimum of 4 days a week onsite as part of our commitment to fostering a culture of professional growth and cross-functional collaboration as we work together to engineer the extraordinary.
This position supports the PSIRT processes including vulnerability vigilance signal monitoring and incident response and assists with managing the coordinated disclosure work at Medtronic. This role will collaborate with a diverse set of stakeholders to intake and assess vulnerabilities and/or incidents determine their relevance to MDT products and disposition the communication of these vulnerabilities to key stakeholders. Familiarity of embedded systems security environments authoritative sources of vulnerability data security scanning tools and common attack vectors is important.
Key objectives include:
Support ongoing assessment of product security related signals pertaining to potential vulnerabilities and/or incidents regarding Medtronic connected products.
Provide both planned and on-demand support for vulnerability assessments for Medtronic businesses in support of regulatory activities.
Readiness for meeting forthcoming cybersecurity reporting requirements in CY 2026 from US Cyber Incident Reporting for Critical Infrastructure Act (CIRCIA) and EU Cyber Resilience Act.
Support identification documentation and assessment of technology tools and associated processes in use by the PSO.
Assist in developing an appropriate architecture framework in alignment with the key strategic pillars of Security by Design and Vulnerability Vigilance.
Participate in conducting an industry assessment for appropriate tooling/solution selection if necessary.
Implement proposed framework to improve PSO visibility reporting metrics and overall maturity in the PSO strategy
Support enterprise quality program for SBOMs (Software Bill of Materials) with adherence to industry defined standards such as CycloneDX SPDX (Software Package Data Exchange) VEX (Vulnerability Exploitability eXchange) and the evolving needs of the SBOM program.
Enable creation of high-quality SBOMs and dissemination of best practices for SBOM generation in support of need for both internal teams inside Medtronic and outside partners such as HDOs regulators and customers. Apply technical understanding of vulnerability management security controls/threat modeling penetration testing/DAST (Dynamic Application Security Testing).
Partner with internal product teams to support implementation of mature DevSecOps practices and drive improvements to existing product development processes (verification validation release).
Specific responsibilities include:
Assuming support for Dependency Track instance (maintenance etc) within Product Security office for SBOM vulnerability assessment.
Strong familiarization with SBOM authoring i.e. making an SBOM (generation augmentation enrichment signing etc.).
Experienced with DevSecOps SDLC Scrum framework Agile/waterfall methodology and related software design principles to support SBOM efforts in premarket products.
Experienced with SCA (Software Composition Analysis) binary analysis SAST (Static Application Security Testing) limited reverse engineering skills to support SBOM efforts in post market/legacy products.
Familiarity with FOSS (Free and Open-Source Software) ecosystems package management and differences with proprietary/closed-source software distribution.
Must have experience and knowledge working with regulated medical devices and cybersecurity requirements.
Remain informed on Regulatory requirements for Product Security.
Enable strong partnerships across the organization to drive best-in-class product security mechanisms.
Continuously anticipate and be prepared for audits.
Proactively engage with third party stakeholders such as researchers industry peers regulators and potentially Medtronic customers.
Benchmark with external organizationsfor best practices on product security tooling architecture.
Contribute to company standards and policies related to product security risks.
Works with little direction towards predetermined long-range goals and objectives.
Establishes streamlined processes and structures that accelerate change initiatives; plays a leadership role in change efforts.
Escalate security and privacy issues as appropriate when discovered.
Must Have: Minimum Requirements:
To be considered for this role please ensure the minimum requirements are evident on your resume.
Requires a Bachelors degreeand minimum of 4 years of relevant experience OR Masters degree with a minimum of 2 years relevant experience OR PhD with 0 years relevant experience.
Nice to Have
5-10 years of program management/development experience with a bachelors degree
Experience in Product Security and Cyber Security
Excellent written and verbal communication skills including demonstrated influence of stakeholders across an organization
Occasional after-hours availability to accommodate different regional and global partners.
Experience working in a regulated environment and/or a formal quality system
Some technical and troubleshooting skills.
Strong capability to research and evaluate emerging technologies
Preference is given to those with relevant product security or engineering experience.
Strong in interpersonal communication and demonstrate a collaborative work style.
Comfortable working in an ambiguous environment.
Innovative thinker; ability to think outside of the current norms and processes
Independent self-starter
Strong communication and collaboration skills
Solid writing and presentation skills
Interest in novel applications of technology
Experience integrating Shift-left security tools and practices
Familiarity with Git-based workflows and foundational python skills
Work with outside vendors and support product teams that work with vendors.
Strengthen relationships with critical Engineering Quality Regulatory Affairs Global Security office Global IT and Leadership stakeholders in Operating Units.
Physical Job Requirements
The above statements are intended to describe the general nature and level of work being performed by employees assigned to this position but they are not an exhaustive list of all the required responsibilities and skills of this position.
The physical demands described within the Responsibilities section of this job description are representative of those that must be met by an employee to successfully perform the essential functions of this job. Reasonable accommodations may be made to enable individuals with disabilities to perform the essential functions. For Office Roles: While performing the duties of this job the employee is regularly required to be independently mobile. The employee is also required to interact with a computer and communicate with peers and co-workers. Contact your manager or local HR to understand the Work Conditions and Physical requirements that may be specific to each role.
Medtronic offers a competitive Salary and flexible Benefits Package
A commitment to our employees lives at the core of our values. We recognize their contributions. They share in the success they help to create. We offer a wide range of benefits resources and competitive compensation plans designed to support you at every career and life stage.
The following benefits and additional compensation are available to those regular employees who work 20 hours per week: Health Dental and vision insuranceHealth Savings AccountHealthcare Flexible Spending AccountLife insurance Long-term disability leaveDependent daycare spending accountTuition assistance/reimbursement andSimple Steps (global well-being program).
The following benefits and additional compensation are available to all regular employees:Incentive plans 401(k) plan plus employer contribution and matchShort-term disabilityPaid time offPaid holidaysEmployee Stock Purchase PlanEmployee Assistance ProgramNon-qualified Retirement Plan Supplement (subject to IRS earning minimums) andCapital Accumulation Plan (available to Vice Presidents and above or subject to IRS earning minimums).
Regular employees are those who are not temporary such as interns. Temporary employees are eligible for paid sick time as required under applicable state law and the Employee Stock Purchase Plan. Please note some of the above benefits may not apply to workers in Puerto Rico.
Further details are available at the link below:
Medtronic benefits and compensation plans
We lead global healthcare technology and boldly attack the most challenging health problems facing humanity by searching out and finding solutions.
Our Mission to alleviate pain restore health and extend life unites a global team of 95000 passionate people.
We are engineers at heart putting ambitious ideas to work to generate real solutions for real people. From the R&D lab to the factory floor to the conference room every one of us experiments creates builds improves and solves. We have the talent diverse perspectives and guts to engineer the extraordinary.
Learn more about our business mission and our commitment to diversity here.
It is the policy of Medtronic to provide equal employment opportunity (EEO) to all persons regardless of age color national origin citizenship status physical or mental disability race religion creed gender sex sexual orientation gender identity and/or expression genetic information marital status status with regard to public assistance veteran status or any other characteristic protected by federal state or local addition Medtronic will provide reasonable accommodations for qualified individuals with disabilities.
If you are applying to perform work for Medtronic Inc. (Medtronic) in any position which will involve performing at least two (2) hours of work on average each week within the unincorporated areas of Los Angeles County you can findhere a list of all material job duties of the specific job position which Medtronic reasonably believes that criminal history may have a direct adverse and negative relationship potentially resulting in the withdrawal of a conditional offer of employment. Medtronic will consider for employment qualified job applicants with arrest or conviction records in accordance with the Los Angeles County Fair Chance Ordinance for Employers and the California Fair Chance Act.
Required Experience:
Senior IC
About Medtronic Together, we can change healthcare worldwide. At Medtronic, we push the limits of what technology can do to help alleviate pain, restore health and extend life. We challenge ourselves and each other to make tomorrow better than yesterday. It is what makes this an excit ... View more