Product Security Engineer (Embedded) -- PA

KAYGENIrvine, CA
Hybrid

About The Position

The Product Security Engineer (Embedded) will support the security of physical, IoT, and embedded medical devices, including embedded Linux and Windows-based platforms, throughout the engineering and product development lifecycle. The engineer will contribute to the development and delivery of secure products in alignment with applicable industry standards and global regulatory requirements. Working under the guidance of senior product security team members, this role will execute product security activities, identify and help mitigate security risks, and collaborate closely with software engineering, R&D, and other cross-functional stakeholders. The ideal candidate will have developed technical expertise in embedded security, strong problem-solving abilities, and the ability to work effectively in an agile engineering environment. A positive work ethic, strong communication skills, and a commitment to project objectives are essential.

Requirements

  • Bachelor’s degree in computer engineering, Cybersecurity, Computer Science, Software Engineering, or a related technical discipline.
  • 2+ years of professional experience in product security, cybersecurity, software development, product development, embedded systems, or software quality assurance.
  • Hands-on experience with embedded Linux, Windows Embedded/IoT, or RTOS-based systems.
  • Familiarity with C/C++ within an embedded software or security engineering environment.
  • Foundational knowledge of information security principles, secure software development, and product security standards.
  • Experience working within a structured software development lifecycle, preferably in an Agile/Scrum environment.
  • Ability to collaborate effectively with engineering and R&D teams.
  • Strong written, verbal, analytical, and problem-solving skills.
  • Must be based in or within reasonable commuting distance of the Irvine, California area.

Nice To Haves

  • Master's degree in Cybersecurity, Computer Science, Software Engineering, Computer Engineering, or a related field.
  • Experience with embedded or firmware security tools and techniques, including: Firmware image analysis, JTAG/SWD hardware debugging, Static analysis of C/C++ embedded code
  • Experience with product cybersecurity in regulated medical device environments, including familiarity with 510(k) and/or PMA-regulated products.
  • Experience with security risk assessments, threat modeling, vulnerability assessments, penetration testing, and security testing.
  • Familiarity with threat modeling methodologies such as STRIDE, PASTA, NIST, and OWASP.
  • Understanding of applied cryptography, including: Encryption algorithms and modes, Key lengths, Hashing, Secure key storage, Key management
  • Familiarity with PKI, including CA hierarchies, certificate lifecycle management, CRL, and OCSP.
  • Experience securing network communications, including TLS/mTLS configuration and validation.
  • Familiarity with medical, IoT, wireless, or device-specific protocols such as HL7, FHIR, and Bluetooth Low Energy (BLE).
  • Foundational understanding of cloud and API security, including authentication, authorization, and protection of sensitive data such as PHI/PII.
  • Experience with cybersecurity tools such as: Black Duck, Coverity, Veracode, Nessus, Snyk, Metasploit
  • Experience configuring and using static code analysis and vulnerability scanning tools.
  • Experience with connected products, embedded software, firmware, networking technologies, or regulated environments.
  • Industry-recognized cybersecurity certifications such as CCNA, CISSP, CISM, GIAC, CCSP, or CEH.

Responsibilities

  • Support engineering teams in defining and implementing security requirements and controls for products and product features.
  • Contribute to the implementation of security technologies and controls, including: Encryption, Authentication and authorization, Audit logging, System hardening, Software Bill of Materials (SBOM), Patch management, Vulnerability monitoring, Antivirus and antimalware controls, where applicable.
  • Help ensure security requirements align with applicable industry standards and regulatory expectations for medical and connected devices.
  • Support the selection and implementation of appropriate cryptographic algorithms and security mechanisms.
  • Assist with key management and secure key storage practices.
  • Support certificate lifecycle management, including certificate issuance, renewal, and revocation.
  • Apply foundational knowledge of cryptographic algorithms, hashing, key lengths, and encryption modes.
  • Evaluate and support secure communications between devices, applications, networks, and cloud-connected components.
  • Assist with validation of TLS/mTLS configurations and other secure communication mechanisms.
  • Support security assessment of relevant medical, proprietary, wireless, or device-specific communication protocols.
  • Assist in identifying and addressing security risks associated with cloud-connected products and device backends.
  • Support security assessments of APIs, including authentication, authorization, and data protection.
  • Apply foundational knowledge of protecting sensitive information in transit and at rest.
  • Participate in technical design reviews and security-focused code inspections.
  • Provide security recommendations and feedback to software engineers and R&D teams.
  • Promote secure coding practices throughout the software development lifecycle.
  • Support product security risk assessments, threat modeling, hazard analysis, and vulnerability management activities.
  • Assist with vulnerability identification, analysis, prioritization, remediation, and verification.
  • Review penetration testing and security assessment results and assist teams in implementing appropriate security controls.
  • Work closely with software development teams to address identified security issues.
  • Assist development teams with product security framework activities and processes.
  • Contribute to security documentation, including: Incident and Vulnerability Management Plans, Product Security White Papers, Security assessment documentation, Risk assessment documentation, Security test reports and supporting artifacts.
  • Participate in product security incident response activities as appropriate.
  • Assist with investigation, documentation, remediation, and follow-up activities related to product security incidents and vulnerabilities.
  • Support the deployment and use of vulnerability scanning and static code analysis tools.
  • Where applicable, assist engineering teams in implementing automated security testing.
  • Support automated verification of software vulnerabilities and operating system security patches.
  • Contribute to configuration and maintenance of security testing tools and processes.
  • Support the quality and completeness of R&D security test deliverables.
  • Assist with test design, data analysis, reporting, and technical review.
  • Help ensure security deliverables comply with applicable regulatory and quality requirements.
  • Collaborate with software engineers, firmware engineers, R&D teams, product teams, and other stakeholders.
  • Work effectively within an agile software development environment.
  • Stay current with emerging product security threats, vulnerabilities, tools, technologies, and industry practices.
  • Perform other duties as required.

Benefits

  • Free Healthcare Insurance
  • 401(k) Retirement Plan
  • Free Life Insurance
  • Sick Time Off
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service