Senior Product Security Engineer

MedtronicMinneapolis, MN
6hOnsite

About The Position

At Medtronic you can begin a life-long career of exploration and innovation, while helping champion healthcare access and equity for all. You’ll lead with purpose, breaking down barriers to innovation in a more connected, compassionate world. A Day in the Life In this critical role you will act as Senior Product Security Engineer, reporting to the Senior Engineering Director within the Product Security Office (PSO) in Corporate Quality. This role is a member of the PSIRT (Product Security Incident Response Team) which is responsible for monitoring, assessing impact, and coordinating Medtronic’s response to security vulnerabilities that could impact our medical device products. This team owns the Coordinated Vulnerability Disclosure Program. We believe that when people from different cultures, genders, and points of view come together, innovation is the result —and everyone wins. Medtronic walks the walk, creating an inclusive culture where you can thrive. Our unwavering commitment to inclusion, diversity, and equity (ID&E) means zero barriers to opportunity within Medtronic and a culture where all employees belong, are respected, and feel valued for who they are and the life experiences they contribute. We know equity starts beyond our workplace, and we must play a role in addressing systemic inequities in our communications if we hope to have long-term sustainable impact. Anchored in our Mission, we continue to drive ID&E forward both to enhance the well-being of Medtronic employees and to accelerate innovation that brings our lifesaving technologies to more people in more places around the world. At Medtronic, we bring bold ideas forward with speed and decisiveness to put patients first in everything we do. In-person exchanges are invaluable to our work. We’re working a minimum of 4 days a week onsite as part of our commitment to fostering a culture of professional growth and cross-functional collaboration as we work together to engineer the extraordinary. This position supports the PSIRT processes including vulnerability vigilance, signal monitoring, and incident response, and assists with managing the coordinated disclosure work at Medtronic. This role will collaborate with a diverse set of stakeholders to intake and assess vulnerabilities and/or incidents, determine their relevance to MDT products, and disposition the communication of these vulnerabilities, to key stakeholders. Familiarity of embedded systems, security environments, authoritative sources of vulnerability data, security scanning tools, and common attack vectors is important. Key objectives include: Support ongoing assessment of product security related “signals” pertaining to potential vulnerabilities and/or incidents regarding Medtronic connected products. Provide both planned and on-demand support for vulnerability assessments for Medtronic businesses in support of regulatory activities. Readiness for meeting forthcoming cybersecurity reporting requirements in CY 2026 from US Cyber Incident Reporting for Critical Infrastructure Act (CIRCIA) and EU Cyber Resilience Act. Support identification, documentation, and assessment of technology, tools, and associated processes in use by the PSO. Assist in developing an appropriate architecture framework in alignment with the key strategic pillars of Security by Design and Vulnerability Vigilance. Participate in conducting an industry assessment for appropriate tooling/solution selection if necessary. Implement proposed framework to improve PSO visibility, reporting, metrics, and overall maturity in the PSO strategy Support enterprise quality program for SBOMs (“Software Bill of Materials”) with adherence to industry defined standards such as CycloneDX, SPDX (“Software Package Data Exchange”), VEX (“Vulnerability Exploitability eXchange”), and the evolving needs of the SBOM program. Enable creation of high-quality SBOMs and dissemination of best practices for SBOM generation in support of need for both internal teams inside Medtronic and outside partners such as HDOs, regulators, and customers. Apply technical understanding of vulnerability management, security controls/threat modeling, penetration testing/DAST (“Dynamic Application Security Testing”). Partner with internal product teams to support implementation of mature DevSecOps practices, and drive improvements to existing product development processes (verification, validation, release).

Requirements

  • Requires a Bachelors degree and minimum of 4 years of relevant experience OR Master's degree with a minimum of 2 years relevant experience OR PhD with 0 years relevant experience.

Nice To Haves

  • 5-10 years of program management/development experience with a bachelor’s degree
  • Experience in Product Security and Cyber Security
  • Excellent written and verbal communication skills including demonstrated influence of stakeholders across an organization
  • Occasional after-hours availability to accommodate different regional and global partners.
  • Experience working in a regulated environment and/or a formal quality system
  • Some technical and troubleshooting skills.
  • Strong capability to research and evaluate emerging technologies
  • Preference is given to those with relevant product security or engineering experience.
  • Strong in interpersonal communication and demonstrate a collaborative work style.
  • Comfortable working in an ambiguous environment.
  • Innovative thinker; ability to think outside of the current norms and processes
  • Independent self-starter
  • Strong communication and collaboration skills
  • Solid writing and presentation skills
  • Interest in novel applications of technology
  • Experience integrating Shift-left security tools and practices
  • Familiarity with Git-based workflows and foundational python skills
  • Work with outside vendors, and support product teams that work with vendors.
  • Strengthen relationships with critical Engineering, Quality, Regulatory Affairs, Global Security office, Global IT, and Leadership stakeholders in Operating Units.

Responsibilities

  • Assuming support for Dependency Track instance (maintenance, etc) within Product Security office for SBOM vulnerability assessment.
  • Strong familiarization with SBOM authoring, i.e., making an SBOM (generation, augmentation, enrichment, signing, etc.).
  • Experienced with DevSecOps, SDLC, Scrum framework, Agile/waterfall methodology, and related software design principles to support SBOM efforts in premarket products.
  • Experienced with SCA (“Software Composition Analysis”), binary analysis, SAST (“Static Application Security Testing”), limited reverse engineering skills to support SBOM efforts in post market/legacy products.
  • Familiarity with FOSS (“Free and Open-Source Software”) ecosystems, package management, and differences with proprietary/closed-source software distribution.
  • Must have experience and knowledge working with regulated medical devices and cybersecurity requirements.
  • Remain informed on Regulatory requirements for Product Security.
  • Enable strong partnerships across the organization to drive best-in-class product security mechanisms.
  • Continuously anticipate and be prepared for audits.
  • Proactively engage with third party stakeholders such as researchers, industry peers, regulators, and potentially Medtronic customers.
  • Benchmark with external organizations for best practices on product security tooling architecture.
  • Contribute to company standards and policies related to product security risks.
  • Works with little direction towards predetermined long-range goals and objectives.
  • Establishes streamlined processes and structures that accelerate change initiatives; plays a leadership role in change efforts.
  • Escalate security and privacy issues as appropriate when discovered.

Benefits

  • Medtronic offers a competitive Salary and flexible Benefits Package
  • Health, Dental and vision insurance
  • Health Savings Account
  • Healthcare Flexible Spending Account
  • Life insurance
  • Long-term disability leave
  • Dependent daycare spending account
  • Tuition assistance/reimbursement
  • Simple Steps (global well-being program)
  • Incentive plans
  • 401(k) plan plus employer contribution and match
  • Short-term disability
  • Paid time off
  • Paid holidays
  • Employee Stock Purchase Plan
  • Employee Assistance Program
  • Non-qualified Retirement Plan Supplement (subject to IRS earning minimums)
  • Capital Accumulation Plan (available to Vice Presidents and above, or subject to IRS earning minimums)
© 2024 Teal Labs, Inc
Privacy PolicyTerms of Service