Sr DevSecOps Engineer

MedtronicLafayette, CO
$124,800 - $187,200Onsite

About The Position

The Sr DevSecOps Engineer defines, implements, and governs secure embedded software platform practices for regulated medical device programs. This role provides technical leadership across CI/CD automation, embedded Linux security, software supply chain controls, vulnerability management, cybersecurity risk analysis, and release evidence generation to support safe, secure, and compliant medical device development. The Sr DevSecOps Engineer will join the Embedded OS Platforms and DevOps Team to implement secure embedded platform DevOps workflows for new and existing medical device development programs. The Embedded OS Platforms and DevOps Team delivers the software infrastructure and foundational system components that enable operation of product application software. This role is responsible for advancing reusable DevSecOps frameworks, secure CI/D pipelines and software supply chain practices, embedded Linux security capabilities, and cybersecurity lifecycle processes across multiple products. The successful candidate will serve as a technical lead who partners with OS and application software developers, systems, product security, quality, regulatory, and program teams to deliver secure, maintainable, and compliant platform solutions.

Requirements

  • AMD Zynq and Zynq UltraScale+ SoCs, NVIDIA ORIN, SafeRTOS, FreeRTOS
  • Yocto-based embedded Linux package development
  • Embedded hypervisors, Linux device drivers, BSPs, and boot flows
  • Custom build systems and CI/CD pipelines
  • Docker, Snyk, SonarQube, and software composition analysis tools
  • Static analysis, software composition analysis, artifact signing, and vulnerability management tools
  • Python, Bash, and Go
  • Atlassian tools including Bitbucket, Jira, Bamboo, and Confluence
  • GitHub and GitLab
  • Networking security, secure boot, firmware signing, and secure update technologies

Nice To Haves

  • Hands-on experience with cloud infrastructure (AWS or similar) and modern DevOps practices.
  • Proficiency with infrastructure-as-code and secure CI/CD tooling.
  • Familiarity with monitoring, observability, and incident management.
  • Experience with security technologies and practices including certificates, secrets management, and compliance support.
  • Experience developing DevSecOps workflows in regulated safety-critical environments such as aerospace, medical, automotive, or industrial controls.
  • Understanding of FDA cybersecurity expectations, IEC 62304, ISO 14971, ISO 13485, SOUP/OTS software management, SBOM practices, and software lifecycle evidence generation.
  • Experience implementing security automation in CI/CD pipelines, including SAST, SCA, container scanning, artifact signing, build reproducibility, traceability, and vulnerability reporting.
  • Experience with threat modeling, vulnerability assessment, cybersecurity risk analysis, and secure-by-design architecture reviews.
  • Ability to collaborate across hardware, software, systems, product security, quality, regulatory, program management, and product management stakeholders.
  • Strong debugging, problem-solving, and root-cause analysis skills.
  • Strong technical communication skills with the ability to translate cybersecurity and DevSecOps risks into actionable engineering and leadership decisions.

Responsibilities

  • Define and own the DevSecOps architecture and roadmap for embedded capital equipment platforms, including secure CI/CD pipelines, build infrastructure, security automation, and release evidence.
  • Establish secure software supply chain practices, including SBOM generation, SOUP/OTS component tracking, license awareness, vulnerability monitoring, end-of-support tracking, and remediation workflows.
  • Develop reusable CI/CD templates and pipeline controls for static analysis, software composition analysis, unit test automation, artifact signing, provenance tracking, cybersecurity evidence capture, and release readiness.
  • Lead threat modeling and cybersecurity risk analysis for embedded platform components, including asset identification, attack surface analysis, exploitability assessment, security controls, and traceability to risk mitigations.
  • Drive CVE intake, enrichment, asset mapping, triage, risk scoring, remediation planning, validation, and reporting in partnership with Product Security, SWQA, Systems, and program teams.
  • Design and implement secure boot, firmware signing, cryptographic configuration, key/certificate lifecycle support, authenticated update mechanisms, and secure device communication patterns.
  • Define runtime security monitoring requirements and support post-market cybersecurity monitoring and vulnerability response workflows. Review reported anomalies, assess cybersecurity impact, and support incident-response activities as needed.
  • Support regulatory submissions and audits by ensuring cybersecurity, software lifecycle, and DevSecOps evidence is complete, traceable, reproducible, and aligned with internal quality system expectations.
  • Collaborate with external vendors and internal partners to evaluate security tooling, embedded Linux support models, vulnerability intelligence, penetration testing outputs, and long-term maintenance approaches.
  • Provide technical leadership and mentoring to software engineers, DevOps engineers, and platform teams on secure coding, build automation, vulnerability handling, and regulated software development practices.

Benefits

  • Competitive Salary
  • Flexible Benefits Package
  • Health, Dental and vision insurance
  • Health Savings Account
  • Healthcare Flexible Spending Account
  • Life insurance
  • Long-term disability leave
  • Dependent daycare spending account
  • Tuition assistance/reimbursement
  • Simple Steps (global well-being program)
  • Incentive plans
  • 401(k) plan plus employer contribution and match
  • Short-term disability
  • Paid time off
  • Paid holidays
  • Employee Stock Purchase Plan
  • Employee Assistance Program
  • Non-qualified Retirement Plan Supplement
  • Capital Accumulation Plan
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service