Sr. Product Security Engineer - Cloud Digital Solutions

Medtronic•Fridley, MN
•$132,000 - $198,000

About The Position

The Neuromodulation and Pelvic Health R&D organizations, bring together a large set of Medtronic’s Neurosciences therapies and their project teams to employ the full breadth of our talent, technologies, products, services, and solutions to address the needs of customers and patients across the globe. These operating units offer devices and therapies to treat chronic pain, movement disorders, overactive bladder, non-obstructive urinary retention, and much more. The Senior Product Security Engineer – Cloud & Digital Solutions leads cybersecurity architecture for Digital Health Platforms, cloud services, web/mobile applications, APIs, remote monitoring, and digital ecosystems supporting connected medical devices.

Requirements

  • Bachelor’s degree in related field with 4 years of relevant experience OR masters degree in related field with 2 years of relevant experience (Computer Engineering, Electrical Engineering, Computer Science, Cybersecurity)
  • Extensive experience in cloud security, application security, digital platforms, cybersecurity architecture, or regulated software development.

Nice To Haves

  • Strong knowledge of cloud-native security, IAM, APIs, PKI, encryption, secrets management, containers, DevSecOps, logging/monitoring, and data protection.
  • Experience with threat modeling, SRA, SBOM/SCA, Security-by-Design, Defense-in-Depth, and regulated medical-device environments.
  • Understanding of medical device regulations and standards (e.g., FDA pre- and post-market guidance on cybersecurity for medical device manufacturers, ISO 13485, ISO 81001-5-1, ISO 27001, SOC2, HIPPA, HiTRUST).
  • Strong decision-making capabilities, weighing relative costs and benefits to identify the most appropriate solution.
  • High attention to detail with a focus on Good Documentation Practices (GDP).
  • Ability to communicate complex, technical information in a creative and engaging way to diverse audiences, orally and in writing.
  • Excellent prioritization skills, with an aptitude for breaking down work into manageable parts and assessing priority and time required.
  • Demonstrated ability to develop and grow productive, trusting, and open relationships with a wide variety of constituencies.
  • For Baccalaureate degrees earned outside of the United States, a degree that satisfies the requirements of 8 C.F.R. § 214.2(h)(4)(iii)(A) is required.

Responsibilities

  • Define Security-by-Design and Defense-in-Depth architecture for Digital Health Platforms, cloud-native services, web/mobile applications, APIs, and remote-monitoring solutions.
  • Define security requirements for identity, authentication, authorization, secrets, encryption, data protection, network segmentation, logging, and service-to-service communication.
  • Design secure interfaces between connected medical-device ecosystems and cloud/digital platforms.
  • Lead threat modeling, Security Risk Analysis, attack-surface analysis, and security requirements definition for cloud and digital solutions.
  • Translate threats into architecture controls, security requirements, verification activities, and risk-control evidence.
  • Maintain SBOM and software/component security requirements across cloud applications, services, containers, APIs, and third-party dependencies.
  • Define security requirements for data-at-rest, data-in-transit, transient data, retention, access control, and privacy across digital-health workflows.
  • Design secure identity, provisioning, certificate, credential, and secrets-management strategies for cloud-connected products and services.
  • Support secure eFOTA orchestration, remote monitoring, device-service authentication, telemetry, and secure digital-service integration.
  • Define cloud security monitoring, logging, vulnerability management, configuration security, and DevSecOps requirements.
  • Develop the application-security assurance roadmap and lead readiness, certification/attestation, and recertification activities for programs such as SOC 2, ISO/IEC 27001, HIPAA compliance, and other applicable security/privacy frameworks.
  • Coordinate control implementation, evidence collection, gap remediation, audit support, and continuous compliance across engineering, IT, quality, privacy, and business stakeholders.
  • Support regulatory submissions and alignment with medical-device cybersecurity, cloud-security, privacy, and digital-health requirements.

Benefits

  • Health, Dental and vision insurance
  • Health Savings Account
  • Healthcare Flexible Spending Account
  • Life insurance
  • Long-term disability leave
  • Dependent daycare spending account
  • Tuition assistance/reimbursement
  • Simple Steps (global well-being program)
  • Incentive plans
  • 401(k) plan plus employer contribution and match
  • Short-term disability
  • Paid time off
  • Paid holidays
  • Employee Stock Purchase Plan
  • Employee Assistance Program
  • Non-qualified Retirement Plan Supplement (subject to IRS earning minimums)
  • Capital Accumulation Plan (available to Vice Presidents and above, or subject to IRS earning minimums)
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service