Medtronic Logo

Medtronic

-Principal Product Security Engineer

Reposted 4 Hours Ago
Be an Early Applicant
In-Office
4 Locations
153K-229K Annually
Senior level
In-Office
4 Locations
153K-229K Annually
Senior level
The Principal Product Security Engineer ensures security of medical devices, integrating cybersecurity measures, threat modeling, and risk assessments, while mentoring engineers and improving security posture.
The summary above was generated by AI
We anticipate the application window for this opening will close on - 20 Dec 2025


 

At Medtronic you can begin a life-long career of exploration and innovation, while helping champion healthcare access and equity for all. You’ll lead with purpose, breaking down barriers to innovation in a more connected, compassionate world.

A Day in the LifeThe Principal Product Security Engineer plays a critical role in ensuring the security of Medtronic Surgical Operating Unit medical device solutions. Reporting to the Director of Product Security, this role drives the integration of advanced cybersecurity measures, identifies and mitigates potential vulnerabilities, and supports initiatives that improve cyber-resiliency throughout the product lifecycle. You will serve as a technical subject matter expert and mentor, collaborating across teams and contributing to long-term improvements in our security posture.

Careers that Change Lives

​​​​​​​In this engineering-focused role, you will join a world-class team of systems, mechanical, electrical, software, and quality engineers within Medtronic’s Surgical Operating Unit (OU). The Surgical OU brings together the people and portfolios of Surgical Robotics and Surgical Innovations to advance surgical care through robotics, surgical energy technologies, and digital solutions.

This role focuses on cybersecurity for medical devices and embedded systems. It is not an IT security, compliance, or GRC-focused position. The ideal candidate will have deep experience working with engineering teams to integrate cybersecurity into real-time systems, embedded firmware, connected devices, or other product-level security contexts.

With the Medtronic Mission as our North Star, we build on our legacy of proven surgical solutions and continue advancing the promise of robotics and digital technologies to improve outcomes for our customers and patients.

This is an onsite role and can be located at one of these office locations: Boston, MA, Lafayette, CO, Minneapolis, MN, or North Haven, CT with a strong preference of Boston or Lafayette.

Make your impact by exploring a career with the world’s leading Medical Device company, striving “to alleviate pain, restore health, and extend life.” 

                                                                                                                                             

A Day in The Life

The Principal Product Security Engineer plays a critical role in ensuring the security of Medtronic Surgical Operating Unit medical device solutions. Reporting to the Director of Product Security, this role drives the integration of advanced cybersecurity measures, identifies and mitigates potential vulnerabilities, and supports initiatives that improve cyber-resiliency throughout the product lifecycle. You will serve as a technical subject matter expert and mentor, collaborating across teams and contributing to long-term improvements in our security posture.

Key Responsibilities:

  • Product Security Strategy & Continuous Learning - Stay abreast of emerging cybersecurity threats, technologies, and regulations specific to medical devices and health software. Contribute to OU and enterprise-wide product security strategy and roadmap development.
  • Secure Product Development Lifecycle - Drive security integration into all stages of the product lifecycle, from concept and design to postmarket. Work closely with system architects, software leads, and hardware engineers to embed secure design patterns in both embedded and cloud-connected environments.
  • Threat Modeling & Risk Assessment - Lead threat modeling sessions, conduct security risk assessments, and identify mitigation strategies in accordance with IEC 81001-5-1, ISO 14971, and FDA premarket cybersecurity guidance.
  • Security Architecture & Design - Collaborate on the design and implementation of secure architectures, focusing on secure boot, secure communications, data protection, access control, secure software updates, and hardware-software integration.
  • Security Testing & Analysis - Support and interpret results from vulnerability scans, penetration tests, and static/dynamic code analysis. Coordinate with internal teams and third-party vendors to ensure timely and appropriate risk mitigation.
  • Security Awareness & Mentorship - Promote a culture of security awareness within R&D and provide mentorship to junior engineers. Lead by example through documentation, review participation, and active knowledge sharing.
  • Regulatory & Standards Compliance - Ensure alignment with applicable standards (e.g., NIST, IEC 60601-4-5, IEC 81001-5-1) and support security documentation efforts for global regulatory submissions.
  • Vendor & Supply Chain Security - Review and assess the cybersecurity posture of third-party suppliers and open-source software components used within product designs.
  • Incident Response Support - Provide technical leadership during postmarket security incidents or field issues. Lead root cause investigations, containment strategies, and risk assessments.
  • Security Documentation - Maintain comprehensive security documentation, including threat model diagrams, risk assessments, shared service inventories, design patterns, security guidelines, and product security plans/reports.

Must Have Requirements

  • Bachelor’s degree with 7 years of experience
  • Or advanced degree with 5 years of technical experience

Nice to Have

  • Bachelor’s degree in a relevant engineering field of study (e.g., Computer Engineering, Software Engineering, or related discipline), completed and verified prior to start
  • Minimum 3 years of experience integrating security into embedded systems or connected medical devices in a regulated product development environment
  • Strong understanding of secure development lifecycle (SDLC), secure boot, cryptography, secure firmware update, secure communication, and hardware/software interface security
  • Master’s degree in a relevant engineering or cybersecurity field
  • Industry-recognized certifications (e.g., CISSP, CSSLP, CISM, CEH)
  • Experience mentoring or technically guiding junior security engineers
  • Demonstrated ability to implement secure architecture in embedded and connected device ecosystems
  • Familiarity with FDA and MDR cybersecurity submission requirements
  • Knowledge of secure coding practices and common vulnerabilities (e.g., OWASP, CWE, CVSS)
  • Experience supporting cross-functional design reviews or formal design assurance processes
  • Working knowledge of secure boot chains, cryptographic controls, and device authentication protocols

Physical Job Requirements

The above statements are intended to describe the general nature and level of work being performed by employees assigned to this position, but they are not an exhaustive list of all the required responsibilities and skills of this position. 

The physical demands described within the Responsibilities section of this job description are representative of those that must be met by an employee to successfully perform the essential functions of this job. Reasonable accommodations may be made to enable individuals with disabilities to perform the essential functions. For Office Roles: While performing the duties of this job, the employee is regularly required to be independently mobile. The employee is also required to interact with a computer, and communicate with peers and co-workers. Contact your manager or local HR to understand the Work Conditions and Physical requirements that may be specific to each role.

Benefits & Compensation
 

Medtronic offers a competitive Salary and flexible Benefits Package
A commitment to our employees lives at the core of our values. We recognize their contributions. They share in the success they help to create.  We offer a wide range of benefits, resources, and competitive compensation plans designed to support you at every career and life stage.
 

Salary ranges for U.S (excl. PR) locations (USD):$152,800.00 - $229,200.00

This position is eligible for a short-term incentive called the Medtronic Incentive Plan (MIP).

The base salary range is applicable across the United States, excluding Puerto Rico and specific locations in California. The offered rate complies with federal and local regulations and may vary based on factors such as experience, certification/education, market conditions, and location. Compensation and benefits information pertains solely to candidates hired within the United States (local market compensation and benefits will apply for others).

The following benefits and additional compensation are available to those regular employees who work 20+ hours per week: Health, Dental and vision insurance, Health Savings Account, Healthcare Flexible Spending Account, Life insurance, Long-term disability leave, Dependent daycare spending account, Tuition assistance/reimbursement, and Simple Steps (global well-being program).

 

The following benefits and additional compensation are available to all regular employees: Incentive plans, 401(k) plan plus employer contribution and match, Short-term disability, Paid time off, Paid holidays, Employee Stock Purchase Plan, Employee Assistance Program, Non-qualified Retirement Plan Supplement (subject to IRS earning minimums), and Capital Accumulation Plan (available to Vice Presidents and above, or subject to IRS earning minimums).

 

Regular employees are those who are not temporary, such as interns.  Temporary employees are eligible for paid sick time, as required under applicable state law, and the Employee Stock Purchase Plan. Please note some of the above benefits may not apply to workers in Puerto Rico.

 

Further details are available at the link below:

Medtronic benefits and compensation plans

About Medtronic

We lead global healthcare technology and boldly attack the most challenging health problems facing humanity by searching out and finding solutions.
Our Mission — to alleviate pain, restore health, and extend life — unites a global team of 95,000+ passionate people. 
We are engineers at heart— putting ambitious ideas to work to generate real solutions for real people. From the R&D lab, to the factory floor, to the conference room, every one of us experiments, creates, builds, improves and solves. We have the talent, diverse perspectives, and guts to engineer the extraordinary.

Learn more about our business, mission, and our commitment to diversity here.

It is the policy of Medtronic to provide equal employment opportunity (EEO) to all persons regardless of age, color, national origin, citizenship status, physical or mental disability, race, religion, creed, gender, sex, sexual orientation, gender identity and/or expression, genetic information, marital status, status with regard to public assistance, veteran status, or any other characteristic protected by federal, state or local law. In addition, Medtronic will provide reasonable accommodations for qualified individuals with disabilities.

If you are applying to perform work for Medtronic, Inc. (“Medtronic”) in any position which will involve performing at least two (2) hours of work on average each week within the unincorporated areas of Los Angeles County, you can find here a list of all material job duties of the specific job position which Medtronic reasonably believes that criminal history may have a direct, adverse and negative relationship potentially resulting in the withdrawal of a conditional offer of employment. Medtronic will consider for employment qualified job applicants with arrest or conviction records in accordance with the Los Angeles County Fair Chance Ordinance for Employers and the California Fair Chance Act.

Top Skills

Cryptography
Cybersecurity
Embedded Systems
Secure Boot
Secure Communications
Secure Development Lifecycle

Similar Jobs

An Hour Ago
In-Office
Bedford, MA, USA
121K-151K Annually
Senior level
121K-151K Annually
Senior level
Software • Energy
The Principal Product Security Engineer will lead product security operations, driving risk mitigation, compliance, and secure development practices while collaborating with teams to enhance security profiles and address client needs.
Top Skills: AIAWSAzureDastIec 62443-4-1Iec 62443-4-2Iso27002NistSastSca
3 Hours Ago
Hybrid
3 Locations
123K-123K Annually
Senior level
123K-123K Annually
Senior level
Artificial Intelligence • Professional Services • Business Intelligence • Consulting • Cybersecurity • Generative AI
The role involves leading technology strategy, managing cross-functional teams, and driving cloud adoption and enterprise-wide transformations.
Top Skills: AgileCloud ComputingScrum
3 Hours Ago
Hybrid
Boston, MA, USA
101K-157K Annually
Senior level
101K-157K Annually
Senior level
Artificial Intelligence • Big Data • Cloud • Information Technology • Machine Learning • Software
The Sr. Partner Marketing Manager will develop and execute partner marketing strategies, campaigns, and manage relationships with key partners to drive growth.
Top Skills: B2B MarketingCampaign ManagementCo-MarketingDigital CampaignsRelationship Management

What you need to know about the Colorado Tech Scene

With a business-friendly climate and research universities like CU Boulder and Colorado State, Colorado has made a name for itself as a startup ecosystem. The state boasts a skilled workforce and high quality of life thanks to its affordable housing, vibrant cultural scene and unparalleled opportunities for outdoor recreation. Colorado is also home to the National Renewable Energy Laboratory, helping cement its status as a hub for renewable energy innovation.

Key Facts About Colorado Tech

  • Number of Tech Workers: 260,000; 8.5% of overall workforce (2024 CompTIA survey)
  • Major Tech Employers: Lockheed Martin, Century Link, Comcast, BAE Systems, Level 3
  • Key Industries: Software, artificial intelligence, aerospace, e-commerce, fintech, healthtech
  • Funding Landscape: $4.9 billion in VC funding in 2024 (Pitchbook)
  • Notable Investors: Access Venture Partners, Ridgeline Ventures, Techstars, Blackhorn Ventures
  • Research Centers and Universities: Colorado School of Mines, University of Colorado Boulder, University of Denver, Colorado State University, Mesa Laboratory, Space Science Institute, National Center for Atmospheric Research, National Renewable Energy Laboratory, Gottlieb Institute

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account