EngineerJobs.io
← Back to all jobs

Job Description

The Cardiac Ablation Solutions unit seeks a Senior Product Security Engineer to strengthen cybersecurity for cardiac ablation medical devices and embedded systems. The role collaborates with engineering teams to embed security across the product lifecycle, guiding threat modeling, vulnerability assessments, and secure design.

Role Overview

This senior position specializes in product security for medical devices and embedded systems. It emphasizes partnering with cross-functional engineering teams to integrate cybersecurity into real-time devices, embedded firmware, and connected solutions, supporting ongoing resilience through lifecycle-wide security controls and design reviews.

Primary Responsibilities

  • Implement security requirements across the medical device development lifecycle by partnering with cross-functional teams and applying best practices from design through deployment.
  • Conduct threat modeling and vulnerability assessments to identify, prioritize, and help mitigate security risks throughout the product lifecycle.
  • Support the design and delivery of secure medical devices by implementing capabilities such as secure boot, secure communications, data protection, software update mechanisms, system integration protections, and access controls.
  • Apply medical device cybersecurity standards and guidance, including NIST, OWASP, and IEC 81001-5-1, working with development teams to strengthen security practices.
  • Remain current on cybersecurity trends affecting medical devices and health software, share best practices, and contribute to the long-term product security strategy.
  • Perform security assessments of company products, including vulnerability and risk assessments, threat analysis, and security code reviews to identify potential design and implementation vulnerabilities.
  • Design and develop security features for products, including systems, applications, and solutions.
  • Integrate new security features and updates into existing products and maintain security across the product lifecycle. Provide engineering recommendations and resolve integration and testing issues.
  • Develop a standardized set of security product requirements and produce metrics to report performance. Define security diagnostics and tools to facilitate analysis of security events, detect and mitigate risks, respond to incidents, and engage with customers on product security concerns. Lead or participate in security architecture and design reviews.

Required Qualifications

  • Product Security Engineering (Security by Design and Secure Software Development)
  • Threat Modeling
  • Risk Management / Vulnerability Assessment (CVSS)
  • Bachelor's degree in engineering, computer science, computer engineering, or related field with 4+ years of experience; or advanced degree with 2+ years of relevant experience
  • Experience in embedded device security within a regulated industry
  • Strong understanding of cybersecurity concepts and frameworks such as NIST and OWASP
  • Working knowledge of secure software development lifecycle principles and security-by-design practices
  • Experience collaborating with engineering teams to identify and address product security risks
  • Familiarity with medical device cybersecurity standards and guidance, including IEC 81001-5-1, ISO 14971, and FDA premarket and post-market cybersecurity guidance
  • Experience supporting FDA and other regulatory cybersecurity submissions
  • Experience with connected healthcare systems or cloud-connected medical devices
  • Security certifications such as CompTIA Security+, CISSP, or similar

Preferred Qualifications

  • Experience in embedded device security within a regulated industry
  • Strong understanding of cybersecurity concepts and frameworks such as NIST and OWASP
  • Working knowledge of secure software development lifecycle principles and security-by-design practices
  • Experience collaborating with engineering teams to identify and address product security risks
  • Familiarity with medical device cybersecurity standards and guidance, including IEC 81001-5-1, ISO 14971, and FDA premarket and post-market cybersecurity guidance
  • Experience supporting FDA and other regulatory cybersecurity submissions
  • Experience with connected healthcare systems or cloud-connected medical devices
  • Security certifications such as CompTIA Security+, CISSP, or similar

Position Description

The Cardiac Ablation Solutions (CAS) team is seeking a Senior Product Security Engineer to join its research and development organization and enhance the security of cardiac ablation medical device solutions. This role concentrates on cybersecurity for medical devices and embedded systems rather than IT security or compliance. The ideal candidate will collaborate with engineering teams to embed cybersecurity into real-time systems, embedded firmware, and connected devices, contributing to initiatives that elevate cyber resilience across the product lifecycle. The successful applicant will act as a technical subject matter expert, mentor colleagues, cross-functionally collaborate, and drive long-term improvements in product security posture.

Compensation

Pay range: $50.00 - $60.00 per hour

Work Location

Onsite in Saint Paul, Minnesota

Similar Jobs