Job Detail

Sr. Product Security Engineer - Medtronic
Lafayette, CO
Posted: Sep 24, 2024 02:42

Job Description

At Medtronic you can begin a life-long career of exploration and innovation, while helping champion healthcare access and equity for all. You'll lead with purpose, breaking down barriers to innovation in a more connected, compassionate world.

A Day in the Life

A Day in The Life

The Senior Product Security Engineer is instrumental in ensuring the robust security of our Surgical OU medical device products and solutions. Reporting directly to the Director of Product Security, this pivotal role spearheads the integration of state-of-the-art security measures, identifies potential vulnerabilities, and champions initiatives to bolster cyber-resiliency throughout the product's life cycle. A profound understanding of regulated embedded devices, environments that underpin client-facing medical device solutions, and adherence to product security compliance frameworks is essential.

Key Responsibilities:

Product Security Strategy & Continuous Learning - Participate in ongoing professional development to stay current with emerging cybersecurity trends and threats related to medical devices and health software products. Contribute to the development and refinement of product security strategies within the Operating Unit (OU), ensuring alignment with established industry best practices and regulatory requirements. Collaborate with senior team members to implement security measures and continuously improve product security processes.

Product Security - Support and lead integration of security into the product development lifecycle, ensuring that security considerations are incorporated from design to deployment. Assist in implementing security measures across medical devices, OT, ICS, IoT, and enterprise security processes/standards. Work closely with cross-functional teams to ensure security is a core part of the product design and development process.

Risk Assessment - Conduct threat modeling, security risk evaluations, and vulnerability assessments to identify and mitigate potential security risks throughout the product lifecycle. Work under limited supervision to address security threats and provide recommendations for risk mitigation. Collaborate with cross-functional teams to ensure risks are evaluated and managed in alignment with security best practices and regulatory requirements.

Security Architecture - Contribute to the design and deployment of secure medical device architectures and product designs. Assist in the implementation of key security features such as secure boot, secure communications, data protection, secure updates, secure integration, and access controls. Collaborate with senior engineers to ensure that security architecture aligns with product security requirements and best practices. Provide input on security design decisions and work to ensure effective implementation throughout the product lifecycle.

Security Standards & Testing - Assist in maintaining and implementing security standards, policies, and procedures for medical device systems and product development. Contribute to security testing activities, including vulnerability scanning, penetration testing, and code reviews. Collaborate with cross-functional teams to ensure adherence to security standards and participate in evaluating testing results to identify and address security vulnerabilities. Provide guidance on testing procedures and contribute to continuous improvement of security practices.

Security Awareness - Contribute to promoting security awareness and assist in delivering training across cross-functional product development teams. Help foster a security-conscious culture by sharing best practices and providing support on security-related topics. Collaborate with engineers to ensure that teams understand the importance of security in product development and work towards embedding security into everyday practices.

Compliance - Ensure compliance with industry standards and regulations related to medical device and health software product security, such as NIST, IEC 60601-4-5, IEC 81001-5-1, and others.

Vendor Assessment - Evaluate third-party vendors and suppliers for their security practices and ensure they meet our security requirements.

Incident Management - Lead and support the effective response to security incidents, ensuring swift resolution, proper mitigation, and clear communication to stakeholders, including customers when needed.

Documentation - Maintain detailed documentation of security best practices, guidance, configurations, design patterns, shared service designs, inventories, incident response plans, security architectures, and reports.

Responsibilities may include the following and other duties may be assigned.

  • Performs security assessments of company products that may include vulnerability and risk assessments, threat analysis, and security code reviews to identify potential design and implementation vulnerabilities.

  • Designs and develops security features for products including systems, applications and/or solutions.

  • Integrates new security features and updates into existing products and ensures the security of all products is maintained throughout the product lifecycle.

  • Provides product security engineering recommendations and resolves integration and testing issues.

  • Builds a standardized set of security product requirements and produces metrics to report performance against those requirements.

  • Reviews and defines security diagnostics and tools to facilitate the analysis and reporting of security events.

  • Detects and mitigates security risks, responds to product security incidents, and works with customers regarding product security related issues.

  • Leads or participates in security architecture and design review meetings.

TECHNICAL SPECIALIST CAREER STREAM: An individual contributor with responsibility in our technical functions to advance existing technology or introduce new technology and therapies. Formulates, delivers and/or manages projects assigned and works with other stakeholders to achieve desired results. May act as a mentor to colleagues or may direct the work of other lower level professionals. The majority of time is spent delivering R&D, systems or initiatives related to new technologies or therapies - from design to implementation - while adhering to policies, using specialized knowledge and skills.

DIFFERENTIATING FACTORS

Autonomy: Seasoned individual contributor.

Works independently under limited supervision to determine and develop approach to solutions.

Coaches and reviews the work of lower level specialists; may manage projects / processes.

Organizational Impact: May be responsible for entire projects or processes within job area.

Contributes to the completion of work group objectives, through building relationships and consensus to reach agreements on assignments.

Innovation and Complexity: Problems and issues faced are difficult, and may require understanding of multiple issues, job areas or specialties.

Makes improvements of processes, systems or products to enhance performance of the job area.

Analysis provided is in-depth in nature and often provides recommendations on process improvements.

Communication and Influence: Communicates with senior internal and external customers and vendors.

Exchange information of facts, statuses, ideas and issues to achieve objective, and influence decision-making.

Leadership and Talent Management: May provide guidance, coaching and training to other employees within job area.

May manage projects, requiring delegation of work and review of others' work product.

Required Knowledge and Experience: Requires advanced knowledge of job area combining breadth and depth, typically obtained through advanced education combined with experience.

May have practical knowledge of project management.

Requires a Baccalaureate Degree and minimum of 4 years of relevant experience, or advanced degree with a minimum of 2 years relevant experience. (For degrees earned outside of the United States, a degree which satisfies the requirements of 8 C.F.R. 214.2(h)(4)(iii)(A)).

Physical Job Requirements

The above statements are intended to describe the general nature and level of work being performed by employees assigned to this position, but they are not an exhaustive list of all the required responsibilities and skills of this position.

The physical demands described within the Responsibilities section of this job description are representative of those that must be met by an employee to successfully perform the essential functions of this job. Reasonable accommodations may be made to enable individuals with disabilities to perform the essential functions. For Office Roles: While performing the duties of this job, the employee is regularly required to be independently mobile. The employee is also required to interact with a computer, and communicate with peers and co-workers. Contact your manager or local HR to understand the Work Conditions and Physical requirements that may be specific to each role.

Benefits & Compensation

Medtronic offers a competitive Salary and flexible Benefits Package

A commitment to our employees lives at the core of our values. We recognize their contributions. They share in the success they help to create. We offer a wide range of benefits, resources, and competitive compensation plans designed to support you at every career and life stage.

Salary ranges for U.S (excl. PR) locations (USD):$123,200.00 - $184,800.00

This position is eligible for a short-term incentive called the Medtronic Incentive Plan (MIP).

The base salary range is applicable across the United States, excluding Puerto Rico and specific locations in California. The offered rate complies with federal and local regulations and may vary based on factors such as experience, certification/education, market conditions, and location. Compensation and benefits information pertains solely to candidates hired within the United States (local market compensation and benefits will apply for others).

Medtronic benefits and compensation plans (https://www3.benefitsolver.com/benefits/BenefitSolverView?page_name=signon&co_num=30601&co_affid=medtronic)

About Medtronic

We lead global healthcare technology and boldly attack the most challenging health problems facing humanity by searching out and finding solutions.

Our Mission - to alleviate pain, restore health, and extend life - unites a global team of 90,000+ passionate people.

We are engineers at heart- putting ambitious ideas to work to generate real solutions for real people. From the R&D lab, to the factory floor, to the conference room, every one of us experiments, creates, builds, improves and solves. We have the talent, diverse perspectives, and guts to engineer the extraordinary.

Learn more about our business, mission, and our commitment to diversity here (http://www.medtronic.com) .

It is the policy of Medtronic to provide equal employment opportunity (EEO) to all persons regardless of age, color, national origin, citizenship status, physical or mental disability, race, religion, creed, gender, sex, sexual orientation, gender identity and/or expression, genetic information, marital status, status with regard to public assistance, veteran status, or any other characteristic protected by federal, state or local law. In addition, Medtronic will provide reasonable accommodations for qualified individuals with disabilities.

At Medtronic, most positions are posted on our career site for 3-7 days.

Welcome to our new Careers Site!

If you applied before July 22nd, please check your email for a notification from us providing you with instructions and a link to set up your new account and retain access to your current activity. If you do not see an email from us, please feel free to proceed with creating a new account.

We lead global healthcare technology and boldly attack the most challenging health problems facing humanity by searching out and finding solutions.

Our Mission - to alleviate pain, restore health, and extend life - unites a global team of 90,000+ passionate people.

We are engineers at heart- putting ambitious ideas to work to generate real solutions for real people. From the R&D lab, to the factory floor, to the conference room, every one of us experiments, creates, builds, improves and solves. We have the talent, diverse perspectives, and guts to engineer the extraordinary.

We change lives . Each team member, each day, helps to improve and redefine how the world treats the most pressing health conditions, from heart disease to diabetes. Our industry leadership comes from the passion and ingenuity of our people. That's who we are. Working alongside one another, we use science, medicine, and a profound understanding of the human body to build extraordinary technologies that can transform lives.

We build extraordinary solutions as one team . With one Medtronic Mindset defining how we work. Speed and decisiveness run through our DNA. Diverse perspectives inspire our bold answers to any challenge that comes our way. And we deliver results the right way, breakthrough after patient breakthrough.

This life-changing career is yours to engineer . By bringing your ambitious ideas, unique perspective and contributions, you will...

  • Build a better future, amplifying your impact on the causes that matter to you and the world

  • Grow a career reflective of your passion and abilities

  • Connect to a dynamic and inclusive culture that welcomes the challenge of life-long learning

These commitments set our team apart from the rest:

Experiences that put people first . Respect for people is the hallmark of our humanity. It fuels our team to positively impact even a single life. And it means we put our people first at Medtronic as well, creating a culture of belonging and always pushing to get you the career-building resources you need.

Life-transforming technologies . No matter your role, you contribute to technologies that transform lives. What we build empowers patients to live life on their terms.

Better outcomes for our world . Here, it's about more than the bottom line. Our Mission to improve human welfare drives us. We advance healthcare, society, and equity with every design, inside and outside our walls.

Insight-driven care . Fresh viewpoints. Cutting-edge AI, data, and automation. You're shaping the future of healthcare technology and defining the next generation of breakthroughs in care

It is the policy of Medtronic to provide equal employment opportunity (EEO) to all persons regardless of age, color, national origin, citizenship status, physical or mental disability, race, religion, creed, gender, sex, sexual orientation, gender identity and/or expression, genetic information, marital status, status with regard to public assistance, veteran status, or any other characteristic protected by federal, state or local law. In addition, Medtronic will provide reasonable accommodations for qualified individuals with disabilities.

For sales reps and other patient facing field employees, going into a healthcare settingis considered an essential function of the job and we expect our employees to comply with all credentialing requirements at the hospitals or clinics they support.

This employer participates in the federal E-Verify program to confirm the identity and employment authorization of all newly hired employees. For further information about the E-Verify program, please click here (https://www.e-verify.gov/employees) .

For updates on job applications, please go to the candidate login page and sign in to check your application status.

If you need assistance completing your application please email AskHR@medtronic.com

To request removal of your personal information from our systems please email RS.HRCompliance@medtronic.com



Job Detail


Company Overview

Medtronic

Lafayette, CO