Principal Product Security Engineer
3 days ago
At Medtronic you can begin a life-long career of exploration and innovation, while helping champion healthcare access and equity for all. You'll lead with purpose, breaking down barriers to innovation in a more connected, compassionate world.
A Day in the LifeWe value what makes you unique. Be a part of a company that thinks differently to solve problems, make progress, and deliver meaningful innovations.The Cardiac and Vascular Group brings all our cardiac and vascular businesses together into one cross-functional, collaborative operating unit to employ the full breadth of our talent, technologies, products, services, and solutions to address the needs of customers and patients across the globe. Cardiac Rhythm Management offers devices and therapies to treat abnormal heart rhythms, as well as cardiac monitoring solutions. Be on the frontlines of the emerging area of medical device cybersecurity as an integral member and technical leader within a team responsible for creating, deploying, and monitoring cybersecurity and information security solutions for Medtronic's medical devices and supporting IT infrastructure. Interact with external and internal cybersecurity researchers to identify and remediate vulnerabilities within Medtronic products and systems. Work directly with R&D teams to ensure all relevant security risks are identified and evaluated, and appropriate and well-balanced solutions are implemented. Develop project security management deliverables for regulatory bodies to comply with standards / guidance documents, and successfully communicate cybersecurity technology to customers, regulatory bodies, and other stakeholders.
Responsibilities may include the following and other duties may be assigned
- Product Security Strategy & Continuous Learning - Stay abreast of emerging cybersecurity threats, technologies, and regulations specific to medical devices and health software. Contribute to OU and enterprise-wide product security strategy and roadmap development.
- Secure Product Development Lifecycle - Drive security integration into all stages of the product lifecycle, from concept and design to postmarket. Work closely with system architects, software leads, and hardware engineers to embed secure design patterns in both embedded and cloud-connected environments.
- Threat Modeling & Risk Assessment - Lead threat modeling sessions, conduct security risk assessments, and identify mitigation strategies in accordance with IEC , ISO 14971, and FDA premarket cybersecurity guidance.
- Security Architecture & Design - Collaborate on the design and implementation of secure architectures, focusing on secure boot, secure communications, data protection, access control, secure software updates, and hardware-software integration.
- Security Testing & Analysis - Support and interpret results from vulnerability scans, penetration tests, and static/dynamic code analysis. Coordinate with internal teams and third-party vendors to ensure timely and appropriate risk mitigation.
- Security Awareness & Mentorship - Promote a culture of security awareness within R&D and provide mentorship to junior engineers. Lead by example through documentation, review participation, and active knowledge sharing.
- Regulatory & Standards Compliance - Ensure alignment with applicable standards (e.g., NIST, IEC , IEC and support security documentation efforts for global regulatory submissions.
- Vendor & Supply Chain Security - Review and assess the cybersecurity posture of third-party suppliers and open-source software components used within product designs.
- Incident Response Support - Provide technical leadership during postmarket security incidents or field issues. Lead root cause investigations, containment strategies, and risk assessments.
- Security Documentation - Maintain comprehensive security documentation, including threat model diagrams, risk assessments, shared service inventories, design patterns, security guidelines, and product security plans/reports.
Required Knowledge and Experience
- Bachelor's or Master's degree in Computer Science, Electrical Engineering, Cybersecurity, or related field.
- 12-16 years of experience in product or embedded security, ideally in the medical device or healthcare technology sector.
- Deep knowledge of product security, secure software development lifecycle (SDLC), cryptography, and secure communication protocols.
- Experience with regulatory standards (FDA, ISO, IEC) and risk management in healthcare.
- Strong track record in threat modeling, vulnerability assessment, and security testing.
- Excellent problem-solving, communication, and collaboration skills.
Physical Job Requirements
The above statements are intended to describe the general nature and level of work being performed by employees assigned to this position, but they are not an exhaustive list of all the required responsibilities and skills of this position.
Medtronic offers a competitive Salary and flexible Benefits Package
A commitment to our employees lives at the core of our values. We recognize their contributions. They share in the success they help to create. We offer a wide range of benefits, resources, and competitive compensation plans designed to support you at every career and life stage.
We lead global healthcare technology and boldly attack the most challenging health problems facing humanity by searching out and finding solutions.
Our Mission — to alleviate pain, restore health, and extend life — unites a global team of 95,000+ passionate people.
We are engineers at heart— putting ambitious ideas to work to generate real solutions for real people. From the R&D lab, to the factory floor, to the conference room, every one of us experiments, creates, builds, improves and solves. We have the talent, diverse perspectives, and guts to engineer the extraordinary.
Learn more about our business, mission, and our commitment to diversity here
-
Software Engineer
7 days ago
Hyderabad, Telangana, India Principal Global Services Full timeResponsibilities Job Purpose Software Engineer is responsible for developing, testing and maintaining the application/s with established processes. With guidance, conduct analysis, elicit requirements, write correct and clean code leveraging best practices, DevOps, testing/debugging, documentation, quality assurance review, implementation and...
-
Software Engineer
3 days ago
Hyderabad, Telangana, India Principal Global Services Full timeResponsibilitiesJob PurposeSoftware Engineer is responsible for developing, testing and maintaining the application/s with established processes. With guidance, conduct analysis, elicit requirements, write correct and clean code leveraging best practices, DevOps, testing/debugging, documentation, quality assurance review, implementation and...
-
Principal AI Application Security Engineer
1 week ago
Hyderabad, Telangana, India Backbase Full time ₹ 12,00,000 - ₹ 36,00,000 per yearkeep millions of users and their banking data safe and secure.No day at Backbase is the same, and even more so for our security engineers. We all know that security and banking need to go hand in hand and with hackers and tech evolving by the day, you'll need to stay on your toes and ahead of the game.Your core responsibility is to ensure the delivery of...
-
Senior Software Engineer
5 days ago
Hyderabad, Telangana, India Principal Global Services Full timeResponsibilities Job Purpose Senior Software Engineer is responsible for developing, testing and maintaining the application/s with established processes by conducting analysis, eliciting requirements, assisting in design, writing correct and clean code leveraging best practices, contributing to DevOps practices, testing/debugging, working on documentation,...
-
Senior Software Engineer
3 days ago
Hyderabad, Telangana, India Principal Global Services Full timeResponsibilitiesJob PurposeSenior Software Engineer is responsible for developing, testing and maintaining the application/s with established processes by conducting analysis, eliciting requirements, assisting in design, writing correct and clean code leveraging best practices, contributing to DevOps practices, testing/debugging, working on documentation,...
-
Principal Security Operations Engineer
4 days ago
Hyderabad, Telangana, India Cubic Corporation Full timeBusiness Unit:Cubic Transportation SystemsCompany Details:When you join Cubic, you become part of a company that creates and delivers technology solutions in transportation to make people's lives easier by simplifying their daily journeys, and defense capabilities to help promote mission success and safety for those who serve their nation. Led by our...
-
Principal Site Reliability Engineer
14 hours ago
Hyderabad, Telangana, India Oracle Full timeOracle is seeking motivated Principal Site Reliability Engineer who thrives in a fast-paced rapidly evolving technology environment. This position requires wide and overall knowledge in Linux administration, AI technologies, software development, cloud computing, networking, cloud security, performance analysis and monitoring to provide the stability,...
-
Principal Application Security Consultant
3 days ago
Hyderabad, Telangana, India Prudent Globaltech Solutions Full timeJob Description:Prudent Technologies and Consulting is seeking an experienced Principal Application Security Engineer to lead our rapidly expanding web application penetration testing services. This senior-level position will play a critical role in advancing our offensive security capabilities, mentoring junior security consultants, and delivering...
-
Principal Software Engineer
16 hours ago
Hyderabad, Telangana, India Microsoft Full timeAs a key member of our team in the role of Principal Software Engineer, you will be instrumental in designing, developing, deploying, and overseeing solutions aimed at protecting end users from cyber threats. Your responsibilities will span across teams, requiring collaboration with partners to forge innovative mobile threat defense solutions. The solutions...
-
Principal Software Engineer(
21 hours ago
Hyderabad, Telangana, India Cloud Angles Digital Transformation Full timeThe OpportunityJoin us as a Principal Software Engineer within our Field Mobile Platform team. Youll be part of a cross-functional group responsible for building, testing, and running platforms that empower field engineers to deliver efficient, compliant, and customer-centric service.Our field workforce depends on a suite of mobile applications to manage...