We anticipate the application window for this opening will close on - 28 Apr 2025 At Medtronic you can begin a life-long career of exploration and innovation, while helping champion healthcare access and equity for all. You’ll lead with purpose, breaking down barriers to innovation in a more connected, compassionate world. • *A Day in the Life** We look for leaders who have a clear vision of where we are going and how to get there, bold inclusive thinkers who create new ideas and bring our best solutions forward to benefit our patients, business partners, and customers. Join a Culture of Collaboration and Innovation. The Medtronic Product Security Office (PSO), within the Enterprise Quality organization, provides corporate-level oversight, services, strategy, and collaboration across the Medtronic Operating Units to safeguard medical devices. In this critical role you will act as Senior Product Security Engineer, reporting to the Senior Product Security Manager within the Product Security Office (PSO) in Corporate Quality. This position is responsible for developing an overarching security tool architecture for Security by Design and Vulnerability Vigilance workstreams. We look for leaders who have a clear vision of where we are going and how to get there, bold inclusive thinkers who create new ideas and bring our best solutions forward to benefit our patients, business partners, and customers. • *Position Responsibilities:** + Identify, document, and assess technology, tools, and associated processes in use by the PSO + Develop an appropriate architecture framework in alignment with the key strategic pillars of Security by Design and Vulnerability Vigilance + Lead industry assessment for appropriate tooling/solution selection if necessary + Implement proposed framework to improve PSO visibility, reporting, metrics, and overall maturity in the PSO strategy + Support enterprise quality program for SBOMs (“Software Bill of Materials”) with adherence to industry defined standards such as CycloneDX, SPDX (“Software Package Data Exchange”), VEX (“Vulnerability Exploitability eXchange”), and the evolving needs of the SBOM program. + Support enterprise creation and exchange of SBOMs to meet the needs for both internal teams inside Medtronic and outside partners such as HDOs, regulators, and customers + Apply technical understanding of vulnerability management, security controls/threat modeling, penetration testing/DAST (“Dynamic Application Security Testing”) + Support product developers, security engineers, project managers for technical needs, i.e., artifact generation, build process steps, validation steps + Work with outside vendors, and support product teams that work with vendors + Strengthen relationships with critical Engineering, Quality, Regulatory Affairs, Global Security office, Global IT, and Leadership stakeholders in Operating Units. • *Specific responsibilities include:** + Strong familiarization with SBOM authoring, i.e., making an SBOM (generation, augmentation, enrichment, signing, etc.) + Experience with DevSecOps, SDLC, Scrum framework, Agile/waterfall methodology, and related software design principles to support SBOM efforts in premarket products + Advise on best practices for CI/CD security processes across relevant platforms such as Jenkins, GitHub, GitLab, Bitbucket, and Azure DevOps + Experience with SCA (“Software Composition Analysis”), binary analysis, SAST (“Static Application Security Testing”), limited reverse engineering skills to support SBOM efforts in post market/legacy products + Understand principles of risk management between supplier and customer, as well as Medtronic’s position in both roles + Familiarity with FOSS (“Free and Open-Source Software”) ecosystems, package management, and differences with proprietary/closed-source software distribution + Must have experience and knowledge working with regulated medical devices and cybersecurity requirements. + Leveraging the Product Security strategy and roadmap to drive maturity. + Remain informed on Regulatory requirements for Product Security. + Create energy and enthusiasm at all levels of the product security organization. + Enable strong partnerships across the organization to drive best-in-class product security mechanisms. + Continuously anticipate and be prepared for audits. + Proactively engage with third party stakeholders such as researchers, industry peers, regulators, and potentially Medtronic customers. + Benchmark with external organizations for best practices on product security tooling architecture. + Contribute to company standards and policies related to product security risks. + Market and communicate program vision to project teams, key business stakeholders, and executive leadership. + Provide detailed functional knowledge and maintain insight to current industry best practices and how they can be applied to Medtronic. + Works with little direction towards predetermined long-range goals and objectives. + Establishes streamlined processes and structures that accelerate change initiatives; plays a leadership role in change efforts. + Escalate security and privacy issues as appropriate when discovered. • *Must Have: Minimum Requirements:** _To be considered for this role, please ensure the minimum requirements are evident on your resume._ + Bachelors degree required + Minimum of 4+ years of cybersecurity and/or secure software engineering experience or advanced degree with 2+ years of cybersecurity and/or secure software engineering experience. • *Nice to Have:** + Experience in Product Security and/or Cyber Security, with preference given to those with relevant product security or engineering experience. + Excellent written and verbal communication skills including demonstrated influence of stakeholders across an organization. + Occasional after-hours availability to accommodate different regional and global partners. + Experience working in a regulated environment and/or a formal quality system. + Some technical and troubleshooting skills. + Strong capability to research and evaluate emerging technologies. + Interest in novel applications of technology. + Strong in interpersonal communication and demonstrate a collaborative work style. + Comfortable working in an ambiguous environment. + Innovative thinker; ability to think outside of the current norms and processes. + Independent self-starter. + Experience working as an engineer or developer for embedded device hardware or firmware, mobile applications, web applications, or desktop applications. + Understanding of the security development process and product development process. + Ability to be creative to think “outside the box”. + Experience facilitating working sessions. + Knowledge in risk management and assessment methodologies, security frameworks and relevant global regulations. + Demonstrated ability to be flexible and take a proactive approach to managing change. + Expected Travel: Up to 20%. • *Physical Job Requirements** The above statements are intended to describe the general nature and level of work being performed by employees assigned to this position, but they are not an exhaustive list of all the required responsibilities and skills of this position. The physical demands described within the Responsibilities section of this job description are representative of those that must be met by an employee to successfully perform the essential functions of this job. Reasonable accommodations may be made to enable individuals with disabilities to perform the essential functions. For Office Roles: While performing the duties of this job, the employee is regularly required to be independently mobile. The employee is also required to interact with a computer, and communicate with peers and co-workers. Contact your manager or local HR to understand the Work Conditions and Physical requirements that may be specific to each role. • *Benefits & Compensation** • *Medtronic offers a competitive Salary and flexible Benefits Package** A commitment to our employees lives at the core of our values. We recognize their contributions. They share in the success they help to create. We offer a wide range of benefits, resources, and competitive compensation plans designed to support you at every career and life stage. Salary ranges for U.S (excl. PR) locations (USD):$123,200.00 - $184,800.00 This position is eligible for a short-term incentive called the Medtronic Incentive Plan (MIP). The base salary range is applicable across the United States, excluding Puerto Rico and specific locations in California. The offered rate complies with federal and local regulations and may vary based on factors such as experience, certification/education, market conditions, and location. Compensation and benefits information pertains solely to candidates hired within the United States (local market compensation and benefits will apply for others). The following benefits and additional compensation are available to those regular employees who work 20+ hours per week: Health, Dental and vision insurance, Health Savings Account, Healthcare Flexible Spending Account, Life insurance, Long-term disability leave, Dependent daycare spending account, Tuition assistance/reimbursement, and Simple Steps (global well-being program). The following benefits and additional compensation are available to all regular employees: Incentive plans, 401(k) plan plus employer contribution and match, Short-term disability, Paid time off, Paid holidays, Employee Stock Purchase Plan, Employee Assistance Program, Non-qualified Retirement Plan Supplement (subject to IRS earning minimums), and Capital Accumulation Plan (available to Vice Presidents and above, or subject to IRS earning minimums). Regular employees are those who are not temporary, such as interns. Temporary employees are eligible for paid sick time, as required under applicable state law, and the Employee Stock Purchase Plan. Please note some of the above benefits may not apply to workers in Puerto Rico. Further details are available at the link below: Medtronic benefits and compensation plans (https://www3.benefitsolver.com/benefits/BenefitSolverView?page\_name=signon&co\_num=30601&co\_affid=medtronic) • *About Medtronic** We lead global healthcare technology and boldly attack the most challenging health problems facing humanity by searching out and finding solutions. Our Mission — to alleviate pain, restore health, and extend life — unites a global team of 95,000+ passionate people. We are engineers at heart— putting ambitious ideas to work to generate real solutions for real people. From the R&D lab, to the factory floor, to the conference room, every one of us experiments, creates, builds, improves and solves. We have the talent, diverse perspectives, and guts to engineer the extraordinary. Learn more about our business, mission, and our commitment to diversity here (http://www.medtronic.com) . It is the policy of Medtronic to provide equal employment opportunity (EEO) to all persons regardless of age, color, national origin, citizenship status, physical or mental disability, race, religion, creed, gender, sex, sexual orientation, gender identity and/or expression, genetic information, marital status, status with regard to public assistance, veteran status, or any other characteristic protected by federal, state or local law. In addition, Medtronic will provide reasonable accommodations for qualified individuals with disabilities. If you are applying to perform work for Medtronic, Inc. (“Medtronic”) in any position which will involve performing at least two (2) hours of work on average each week within the unincorporated areas of Los Angeles County, you can find here (https://www.medtronic.com/content/dam/medtronic-wide/public/united-states/employee-support-services/careers/la-county-legal-notice.pdf) a list of all material job duties of the specific job position which Medtronic reasonably believes that criminal history may have a direct, adverse and negative relationship potentially resulting in the withdrawal of a conditional offer of employment. Medtronic will consider for employment qualified job applicants with arrest or conviction records in accordance with the Los Angeles County Fair Chance Ordinance for Employers and the California Fair Chance Act. We lead global healthcare technology and boldly attack the most challenging health problems facing humanity by searching out and finding solutions. Our Mission — to alleviate pain, restore health, and extend life — unites a global team of 95,000+ passionate people. We are engineers at heart— putting ambitious ideas to work to generate real solutions for real people. From the R&D lab, to the factory floor, to the conference room, every one of us experiments, creates, builds, improves and solves. We have the talent, diverse perspectives, and guts to engineer the extraordinary. • *We change lives** . Each team member, each day, helps to improve and redefine how the world treats the most pressing health conditions, from heart disease to diabetes. Our industry leadership comes from the passion and ingenuity of our people. That’s who we are. Working alongside one another, we use science, medicine, and a profound understanding of the human body to build extraordinary technologies that can transform lives. • *We build extraordinary solutions as one team** . With one Medtronic Mindset defining how we work. Speed and decisiveness run through our DNA. Diverse perspectives inspire our bold answers to any challenge that comes our way. And we deliver results the right way, breakthrough after patient breakthrough. • *This life-changing career is yours to engineer** . By bringing your ambitious ideas, unique perspective and contributions, you will… + **Build** a better future, amplifying your impact on the causes that matter to you and the world + **Grow** a career reflective of your passion and abilities + **Connect** to a dynamic and inclusive culture that welcomes the challenge of life-long learning These commitments set our team apart from the rest: • *Experiences that put people first** . Respect for people is the hallmark of our humanity. It fuels our team to positively impact even a single life. And it means we put our people first at Medtronic as well, creating a culture of belonging and always pushing to get you the career-building resources you need. • *Life-transforming technologies** . No matter your role, you contribute to technologies that transform lives. What we build empowers patients to live life on their terms. • *Better outcomes for our world** . Here, it’s about more than the bottom line. Our Mission to improve human welfare drives us. We advance healthcare, society, and equity with every design, inside and outside our walls. • *Insight-driven care** . Fresh viewpoints. Cutting-edge AI, data, and automation. You're shaping the future of healthcare technology and defining the next generation of breakthroughs in care It is the policy of Medtronic to provide equal employment opportunity (EEO) to all persons regardless of age, color, national origin, citizenship status, physical or mental disability, race, religion, creed, gender, sex, sexual orientation, gender identity and/or expression, genetic information, marital status, status with regard to public assistance, veteran status, or any other characteristic protected by federal, state or local law. In addition, Medtronic will provide reasonable accommodations for qualified individuals with disabilities. For sales reps and other patient facing field employees, going into a healthcare setting is considered an essential function of the job and we expect our employees to comply with all credentialing requirements at the hospitals or clinics they support. This employer participates in the federal E-Verify program to confirm the identity and employment authorization of all newly hired employees. For further information about the E-Verify program, please click here (https://www.e-verify.gov/employees) . For updates on job applications, please go to the candidate login page and sign in to check your application status. If you need assistance completing your application please email AskHR@medtronic.com To request removal of your personal information from our systems please email RS.HRCompliance@medtronic.com We anticipate the application window for this opening will close on - 28 Apr 2025 At Medtronic you can begin a life-long career of exploration and innovation, while helping champion healthcare access and equity for all. You’ll lead with purpose, breaking down barriers to innovation in a more connected, compassionate world. • *A Day in the Life** We look for leaders who have a clear vision of where we are going and how to get there, bold inclusive thinkers who create new ideas and bring our best solutions forward to benefit our patients, business partners, and customers. Join a Culture of Collaboration and Innovation. The Medtronic Product Security Office (PSO), within the Enterprise Quality organization, provides corporate-level oversight, services, strategy, and collaboration across the Medtronic Operating Units to safeguard medical devices. In this critical role you will act as Senior Product Security Engineer, reporting to the Senior Product Security Manager within the Product Security Office (PSO) in Corporate Quality. This position is responsible for developing an overarching security tool architecture for Security by Design and Vulnerability Vigilance workstreams. We look for leaders who have a clear vision of where we are going and how to get there, bold inclusive thinkers who create new ideas and bring our best solutions forward to benefit our patients, business partners, and customers. • *Position Responsibilities:** + Identify, document, and assess technology, tools, and associated processes in use by the PSO + Develop an appropriate architecture framework in alignment with the key strategic pillars of Security by Design and Vulnerability Vigilance + Lead industry assessment for appropriate tooling/solution selection if necessary + Implement proposed framework to improve PSO visibility, reporting, metrics, and overall maturity in the PSO strategy + Support enterprise quality program for SBOMs (“Software Bill of Materials”) with adherence to industry defined standards such as CycloneDX, SPDX (“Software Package Data Exchange”), VEX (“Vulnerability Exploitability eXchange”), and the evolving needs of the SBOM program. + Support enterprise creation and exchange of SBOMs to meet the needs for both internal teams inside Medtronic and outside partners such as HDOs, regulators, and customers + Apply technical understanding of vulnerability management, security controls/threat modeling, penetration testing/DAST (“Dynamic Application Security Testing”) + Support product developers, security engineers, project managers for technical needs, i.e., artifact generation, build process steps, validation steps + Work with outside vendors, and support product teams that work with vendors + Strengthen relationships with critical Engineering, Quality, Regulatory Affairs, Global Security office, Global IT, and Leadership stakeholders in Operating Units. • *Specific responsibilities include:** + Strong familiarization with SBOM authoring, i.e., making an SBOM (generation, augmentation, enrichment, signing, etc.) + Experience with DevSecOps, SDLC, Scrum framework, Agile/waterfall methodology, and related software design principles to support SBOM efforts in premarket products + Advise on best practices for CI/CD security processes across relevant platforms such as Jenkins, GitHub, GitLab, Bitbucket, and Azure DevOps + Experience with SCA (“Software Composition Analysis”), binary analysis, SAST (“Static Application Security Testing”), limited reverse engineering skills to support SBOM efforts in post market/legacy products + Understand principles of risk management between supplier and customer, as well as Medtronic’s position in both roles + Familiarity with FOSS (“Free and Open-Source Software”) ecosystems, package management, and differences with proprietary/closed-source software distribution + Must have experience and knowledge working with regulated medical devices and cybersecurity requirements. + Leveraging the Product Security strategy and roadmap to drive maturity. + Remain informed on Regulatory requirements for Product Security. + Create energy and enthusiasm at all levels of the product security organization. + Enable strong partnerships across the organization to drive best-in-class product security mechanisms. + Continuously anticipate and be prepared for audits. + Proactively engage with third party stakeholders such as researchers, industry peers, regulators, and potentially Medtronic customers. + Benchmark with external organizations for best practices on product security tooling architecture. + Contribute to company standards and policies related to product security risks. + Market and communicate program vision to project teams, key business stakeholders, and executive leadership. + Provide detailed functional knowledge and maintain insight to current industry best practices and how they can be applied to Medtronic. + Works with little direction towards predetermined long-range goals and objectives. + Establishes streamlined processes and structures that accelerate change initiatives; plays a leadership role in change efforts. + Escalate security and privacy issues as appropriate when discovered. • *Must Have: Minimum Requirements:** _To be considered for this role, please ensure the minimum requirements are evident on your resume._ + Bachelors degree required + Minimum of 4+ years of cybersecurity and/or secure software engineering experience or advanced degree with 2+ years of cybersecurity and/or secure software engineering experience. • *Nice to Have:** + Experience in Product Security and/or Cyber Security, with preference given to those with relevant product security or engineering experience. + Excellent written and verbal communication skills including demonstrated influence of stakeholders across an organization. + Occasional after-hours availability to accommodate different regional and global partners. + Experience working in a regulated environment and/or a formal quality system. + Some technical and troubleshooting skills. + Strong capability to research and evaluate emerging technologies. + Interest in novel applications of technology. + Strong in interpersonal communication and demonstrate a collaborative work style. + Comfortable working in an ambiguous environment. + Innovative thinker; ability to think outside of the current norms and processes. + Independent self-starter. + Experience working as an engineer or developer for embedded device hardware or firmware, mobile applications, web applications, or desktop applications. + Understanding of the security development process and product development process. + Ability to be creative to think “outside the box”. + Experience facilitating working sessions. + Knowledge in risk management and assessment methodologies, security frameworks and relevant global regulations. + Demonstrated ability to be flexible and take a proactive approach to managing change. + Expected Travel: Up to 20%. • *Physical Job Requirements** The above statements are intended to describe the general nature and level of work being performed by employees assigned to this position, but they are not an exhaustive list of all the required responsibilities and skills of this position. The physical demands described within the Responsibilities section of this job description are representative of those that must be met by an employee to successfully perform the essential functions of this job. Reasonable accommodations may be made to enable individuals with disabilities to perform the essential functions. For Office Roles: While performing the duties of this job, the employee is regularly required to be independently mobile. The employee is also required to interact with a computer, and communicate with peers and co-workers. Contact your manager or local HR to understand the Work Conditions and Physical requirements that may be specific to each role. • *Benefits & Compensation** • *Medtronic offers a competitive Salary and flexible Benefits Package** A commitment to our employees lives at the core of our values. We recognize their contributions. They share in the success they help to create. We offer a wide range of benefits, resources, and competitive compensation plans designed to support you at every career and life stage. Salary ranges for U.S (excl. PR) locations (USD):$123,200.00 - $184,800.00 This position is eligible for a short-term incentive called the Medtronic Incentive Plan (MIP). The base salary range is applicable across the United States, excluding Puerto Rico and specific locations in California. The offered rate complies with federal and local regulations and may vary based on factors such as experience, certification/education, market conditions, and location. Compensation and benefits information pertains solely to candidates hired within the United States (local market compensation and benefits will apply for others). The following benefits and additional compensation are available to those regular employees who work 20+ hours per week: Health, Dental and vision insurance, Health Savings Account, Healthcare Flexible Spending Account, Life insurance, Long-term disability leave, Dependent daycare spending account, Tuition assistance/reimbursement, and Simple Steps (global well-being program). The following benefits and additional compensation are available to all regular employees: Incentive plans, 401(k) plan plus employer contribution and match, Short-term disability, Paid time off, Paid holidays, Employee Stock Purchase Plan, Employee Assistance Program, Non-qualified Retirement Plan Supplement (subject to IRS earning minimums), and Capital Accumulation Plan (available to Vice Presidents and above, or subject to IRS earning minimums). Regular employees are those who are not temporary, such as interns. Temporary employees are eligible for paid sick time, as required under applicable state law, and the Employee Stock Purchase Plan. Please note some of the above benefits may not apply to workers in Puerto Rico. Further details are available at the link below: Medtronic benefits and compensation plans (https://www3.benefitsolver.com/benefits/BenefitSolverView?page\_name=signon&co\_num=30601&co\_affid=medtronic) • *About Medtronic** We lead global healthcare technology and boldly attack the most challenging health problems facing humanity by searching out and finding solutions. Our Mission — to alleviate pain, restore health, and extend life — unites a global team of 95,000+ passionate people. We are engineers at heart— putting ambitious ideas to work to generate real solutions for real people. From the R&D lab, to the factory floor, to the conference room, every one of us experiments, creates, builds, improves and solves. We have the talent, diverse perspectives, and guts to engineer the extraordinary. Learn more about our business, mission, and our commitment to diversity here (http://www.medtronic.com) . It is the policy of Medtronic to provide equal employment opportunity (EEO) to all persons regardless of age, color, national origin, citizenship status, physical or mental disability, race, religion, creed, gender, sex, sexual orientation, gender identity and/or expression, genetic information, marital status, status with regard to public assistance, veteran status, or any other characteristic protected by federal, state or local law. In addition, Medtronic will provide reasonable accommodations for qualified individuals with disabilities. If you are applying to perform work for Medtronic, Inc. (“Medtronic”) in any position which will involve performing at least two (2) hours of work on average each week within the unincorporated areas of Los Angeles County, you can find here (https://www.medtronic.com/content/dam/medtronic-wide/public/united-states/employee-support-services/careers/la-county-legal-notice.pdf) a list of all material job duties of the specific job position which Medtronic reasonably believes that criminal history may have a direct, adverse and negative relationship potentially resulting in the withdrawal of a conditional offer of employment. Medtronic will consider for employment qualified job applicants with arrest or conviction records in accordance with the Los Angeles County Fair Chance Ordinance for Employers and the California Fair Chance Act. We lead global healthcare technology and boldly attack the most challenging health problems facing humanity by searching out and finding solutions. Our Mission — to alleviate pain, restore health, and extend life — unites a global team of 95,000+ passionate people. We are engineers at heart— putting ambitious ideas to work to generate real solutions for real people. From the R&D lab, to the factory floor, to the conference room, every one of us experiments, creates, builds, improves and solves. We have the talent, diverse perspectives, and guts to engineer the extraordinary. • *We change lives** . Each team member, each day, helps to improve and redefine how the world treats the most pressing health conditions, from heart disease to diabetes. Our industry leadership comes from the passion and ingenuity of our people. That’s who we are. Working alongside one another, we use science, medicine, and a profound understanding of the human body to build extraordinary technologies that can transform lives. • *We build extraordinary solutions as one team** . With one Medtronic Mindset defining how we work. Speed and decisiveness run through our DNA. Diverse perspectives inspire our bold answers to any challenge that comes our way. And we deliver results the right way, breakthrough after patient breakthrough. • *This life-changing career is yours to engineer** . By bringing your ambitious ideas, unique perspective and contributions, you will… + **Build** a better future, amplifying your impact on the causes that matter to you and the world + **Grow** a career reflective of your passion and abilities + **Connect** to a dynamic and inclusive culture that welcomes the challenge of life-long learning These commitments set our team apart from the rest: • *Experiences that put people first** . Respect for people is the hallmark of our humanity. It fuels our team to positively impact even a single life. And it means we put our people first at Medtronic as well, creating a culture of belonging and always pushing to get you the career-building resources you need. • *Life-transforming technologies** . No matter your role, you contribute to technologies that transform lives. What we build empowers patients to live life on their terms. • *Better outcomes for our world** . Here, it’s about more than the bottom line. Our Mission to improve human welfare drives us. We advance healthcare, society, and equity with every design, inside and outside our walls. • *Insight-driven care** . Fresh viewpoints. Cutting-edge AI, data, and automation. You're shaping the future of healthcare technology and defining the next generation of breakthroughs in care It is the policy of Medtronic to provide equal employment opportunity (EEO) to all persons regardless of age, color, national origin, citizenship status, physical or mental disability, race, religion, creed, gender, sex, sexual orientation, gender identity and/or expression, genetic information, marital status, status with regard to public assistance, veteran status, or any other characteristic protected by federal, state or local law. In addition, Medtronic will provide reasonable accommodations for qualified individuals with disabilities. For sales reps and other patient facing field employees, going into a healthcare setting is considered an essential function of the job and we expect our employees to comply with all credentialing requirements at the hospitals or clinics they support. This employer participates in the federal E-Verify program to confirm the identity and employment authorization of all newly hired employees. For further information about the E-Verify program, please click here (https://www.e-verify.gov/employees) . For updates on job applications, please go to the candidate login page and sign in to check your application status. If you need assistance completing your application please email AskHR@medtronic.com To request removal of your personal information from our systems please email RS.HRCompliance@medtronic.com
Job Type
Fulltime role
Skills required
CI/CD, Jenkins, GitHub, Azure
Location
Mounds View, Minnesota
Salary
$29.45 - $46.85
Date Posted
April 20, 2025
The Senior Product Security Engineer at Medtronic will develop a security tool architecture to enhance product security for medical devices. This role involves collaboration across teams to implement security best practices and ensure compliance with industry standards.