Senior Principal Product Security Engineer

Senior Principal Product Security Engineer
Company:

Medtronic


Details of the offer

Careers that Change LivesIn this role, you will jointhe Information Security and Privacy technology group withinthe MedtronicDiabetesOperating Unit (OU). This isanew, powerful operating unitsecuringthe people and product portfolio ofDiabetes. With the Medtronic Mission as our North Star, we will buildand innovateforthe benefit of the customers and patients we serve.?A Day in the LifeTheSenior Principal ProductSecurity Engineer is instrumental in ensuring theprivacy andsecurity of ourDiabetesoperating unit. Reporting directly to the Director ofPrivacy and InformationSecurity, this role spearheads the integration ofprivacy by design andstate-of-the-artsecurity measures,identifiespotential vulnerabilitiesand remediation, and champions initiatives to bolsterprivacy andcyber-resiliency throughout thebusiness. Adeepunderstanding ofprivacy regulation and corresponding security controls, environments that underpin client-facing medical device solutions, anddeveloping driving adoption ofprivacy andsecurity frameworks is essential#MDTDiabetesReferralCampaignKey Responsibilities:Responsibilities may include the following and other duties may be assigned.Product Security Strategy & Continuous Learning-?Engage in continuous professional development to stay updated with the latest cybersecurity trends and threats specific to medical devices and health software products. Contribute to OU and enterprise product security strategy that aligns with industry best practices and regulatoryrequirements.Privacy by Design:collaborate with legal and technical stakeholders toconduct privacy impact assessments, data minimizationrequirements and automations,anduser-centric and secure designs. Tofoster a privacy-conscious culture.Product Security-?Lead efforts to embed security into the product development lifecycle, ensuring that security considerations are integrated from design through deployment. This includesin-house developed technology, licensed technology, consumerdevices, and enterprise security processes /standards.Risk Assessment -?Systematically perform threat modeling, security risk evaluations, and vulnerability assessments to highlight and mitigate potential security threats throughout the product lifecycle.Privacy &Security Architecture- Aid in devising and deploying secureproductarchitectures?and? designs, considering factors such as secure boot, secure communications, data protection, secure updates, secure integration, and access controlsStandards & Testing-Maintainand enforce security standards, policies, and procedures for medical device systems and product development. Oversee security testing activities, including penetration testing, vulnerability scanning, and codereviewsSecurity Awareness- Drive and promote security awareness and training across cross-functional product development teams to foster a security-consciouscultureCompliance- Ensure compliance with industry standards and regulations related tocovered entitiessuch as NIST 801 and HIPAADocumentation?-Maintaindetailed documentation of security best practices, guidance, configurations, design patterns, shared service designs, inventories, incident response plans, security architectures, andreportsMust Have: Minimum RequirementsBachelors degree requiredRequires a University Degree and minimum of 10 years of relevant experience, or advanced degree with a minimum of 8 years of relevant experienceNice to Have5 years ofPrivacy or Securityengineeringexperience in a regulated industryDegree in related engineering or cybersecurity from an accredited institutionAbility to adapt to the fast-evolving cybersecurity landscape and implement proactive strategies.Demonstrated aptitude in identifying challenges and providing innovative solutions.Experience in mentoring and leading junior security engineers, fostering growth within the team.Demonstrated experience in staying updated with evolving regulations in the medical device sector.Industry-recognized certifications such as [CISSP, CSSLP, CISM] are highlydesirableProficiencyin secure coding methodologies and standardsAbout MedtronicTogether, we can change healthcare worldwide. At Medtronic, we push the limits of what technology, therapies and services can do to help alleviate pain, restore health, and extend life.  We challenge ourselves and each other to make tomorrow better than yesterday. It is what makes this an exciting and rewarding place to be.We want to accelerate and advance our ability to create meaningful innovations - but we will only succeed with the right people on our team. Let's work together to address universal healthcare needs and improve patients' lives. Help us shape the future.Physical Job RequirementsThe physical demands described within the Responsibilities section of this job description are representative of those that must be met by an employee to successfully perform the essential functions of this job. Reasonable accommodations may be made to enable individuals with disabilities to perform the essential functions. For Office Roles: While performing the duties of this job, the employee is regularly required to be independently mobile. The employee is also required to interact with a computer, and communicate with peers and co-workers. Contact your manager or local HR to understand the Work Conditions and Physical requirements that may be specific to each role. (ADA-United States of America)A commitment to our employees lives at the core of our values. We recognize their contributions. They share in the success they help to create.? We offer a wide range of benefits, resources, and competitive compensation plans designed to support you at every career and life stage. Learn more about our benefits at http://benefits.medtronic.comThis position is eligible for a short-term incentive plan.? Learn more about Medtronic Incentive Plan (MIP) on page 6 here .The provided base salary range is used nationally (except in certain CA locations).?The rate offered is compliant with federal/local regulations and may vary by experience,?certification/education, market conditions, location, etc.


Source: Eightfold_Ai

Requirements

Senior Principal Product Security Engineer
Company:

Medtronic


Data Analyst - Immediate Start

We are hiring an ambitious Data analyst to join our passionate team at Collective Health in San Francisco, CA. Growing your career as a Full Time Data analys...


From Collective Health - California

Published a month ago

Data Engineer

One of our client is looking for Data Engineer for the location Onsite Oakland, CA Role : Data Engineer Location : Onsite Oakland, CA ( LOCALS PREFERRED ...


From Reqroute,Inc - California

Published a month ago

Network Engineer

NO C2C VISA: USC Experience: 8+ Years Required Skills: Provide support and architectural guidance for Cisco networking environments, primarily focusing...


From Sbc Solutions - California

Published a month ago

Engineer - Urgent Hiring

We are searching for an enthusiastic Engineer to join our high calibre team at Assort Health (hiring founding engineers) in San Francisco, CA. Growing your c...


From Assort Health (Hiring Founding Engineers) - California

Published a month ago

Built at: 2024-05-08T03:07:01.633Z