×
Register Here to Apply for Jobs or Post Jobs. X

Sr. Product Security Engineer Embedded​/IoT

Job in Minneapolis, Hennepin County, Minnesota, 55400, USA
Listing for: Medtronic
Full Time position
Listed on 2026-03-06
Job specializations:
  • Engineering
    Cybersecurity, Systems Engineer
  • IT/Tech
    Cybersecurity, Systems Engineer
Salary/Wage Range or Industry Benchmark: 80000 - 100000 USD Yearly USD 80000.00 100000.00 YEAR
Job Description & How to Apply Below
Position: Sr. Product Security Engineer - (Embedded/IoT)

We anticipate the application window for this opening will close on - 23 Mar 2026.

At Medtronic you can begin a life‑long career of exploration and innovation, while helping champion healthcare access and equity for all. You’ll lead with purpose, breaking down barriers to innovation in a more connected, compassionate world.

A Day in the Life

Onsite

We’re working onsite 4 days a week to drive performance, foster an environment of belonging, and collaborate to inspire as we engineer the extraordinary.

At Medtronic, we’re driven by our Mission to alleviate pain, restore health, and extend life for millions of people around the world through innovative biomedical devices and connected health solutions. As our products become increasingly connected, securing the medical device ecosystem at the product and system level is critical to ensuring patient safety and product integrity. The Senior Product Security Engineer will play a key role in securing connected and embedded medical devices across the full product lifecycle.

This role is focused on device/product security engineering (not enterprise IT security) and partners closely with R&D, software, systems, and quality teams to design and implement robust, scalable security controls.

The ideal candidate brings hands‑on experience securing embedded or IoT products in regulated environments
, with strong depth in threat modeling, secure architecture, cryptography, and device‑level risk management.

Key Responsibilities

Product Security Engineering – Embed security requirements into the medical device development lifecycle, partnering with R&D and systems teams from architecture through release.

Threat Modeling & Risk Assessment – Perform system‑level threat modeling (e.g., STRIDE or similar), attack surface analysis, and vulnerability assessments for connected and embedded medical devices.

Secure Architecture – Support and review implementation of device security capabilities such as:

  • Secure boot and root of trust
  • Secure firmware/software update mechanisms
  • Device identity and authentication
  • Secure communications and protocol hardening
  • Data protection at rest and in transit
  • Key management and Hardware Security Module (HSM) concepts

Cryptography & Post‑Quantum Readiness – Apply modern cryptographic principles and support forward‑looking strategies including quantum‑resistant approaches where applicable.

Secure SDLC Integration – Partner with agile development teams to embed security into design reviews, code reviews, CI/CD pipelines, and verification activities.

Verification & Validation – Define and support security V&V activities including penetration testing, static/dynamic analysis, fuzz testing, and vulnerability management.

Standards & Compliance – Ensure alignment with medical device cybersecurity expectations including:

  • FDA premarket cybersecurity guidance
  • IEC 81001‑5‑1
  • ISO 14971
  • NIST frameworks
  • Relevant Medtronic quality processes

Incident & Vulnerability Management – Support coordinated vulnerability disclosure, post‑market monitoring, and security issue response for released products.

Cross‑Functional Partnership – Work closely with R&D, systems, software, quality, and regulatory teams to drive secure product development.

Industry Awareness – Maintain awareness of evolving threats, healthcare cybersecurity trends, and regulatory expectations for connected medical devices.

Minimum Requirements
  • Bachelor’s degree in Computer Science, Computer Engineering, Electrical Engineering, or related technical field and 4+ years of experience in:
    • Embedded/device security
    • IoT security
    • Product security engineering
    • OR advanced degree with 2+ years of relevant experience
To Be Successful in This Role

Device/Product Security Depth – Demonstrated hands‑on experience securing embedded or connected products (medical device experience strongly preferred).

Threat Modeling Expertise – Practical experience performing system or device‑level threat modeling and risk assessments.

Embedded/IoT Security Knowledge – Strong understanding of:

  • Embedded systems
  • Firmware/software interactions
  • Device communications
  • Hardware‑software security boundaries

Cryptography Fundamentals – Working knowledge of:

  • Modern…
To View & Apply for jobs on this site that accept applications from your location or country, tap the button below to make a Search.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
 
 
 
Search for further Jobs Here:
(Try combinations for better Results! Or enter less keywords for broader Results)
Location
Increase/decrease your Search Radius (miles)

Job Posting Language
Employment Category
Education (minimum level)
Filters
Education Level
Experience Level (years)
Posted in last:
Salary