Sr. Product Security Engineer - Cloud Digital Solutions

Medtronic Fridley, Minnesota, United States of America Updated 11 September 2026
MedTechPharmaRegulatory AffairsQuality Assuranceheorgdpregulatory submissionemafdaiso 13485cro

Job description

We anticipate the application window for this opening will close on - 18 Sep 2026 Careers that change lives start here. Medtronic is a global leader in healthcare technology with a Mission to alleviate pain, restore health, and extend life. Our 95,000 employees work across more than 150 countries to put patients first — developing innovative medical technologies that improve the lives of 72+ million patients each year. Your unique talents will help shape the future of healthcare while building a career grounded in purpose, growth, and impact. A Day in the Life The Neuromodulation and Pelvic Health R&D organizations, bring together a large set of Medtronic’s Neurosciences therapies and their project teams to employ the full breadth of our talent, technologies, products, services, and solutions to address the needs of customers and patients across the globe. These operating units offer devices and therapies to treat chronic pain, movement disorders, overactive bladder, non-obstructive urinary retention, and much more. The Senior Product Security Engineer – Cloud & Digital Solutions leads cybersecurity architecture for Digital Health Platforms, cloud services, web/mobile applications, APIs, remote monitoring, and digital ecosystems supporting connected medical devices. Primary Responsibilities Cloud & Digital Security Architecture Define Security-by-Design and Defense-in-Depth architecture for Digital Health Platforms, cloud-native services, web/mobile applications, APIs, and remote-monitoring solutions. Define security requirements for identity, authentication, authorization, secrets, encryption, data protection, network segmentation, logging, and service-to-service communication. Design secure interfaces between connected medical-device ecosystems and cloud/digital platforms. Threat Modeling & Security Risk Lead threat modeling, Security Risk Analysis, attack-surface analysis, and security requirements definition for cloud and digital solutions. Translate threats into architecture controls, security requirements, verification activities, and risk-control evidence. Maintain SBOM and software/component security requirements across cloud applications, services, containers, APIs, and third-party dependencies. Data, Provisioning & Connected Services Define security requirements for data-at-rest, data-in-transit, transient data, retention, access control, and privacy across digital-health workflows. Design secure identity, provisioning, certificate, credential, and secrets-management strategies for cloud-connected products and services. Support secure eFOTA orchestration, remote monitoring, device-service authentication, telemetry, and secure digital-service integration. Cloud Security Operations, Assurance & Compliance Define cloud security monitoring, logging, vulnerability management, configuration security, and DevSecOps requirements. Develop the application-security assurance roadmap and lead readiness, certification/attestation, and recertification activities for programs such as SOC 2, ISO/IEC 27001, HIPAA compliance, and other applicable security/privacy frameworks . Coordinate control implementation, evidence collection, gap remediation, audit support, and continuous compliance across engineering, IT, quality, privacy, and business stakeholders. Support regulatory submissions and alignment with medical-device cybersecurity, cloud-security, privacy, and digital-health requirements. Required Qualifications Bachelor’s degree in related field with 4 years of relevant experience OR masters degree in related field with 2 years of relevant experience (Computer Engineering, Electrical Engineering, Computer Science, Cybersecurity) Extensive experience in cloud security, application security, digital platforms, cybersecurity architecture, or regulated software development. Preferred Qualifications Strong knowledge of cloud-native security, IAM, APIs, PKI, encryption, secrets management, containers, DevSecOps, logging/monitoring, and data protection. Experience with threat modeling, SRA, SBOM/SCA, Security-by-Design, Defense-in-Depth, and regulated medical-device environments. Understanding of medical device regulations and standards (e.g., FDA pre- and post-market guidance on cybersecurity for medical device manufacturers, ISO 13485, ISO 81001-5-1, ISO 27001, SOC2, HIPPA, HiTRUST). Strong decision-making capabilities, weighing relative costs and benefits to identify the most appropriate solution. High attention to detail with a focus on Good Documentation Practices (GDP). Ability to communicate complex, technical information in a creative and engaging way to diverse audiences, orally and in writing. Excellent prioritization skills, with an aptitude for breaking down work into manageable parts and assessing priority and time required. Demonstrated ability to develop and grow productive, trusting, and open relationships with a wide variety of constituencies. For Baccalaureate degrees earned outside of the United States, a degree that satisfies the requirements of 8 C.F.R. § 214.2(h)(4)(iii)(A) is required. Physical Job Requirements The above statements are intended to describe the general nature and level of work being performed by employees assigned to this position, but they are not an exhaustive list of all the required responsibilities and skills of this position. The physical demands described within the Responsibilities section of this job description are representative of those that must be met by an employee to successfully perform the essential functions of this job. Reasonable accommodations may be made to enable individuals with disabilities to perform the essential functions. For Office Roles: While performing the duties of this job, the employee is regularly required to be independently mobile. The employee is also required to interact with a computer, and communicate with peers and co-workers. Contact your manager or local HR to understand the Work Conditions and Physical requirements that may be specific to each role. U.S. Work Authorization & Sponsorship At Medtronic, we are committed to fostering an environment where employees can thrive and make a meaningful impact. In alignment with our enterprise-wide workforce planning approach, U.S. work authorization sponsorship (H-1B, TN, J, etc.) is offered exclusively for Principal-level roles and above, where specialized expertise aligns with long-term business needs. Roles below the Principal level require candidates to possess unrestricted U.S. work authorization at the time of hire and for the duration of employment. ‌ Recruitment Fraud Alert We are aware of phishing scams targeting job seekers. Please keep the following in mind: Apply only through official Medtronic channels. All legitimate Medtronic recruiting communications come from approve

Stand out for this role

NoxPharm tailors your CV to this job description by aligning your experience with the role requirements and terminology. Built for pharma & life sciences.

Tailor my CV now — free to try