Principal Product Security Engineer
MedTechPharmaRegulatory AffairsQuality Assurancesaspythonregulatory submissionemafdacro
Job description
Careers that change lives start here. Medtronic is a global leader in healthcare technology with a Mission to alleviate pain, restore health, and extend life. Our 95,000 employees work across more than 150 countries to put patients first — developing innovative medical technologies that improve the lives of 72+ million patients each year. Your unique talents will help shape the future of healthcare while building a career grounded in purpose, growth, and impact. A Day in the Life Job Description Medtronic At Medtronic, we value what makes you unique. Be part of a company that thinks differently to solve problems, make progress, and deliver meaningful innovations. Our Purpose At Medtronic Patient Care Systems (PCS), we power the digital heartbeat behind life-saving cardiac therapies. We build the connected ecosystem that enables clinicians to monitor, manage, and protect millions of patients living with implantable cardiac devices around the world. From secure device connectivity and real-time data platforms to intelligent clinical tools and patient-facing experiences, PCS transforms complex cardiac data into clarity — helping physicians make faster decisions, improving outcomes, and giving patients greater confidence in their care. Our work ensures that life-saving therapies are not only delivered securely, safely and reliably, but continuously improved through innovation, insight, and global scale. If you want to build technology that truly matters — join us. Together, we are shaping the future of connected cardiac care and changing lives every single day Come for a job, stay for a career! A Day in The Life Of: As a Principal Product Security Engineer, Mobile Applications , you will serve as a technical leader helping software teams build secure mobile applications and connected digital health solutions that support life-changing medical technologies. You will work closely with software engineers, architects, quality, regulatory, and clinical partners to embed security across the software development lifecycle. This role is ideal for someone who enjoys solving complex technical problems, influencing engineering direction, mentoring others, and translating security and regulatory requirements into practical, risk-based solutions. You will help ensure products are secure by design while balancing patient safety, usability, regulatory expectations, and engineering efficiency. In this role, no two days are the same. You may be: Leading threat models and cybersecurity risk assessments for new mobile applications and connected software systems Reviewing application and system architecture and recommending security controls Helping teams interpret results from security testing tools such as SAST, SCA, IAST, and DAST Supporting regulatory submissions and responses to cybersecurity questions from regulators Leading vulnerability investigations, remediation planning, and postmarket security activities Driving improvements in security tooling, automation, and engineering processes Mentoring Product Security Engineers and influencing secure development practices across teams You will support multiple software development programs at once and serve as a trusted security leader throughout the product lifecycle, from concept through release and post market support. Application and Product Security Serve as a lead Product Security partner for engineering teams developing mobile apps, Software as a Medical Device, APIs, and cloud-connected software ecosystems Lead secure design and architecture reviews Advise on authentication, authorization, secure communications, API security, and application resilience Guide teams on mobile security controls such as secure storage, certificate validation, runtime protections, and application hardening Translate technical findings into practical, risk-based recommendations developers can act on Risk Assessment and Lifecycle Security Lead threat modeling, cybersecurity risk assessments, and vulnerability analysis Define security requirements and support secure design decisions across the product lifecycle Review penetration testing results and guide remediation efforts Help ensure compliance with FDA guidance, IEC 81001-5-1, and evolving global cybersecurity standards and regulations Regulatory and Compliance Support Develop and maintain cybersecurity documentation for regulatory submissions, audits, and lifecycle activities, including: Threat models Security risk assessments Security test plans and reports Software Bills of Materials Security architecture documentation Vulnerability assessments and dispositions Support responses to regulatory questions, customer security assessments, inspections, and audits Incident Response and Continuous Improvement Support Product Security Incident Response, Coordinated Vulnerability Disclosure, and postmarket vulnerability investigations Assess exploitability, product impact, and remediation options to support risk-based decision making Improve security workflows through automation, tooling, and process enhancements Share knowledge, mentor less experienced engineers, and help teams strengthen secure software development practices Key Skills & Experience Application Security or Product Security experience Mobile application security, including iOS, Android, .NET MAUI, or Xamarin Secure Software Development Lifecycle API security OWASP Top 10 and OWASP MASVS Threat modeling SAST, SCA, IAST, DAST, and SBOM analysis PKI, JWT, TLS, and secure communications Python or PowerShell Cloud-connected applications Understanding of FDA cybersecurity guidance and IEC 81001-5-1 Experience in medical device cybersecurity, PSIRT, or coordinated vulnerability disclosure Demonstrated ability to lead complex cross-functional cybersecurity activities, influence technical direction, and mentor other engineers Minimum Qualifications Bachelor’s degree (Level 8 NFQ) in Computer Engineering, Software Engineering, Computer Science or related technical discipline. 7+ years of cybersecurity or related technical experience, or an advanced degree with 5+ years of relevant experience For degrees earned outside the United States, a degree that satisfies the requirements of 8 C.F.R. 214.2(h)(4)(iii)(A) Physical Job Requirements The above statements are intended to describe
Stand out for this role
NoxPharm tailors your CV to this job description by aligning your experience with the role requirements and terminology. Built for pharma & life sciences.
Tailor my CV now — free to trySimilar MedTech jobs
Custom Software Developer - RDT Pharma R&D
Roche — 2 Locations
Supply Planner
Stryker — Salt Lake City, Utah
Associate Area Manager or Area Manager (Albuquerque, NM) - Johnson & Johnson MedTech, Heart Recoverych – Heart Recovery
Johnson & Johnson — 2 Locations
[MedTech] メドテック エデュケーション プロフェッショナルエデュケーション EP&NV エレクトロフィジオロジー スタッフ
Johnson & Johnson — Chiyoda, Tokyo, Japan
Supply Chain Executive (Diagnostics) - Glasgow
Abbott — United Kingdom-Glasgow
Medical Representative (ETC - Nutrition) - Hai Phong
Abbott — Vietnam - Hanoi