Sr. Product Security Engineer - Post Market Surveillance

Medtronic Fridley, Minnesota, United States of America Updated 11 September 2026
MedTechPharmaRegulatory AffairsQuality Assuranceheorgdpemafdaiso 13485mdrcro

Job description

We anticipate the application window for this opening will close on - 18 Sep 2026 Careers that change lives start here. Medtronic is a global leader in healthcare technology with a Mission to alleviate pain, restore health, and extend life. Our 95,000 employees work across more than 150 countries to put patients first — developing innovative medical technologies that improve the lives of 72+ million patients each year. Your unique talents will help shape the future of healthcare while building a career grounded in purpose, growth, and impact. A Day in the Life The Neuromodulation and Pelvic Health R&D organizations, bring together a large set of Medtronic’s Neurosciences therapies and their project teams to employ the full breadth of our talent, technologies, products, services, and solutions to address the needs of customers and patients across the globe. These operating units offer devices and therapies to treat chronic pain, movement disorders, overactive bladder, non-obstructive urinary retention, and much more. The Senior Product Security Engineer – Post Market Surveillance leads cybersecurity activities for fielded medical devices and supporting systems. The role owns vulnerability surveillance, field security event assessment, security impact and risk analysis, post-market compliance, security operations support, and issue disposition through closure. Primary Responsibilities Vulnerability, Field Event & Security Impact Management Monitor and assess vulnerability signals, field complaints, anomalous behavior, and suspected security events affecting released products. Determine applicability, exploitability, severity, product impact, and required escalation; coordinate investigation, remediation, and disposition. Partner with Risk Management and Systems Engineering to update Security Risk Analysis, threat models, hazard analyses, and residual-risk assessments. Security Operations & Product Security Assets Maintain visibility of security assets across fielded products, including keys, certificates, credentials, trust anchors, and signing infrastructure. Support secure provisioning, certificate/key distribution, rotation, revocation, and retirement with manufacturing and operations teams. Maintain Defense-in-Depth, Security-by-Design, security requirements, and SBOM expectations throughout the post-market lifecycle. Regulatory, Standards & Customer Compliance Assess evolving FDA, EU MDR, China and other cybersecurity requirements and support fielded-product recertification and remediation. Map cybersecurity standards and best practices into internal processes and represent Product Security in standards and technical forums. Support HCP/customer security and privacy questionnaires, onboarding, and automation of recurring assurance activities. Audit, FCA & CAPA Represent Product Security during regulatory audits, FCA, CAPA, quality reviews, and risk-management boards. Support root-cause analysis, corrective actions, effectiveness verification, and closure. Required Qualifications Bachelor’s degree in related field with 4 years of relevant experience OR masters degree in related field with 2 years of relevant experience (Computer Engineering, Electrical Engineering, Computer Science, Cybersecurity) Extensive experience in product security, cybersecurity, embedded/software systems, or regulated product development. Preferred Qualifications Experience with vulnerability management, CVSS, threat modeling, SRA, SBOM/SCA, incident analysis, and medical-device cybersecurity. Understanding of medical device regulations and standards (e.g., FDA pre- and post-market guidance on cybersecurity for medical device manufacturers, ISO 13485, ISO 81001-5-1). Strong decision-making capabilities, weighing relative costs and benefits to identify the most appropriate solution. High attention to detail with a focus on Good Documentation Practices (GDP). Ability to communicate complex, technical information in a creative and engaging way to diverse audiences, orally and in writing. Excellent prioritization skills, with an aptitude for breaking down work into manageable parts and assessing priority and time required. Demonstrated ability to develop and grow productive, trusting, and open relationships with a wide variety of constituencies. For Baccalaureate degrees earned outside of the United States, a degree that satisfies the requirements of 8 C.F.R. § 214.2(h)(4)(iii)(A) is required. Physical Job Requirements The above statements are intended to describe the general nature and level of work being performed by employees assigned to this position, but they are not an exhaustive list of all the required responsibilities and skills of this position. The physical demands described within the Responsibilities section of this job description are representative of those that must be met by an employee to successfully perform the essential functions of this job. Reasonable accommodations may be made to enable individuals with disabilities to perform the essential functions. For Office Roles: While performing the duties of this job, the employee is regularly required to be independently mobile. The employee is also required to interact with a computer, and communicate with peers and co-workers. Contact your manager or local HR to understand the Work Conditions and Physical requirements that may be specific to each role. U.S. Work Authorization & Sponsorship At Medtronic, we are committed to fostering an environment where employees can thrive and make a meaningful impact. In alignment with our enterprise-wide workforce planning approach, U.S. work authorization sponsorship (H-1B, TN, J, etc.) is offered exclusively for Principal-level roles and above, where specialized expertise aligns with long-term business needs. Roles below the Principal level require candidates to possess unrestricted U.S. work authorization at the time of hire and for the duration of employment. ‌ Recruitment Fraud Alert We are aware of phishing scams targeting job seekers. Please keep the following in mind: Apply only through official Medtronic channels. All legitimate Medtronic recruiting communications come from approved Medtronic platforms and official @medtronic.com email addresses. Medtronic will never ask for payment or sensitive personal information (such as bank account or Social Security details) during early stages of the hiring process. Any such requests are not legitimate. If you receive a suspicious message claiming to be from Medtronic, do not respond, click links, or open attachments. If you have any questions, concerns regarding the authenticity of a communication alleged to ha

Stand out for this role

NoxPharm tailors your CV to this job description by aligning your experience with the role requirements and terminology. Built for pharma & life sciences.

Tailor my CV now — free to try