Principal Product Security Engineer
IND-TS Hyderabad Nanakramguda
Medtronic
Medtronic ist ein weltweiter Marktführer in Gesundheitstechnologie und den damit verbundenen Dienstleistungen und Lösungen. Wir arbeiten mit unseren Partnern zusammen, um gemeinsam den gewaltigen Herausforderungen des Gesundheitswesens zu...At Medtronic you can begin a life-long career of exploration and innovation, while helping champion healthcare access and equity for all. You’ll lead with purpose, breaking down barriers to innovation in a more connected, compassionate world.
A Day in the LifeBe on the frontlines of the emerging area of medical device cybersecurity as an integral member and technical leader within a team responsible for creating, deploying, and monitoring cybersecurity and information security solutions for Medtronic’s medical devices and supporting IT infrastructure. Interact with external and internal cybersecurity researchers to identify and remediate vulnerabilities within Medtronic products and systems. Work directly with R&D teams to ensure all relevant security risks are identified and evaluated, and appropriate and well-balanced solutions are implemented. Develop project security management deliverables for regulatory bodies to comply with standards / guidance documents, and successfully communicate cybersecurity technology to customers, regulatory bodies, and other stakeholders.Responsibilities may include the following and other duties may be assigned
- Lead and perform product and device-oriented cybersecurity-related activities ranging from incident response to vulnerability assessments and mitigation implementation.
- Develop and perform product-level intrusion detection activities.
- Lead product risk assessments in conjunction with product R&D teams and develop and recommend specific security controls for product/system wide security needs.
- Participate in the creation and testing of product security-related requirements and processes.
- Manage security-related deliverables for regulatory bodies, ensuring compliance with key standards / guidance documents.
- Evaluate and test security risks on programs across the entire development lifecycle, including market-released product.
- Support emerging cybersecurity certification initiatives.
- Maintain and update security documentation.
- Create and maintain threat models using STRIDE.
Required Knowledge and Experience
- An undergraduate (Bachelors) or graduate degree in computer science, computer engineering, electrical engineering, or similar discipline.
- CISSP or similar certification, or sufficient demonstrated experience
- Experience in embedded devices vulnerability assessment, especially medical devices and Threat Modelling and risk scoring
- Formal education in cybersecurity and information assurance.
- Minimum 12-year experience with 4 years of technical, cybersecurity-related experience,
- Experience in analyzing security posture and vulnerability assessment
- experience in penetration testing, fuzz testing of Web, enterprise cloud and Desktop solutions, (Black box, Gray box and Whitebox testing)
- Experience in static code analysis for security vulnerability
- Software Product Development experience, Programming skills in one or more of the following: C, C++, Python, Java, .NET, Go, Ruby and/or Scala
- Understanding of national and international laws, regulations, and policies related to regulated medical device cybersecurity
- Demonstrated understanding of information security practices, risk management processes, cybersecurity principles, and incident response methodologies
Physical Job Requirements
The above statements are intended to describe the general nature and level of work being performed by employees assigned to this position, but they are not an exhaustive list of all the required responsibilities and skills of this position.
Medtronic offers a competitive Salary and flexible Benefits Package
A commitment to our employees lives at the core of our values. We recognize their contributions. They share in the success they help to create. We offer a wide range of benefits, resources, and competitive compensation plans designed to support you at every career and life stage.
We lead global healthcare technology and boldly attack the most challenging health problems facing humanity by searching out and finding solutions.
Our Mission — to alleviate pain, restore health, and extend life — unites a global team of 90,000+ passionate people.
We are engineers at heart— putting ambitious ideas to work to generate real solutions for real people. From the R&D lab, to the factory floor, to the conference room, every one of us experiments, creates, builds, improves and solves. We have the talent, diverse perspectives, and guts to engineer the extraordinary.
Learn more about our business, mission, and our commitment to diversity here
* Salary range is an estimate based on our InfoSec / Cybersecurity Salary Index 💰
Tags: Black box C CISSP Cloud Code analysis Compliance Computer Science Incident response Intrusion detection IT infrastructure Java Monitoring Pentesting Product security Python R&D Risk assessment Risk management Ruby Scala Vulnerabilities
Perks/benefits: Career development Competitive pay Equity / stock options Health care
More jobs like this
Explore more career opportunities
Find even more open roles below ordered by popularity of job title or skills/products/technologies used.