SonicJobs Logo
Left arrow iconBack to search

Sr. Product Security Engineer - (Embedded/IoT)

Medtronic
Posted 6 days ago, valid for 4 days
Location

Denver, CO 80259, US

Salary

$98,400 - $147,600 per year

Contract type

Full Time

Health Insurance
Retirement Plan
Paid Time Off
Life Insurance
Tuition Reimbursement
Employee Assistance
Flexible Spending Account

By applying, a Sonicjobs account will be created for you. Sonicjobs's Privacy Policy and Terms & Conditions will apply.

SonicJobs' Terms & Conditions and Privacy Policy also apply.

Sonic Summary

info
  • Medtronic is seeking a Senior Product Security Engineer with a focus on securing connected medical devices, requiring a minimum of 4 years of relevant experience in embedded or IoT security.
  • The position involves collaborating with R&D, software, and quality teams to integrate security into the medical device development lifecycle and conducting threat modeling and risk assessments.
  • Candidates should possess a bachelor's degree in a technical field and have hands-on experience with cryptography, secure architecture, and product security engineering.
  • The salary range for this position is between $98,400.00 and $147,600.00, depending on experience and qualifications.
  • This role is based onsite at the Minnesota Rice Creek East facility, where employees work four days a week.
We anticipate the application window for this opening will close on - 11 May 2026


Ā 

At Medtronic you can begin a life-long career of exploration and innovation, while helping champion healthcare access and equity for all. You’ll lead with purpose, breaking down barriers to innovation in a more connected, compassionate world.

A Day in the Life

Ā Ā Ā Ā Ā Ā Ā Ā Ā 

Ā Ā Ā Ā Ā Ā Ā Ā Ā 

Across our global Neuroscience organization, we advance care for some of medicine’s most complex neurological and spinal conditions. By combining innovative technology, data-driven insights, and deep clinical expertise, we partner with physicians and health systems to improve how patients are treated and supported throughout their care journey.

Our Neuromodulation operating unit delivers advanced therapies for chronic pain, movement disorders, and nervous system conditions, offering SCS, DBS, and targeted drug delivery. Through proven technology, clinical evidence, and innovation, we provide personalized solutions that restore function and enhance quality of life.Ā 

Check us out on LinkedIn: Medtronic Brain Modulation and Pain Interventions

Pelvic Health

Our Pelvic Health Operating Unit advances care for patients living with bladder and bowel control conditions through targeted, minimally invasive neuromodulation therapies, including sacral and tibial solutions. Designed to modulate nerve pathways and restore communication between the brain and pelvic floor, these programmable therapies deliver personalized treatment supported by strong clinical evidence and long-term outcomes—helping improve confidence, independence, and quality of life.

Check us out on LinkedIn: Medtronic Pelvic Health

OnsiteĀ 

We’reĀ working onsite 4 days a week at our Minnesota Rice Creek East facility, to driveĀ performance, foster an environment of belonging, and collaborate to inspire as we engineer the extraordinary.Ā 

At Medtronic,Ā we’reĀ driven by our Mission to alleviate pain, restore health, and extend life for millions of people around the world through innovative biomedical devices and connected health solutions. As our products become increasingly connected, securing theĀ medical device ecosystem at the product and system levelĀ is critical to ensuring patient safety and product integrity.Ā TheĀ Senior Product Security EngineerĀ will play a key role in securing connected and embedded medical devices across the full product lifecycle. This role is focused onĀ device/product security engineeringĀ (not enterprise IT security) and partners closely with R&D, software, systems, and quality teams to design and implement robust, scalable security controls.Ā 

The ideal candidate bringsĀ hands-on experience securing embedded or IoT products in regulated environments, with strong depth in threat modeling, secure architecture, cryptography, and device-level risk management.Ā 

Ā 

Key Responsibilities:

Product Security Engineering – Embed security requirements into the medical device development lifecycle, partnering with R&D and systems teams from architecture through release.Ā 

Threat Modeling & Risk Assessment – Perform system-level threat modeling (e.g., STRIDE or similar), attack surface analysis, and vulnerability assessments for connected and embedded medical devices.Ā 

Secure Architecture – Support and review implementation of device security capabilities such as:Ā 

  • SecureĀ bootĀ andĀ rootĀ of trustĀ 

  • Secure firmware/software update mechanismsĀ 

  • Device identity and authenticationĀ 

  • Secure communications and protocol hardeningĀ 

  • Data protection at rest and in transitĀ 

  • Key management and Hardware Security Module (HSM) conceptsĀ 

Cryptography & Post-Quantum Readiness – Apply modern cryptographic principles and support forward-looking strategies including quantum-resistant approaches where applicable.Ā 

Secure SDLC Integration – Partner with agile development teams to embed security into design reviews, code reviews, CI/CD pipelines, and verification activities.Ā 

Verification & Validation – Define and support security V&V activities including penetration testing, static/dynamic analysis, fuzz testing, and vulnerability management.Ā 

Standards & Compliance – Ensure alignment with medical device cybersecurity expectations including:Ā 

  • FDA premarket cybersecurity guidanceĀ 

  • IEC 81001-5-1Ā 

  • ISO 14971Ā 

  • NIST frameworksĀ 

  • Relevant Medtronic quality processesĀ 

Incident & Vulnerability Management – Support coordinated vulnerability disclosure, post-market monitoring, and security issue response for released products.Ā 

Cross-Functional Partnership – Work closely with R&D, systems, software, quality, and regulatory teams to drive secure product development.Ā 

Industry Awareness – Maintain awareness of evolving threats, healthcare cybersecurity trends, and regulatory expectations for connected medical devices.Ā 

Ā 

MinimumĀ RequirementsĀ 

Bachelor’s degree in Computer Science, Computer Engineering, Electrical Engineering, or related technical fieldĀ andĀ 4+ years of experience in:Ā 

  • Embedded/device securityĀ 

  • IoT securityĀ 

  • Product security engineeringĀ 

  • OR advanced degree with 2+ years of relevant experienceĀ 

Ā 

To Be Successful in This RoleĀ :

Device/Product Security Depth – Demonstrated hands-on experience securing embedded or connected products (medical device experience strongly preferred).Ā 

Threat Modeling Expertise – Practical experience performing system or device-level threat modeling and risk assessments.Ā 

Embedded/IoT Security Knowledge – Strong understanding of:Ā 

  • Embedded systemsĀ 

  • Firmware/software interactionsĀ 

  • Device communicationsĀ 

  • Hardware-software security boundariesĀ 

Cryptography Fundamentals – Working knowledge of:Ā 

  • Modern cryptographic primitivesĀ 

  • Key managementĀ 

  • PKI conceptsĀ 

  • Secure protocol implementationĀ 

Regulatory Awareness – Familiarity with medical device cybersecurity expectations and regulated product environments.Ā 

Secure Development Practices – Experience working with agile teams and integrating security into SDLC/DevSecOpsĀ workflows.Ā 

Collaboration Skills – Strong ability to influence cross-functional engineering teams.Ā 

Ā 

Technical SkillsĀ 

  • Embedded or IoT securityĀ 

  • Threat modeling methodologies (STRIDE or similar)Ā 

  • Secure boot / root of trust conceptsĀ 

  • Secure firmware update mechanismsĀ 

  • Network and device protocol securityĀ 

  • Cryptography and key managementĀ 

  • Vulnerability assessment and penetration testingĀ 

  • Familiarity with NIST, MITRE, OWASP (device context)Ā 

Ā 

Preferred:

  • Medical device cybersecurity experienceĀ 

  • Experience with IEC 81001-5-1Ā 

  • Experience with FDA cybersecurity submissionsĀ 

  • Background in connected healthcare productsĀ 

  • Security certifications (Security+, CISSP, etc.)Ā 

Ā 

For Baccalaureate degrees earned outside of the United States, a degree that satisfies the requirements of 8 C.F.R. § 214.2(h)(4)(iii)(A) is required.

Physical Job Requirements

The above statements are intended to describe the general nature and level of work being performed by employees assigned to this position, but they are not an exhaustive list of all the required responsibilities and skills of this position. 

The physical demands described within the Responsibilities section of this job description are representative of those that must be met by an employee to successfully perform the essential functions of this job. Reasonable accommodations may be made to enable individuals with disabilities to perform the essential functions. For Office Roles: While performing the duties of this job, the employee is regularly required to be independently mobile. The employee is also required to interact with a computer, and communicate with peers and co-workers. Contact your manager or local HR to understand the Work Conditions and Physical requirements that may be specific to each role.

U.S. Work Authorization & Sponsorship

At Medtronic, we are committed to fostering an environment where employees can thrive and make a meaningful impact. In alignment with our enterprise-wide workforce planning approach, U.S. work authorization sponsorship (H-1B, TN, J, etc.) is offered exclusively for Principal-level roles and above, where specialized expertise aligns with long-term business needs. Roles below the Principal level require candidates to possess unrestricted U.S. work authorization at the time of hire and for the duration of employment.

Join us in our mission to alleviate pain, restore health, and extend life—where your unique background and perspective are valued.

Benefits & Compensation
Ā 

Medtronic offers a competitive Salary and flexible Benefits Package
A commitment to our employees lives at the core of our values. We recognize their contributions. They share in the success they help to create.Ā  We offer a wide range of benefits, resources, and competitive compensation plans designed to support you at every career and life stage.
Ā 

Salary ranges for U.S (excl. PR) locations (USD):$98,400.00 - $147,600.00

Ā 

This position is eligible for a short-term incentive called the Medtronic Incentive Plan (MIP).

The base salary range is applicable across the United States, excluding Puerto Rico and specific locations in California. The offered rate complies with federal and local regulations and may vary based on factors such as experience, certification/education, market conditions, and location. Compensation and benefits information pertains solely to candidates hired within the United States (local market compensation and benefits will apply for others).

The following benefits and additional compensation are available to those regular employees who work 20+ hours per week: Health, Dental and vision insurance,Ā Health Savings Account,Ā Healthcare Flexible Spending Account,Ā Life insurance, Long-term disability leave,Ā Dependent daycare spending account,Ā Tuition assistance/reimbursement, andĀ Simple Steps (global well-being program).

Ā 

The following benefits and additional compensation are available to all regular employees:Ā Incentive plans, 401(k) plan plus employer contribution and match,Ā Short-term disability,Ā Paid time off,Ā Paid holidays,Ā Employee Stock Purchase Plan,Ā Employee Assistance Program,Ā Non-qualified Retirement Plan Supplement (subject to IRS earning minimums), andĀ Capital Accumulation Plan (available to Vice Presidents and above, or subject to IRS earning minimums).

Ā 

Regular employees are those who are not temporary, such as interns.Ā  Temporary employees are eligible for paid sick time, as required under applicable state law, and the Employee Stock Purchase Plan. Please note some of the above benefits may not apply to workers in Puerto Rico.

Ā 

Further details are available at the link below:

Medtronic benefits and compensation plans

About Medtronic

We lead global healthcare technology and boldly attack the most challenging health problems facing humanity by searching out and finding solutions.
Our Mission — to alleviate pain, restore health, and extend life — unites a global team of 95,000+ passionate people.Ā 
We are engineers at heart— putting ambitious ideas to work to generate real solutions for real people. From the R&D lab, to the factory floor, to the conference room, every one of us experiments, creates, builds, improves and solves. We have the talent, diverse perspectives, and guts to engineer the extraordinary.

Learn more about our business, mission, and our commitment to diversity here.

It is the policy of Medtronic to provide equal employment opportunity (EEO) to all persons regardless of age, color, national origin, citizenship status, physical or mental disability, race, religion, creed, gender, sex, sexual orientation, gender identity and/or expression, genetic information, marital status, status with regard to public assistance, veteran status, or any other characteristic protected by federal, state or local law. In addition, Medtronic will provide reasonable accommodations for qualified individuals with disabilities.

If you are applying to perform work for Medtronic, Inc. (ā€œMedtronicā€) in any position which will involve performing at least two (2) hours of work on average each week within the unincorporated areas of Los Angeles County, you can findĀ here a list of all material job duties of the specific job position which Medtronic reasonably believes that criminal history may have a direct, adverse and negative relationship potentially resulting in the withdrawal of a conditional offer of employment. Medtronic will consider for employment qualified job applicants with arrest or conviction records in accordance with the Los Angeles County Fair Chance Ordinance for Employers and the California Fair Chance Act.




Learn more about this Employer on their Career Site

Apply now in a few quick clicks

By applying, a Sonicjobs account will be created for you. Sonicjobs's Privacy Policy and Terms & Conditions will apply.

SonicJobs' Terms & Conditions and Privacy Policy also apply.