Sr. Product Security Engineer - (Embedded/IoT)
Fort Worth
Wednesday, 22 April 2026
Across our global Neuroscience organization, we advance care for some of medicine’s most complex neurological and spinal conditions. By combining innovative technology, data-driven insights, and deep clinical expertise, we partner with physicians and health systems to improve how patients are treated and supported throughout their care journey. Our Neuromodulation operating unit delivers advanced therapies for chronic pain, movement disorders, and nervous system conditions, offering SCS, DBS, and targeted drug delivery. Through proven technology, clinical evidence, and innovation, we provide personalized solutions that restore function and enhance quality of life. Check us out on LinkedIn: Medtronic Brain Modulation and Pain Interventions. Pelvic Health. Our Pelvic Health Operating Unit advances care for patients living with bladder and bowel control conditions through targeted, minimally invasive neuromodulation therapies, including sacral and tibial solutions. Designed to modulate nerve pathways and restore communication between the brain and pelvic floor, these programmable therapies deliver personalized treatment supported by strong clinical evidence and long-term outcomes—helping improve confidence, independence, and quality of life. Check us out on LinkedIn: Medtronic Pelvic Health. Onsite We’re working onsite 4 days a week at our Minnesota Rice Creek East facility, to drive performance, foster an environment of belonging, and collaborate to inspire as we engineer the extraordinary. At Medtronic, we’re driven by our Mission to alleviate pain, restore health, and extend life for millions of people around the world through innovative biomedical devices and connected health solutions. As our products become increasingly connected, securing the medical device ecosystem at the product and system level is critical to ensuring patient safety and product integrity. The Senior Product Security Engineer will play a key role in securing connected and embedded medical devices across the full product lifecycle. This role is focused on device/product security engineering (not enterprise IT security) and partners closely with R&D, software, systems, and quality teams to design and implement robust, scalable security controls. The ideal candidate brings hands-on experience securing embedded or IoT products in regulated environments, with strong depth in threat modeling, secure architecture, cryptography, and device-level risk management. Key Responsibilities:Product Security Engineering – Embed security requirements into the medical device development lifecycle, partnering with R&D and systems teams from architecture through release. Threat Modeling & Risk Assessment – Perform system-level threat modeling (e.g., STRIDE or similar), attack surface analysis, and vulnerability assessments for connected and embedded medical devices. Secure Architecture – Support and review implementation of device security capabilities such as: Secure boot and root of trust Secure firmware/software update mechanisms Device identity and authentication Secure communications and protocol hardening Data protection at rest and in transit Key management and Hardware Security Module (HSM) concepts Cryptography & Post-Quantum Readiness – Apply modern cryptographic principles and support forward-looking strategies including quantum-resistant approaches where applicable. Secure SDLC Integration – Partner with agile development teams to embed security into design reviews, code reviews, CI/ CD pipelines, and verification activities. Verification & Validation – Define and support security V&V activities including penetration testing, static/dynamic analysis, fuzz testing, and vulnerability management. Standards & Compliance – Ensure alignment with medical device cybersecurity expectations including: FDA premarket cybersecurity guidance IEC 81001-5-1 ISO 14971 NIST frameworks Relevant Medtronic quality processes Incident & Vulnerability Management – Support coordinated vulnerability disclosure, post-market monitoring, and security issue response for released products. Cross-Functional Partnership – Work closely with R&D, systems, software, quality, and regulatory teams to drive secure product development. Industry Awareness – Maintain awareness of evolving threats, healthcare cybersecurity trends, and regulatory expectations for connected medical devices. Minimum Requirements Bachelor’s degree in Computer Science, Computer Engineering, Electrical Engineering, or related technical field and 4 years of experience in: Embedded/device security IoT security Product security engineering OR advanced degree with 2 years of relevant experience To Be Successful in This Role :Device/ Product Security Depth – Demonstrated hands-on experience securing embedded or connected products (medical device experience strongly preferred). Threat Modeling Expertise – Practical experience performing system or device-level threat modeling and risk assessments. Embedded/ IoT Security Knowledge – Strong understanding of: Embedded systems Firmware/software interactions Device communications Hardware-software security boundaries Cryptography Fundamentals – Working knowledge of: Modern cryptographic primitives Key management PKI concepts Secure protocol implementation Regulatory Awareness – Familiarity with medical device cybersecurity expectations and regulated product environments. Secure Development Practices – Experience working with agile teams and integrating security into SDLC/ Dev. Sec. Ops workflows. Collaboration Skills – Strong ability to influence cross-functional engineering teams. Technical Skills Embedded or IoT security Threat modeling methodologies (STRIDE or similar) Secure boot / root of trust concepts Secure firmware update mechanisms Network and device protocol security Cryptography and key management Vulnerability assessment and penetration testing Familiarity with NIST, MITRE, OWASP (device context) Preferred:Medical device cybersecurity experience Experience with IEC 81001-5-1 Experience with FDA cybersecurity submissions Background in connected healthcare products Security certifications (Security , CISSP, etc.) For Baccalaureate degrees earned outside of the United States, a degree that satisfies the requirements of 8 C. F. R. § 214.2(h)(4)(iii)(A) is required. Physical Job Requirements. The above statements are intended to describe the general nature and level of work being performed by employees assigned to this position, but they are not an exhaustive list of all the required responsibilities and skills of this position.