Senior Product Security Engineer

Medtronic

Confirmed live yesterday High trust
Closes tomorrow

Quick summary

Work type
On-site
Location
MN
Salary
$132,000–$198,000 / yr
Posted
6 days ago
Freshness
Confirmed live yesterday
Closes
Sep 18, 2026 (soon)

Market check

Salary context

Competitive pay

How this pay compares to similar roles

Similar $188k
This role $165k
$121k most similar roles pay here $236k

This role pays less than 65% of similar roles. Most pay $159,000–$217,500 — the shaded band above. At the midpoint, this role pays about $165k versus about $188k for comparable roles.

Based on 240 similar postings.

Employer

About Medtronic

Medtronic plc is the world's largest medical technology company by revenue, specializing in device-based therapies for over 70 health conditions.

Medtronic currently has 56 open roles on FindRole.

Listed pay typically runs $124,000–$186,000 across 55 roles with salary data.

Most-posted roles

View all roles at Medtronic

At a glance

TL;DR · Senior Product Security Engineer

Sr. Product Security Engineer - Cloud Digital Solutions leads cybersecurity architecture for Digital Health Platforms, cloud services, web and mobile applications, APIs, and remote monitoring solutions supporting connected medical devices. This role involves defining security-by-design and defense-in-depth architectures, performing threat modeling, and conducting security risk analysis to protect digital ecosystems. The position requires managing SBOMs, overseeing data protection for at-rest and in-transit information, and ensuring compliance with standards like SOC 2, ISO/IEC 27001, and HIPAA. Key technical competencies include cloud-native security, IAM, PKI, encryption, secrets management, containers, DevSecOps, and vulnerability management. The role addresses the critical challenge of securing interconnected medical device infrastructure and digital health workflows while ensuring alignment with stringent medical-device cybersecurity regulations and requirements for data privacy across various connected services and platforms.

What you'll do

  • Define Security-by-Design and Defense-in-Depth architectures for cloud services, mobile applications, and medical device ecosystems.
  • Establish security requirements for identity management, encryption, network segmentation, and data protection across digital platforms.
  • Lead threat modeling, risk analysis, and attack-surface mapping to translate identified threats into technical controls.
  • Manage Software Bill of Materials (SBOM) and security requirements for containers, APIs, and third-party dependencies.
  • Design secure protocols for eFOTA orchestration, remote monitoring, and device-to-service authentication.
  • Develop and execute the application-security roadmap including vulnerability management and DevSecOps integration.
  • Lead compliance activities and evidence collection for SOC 2, ISO 27001, HIPAA, and other medical device regulations.
  • Coordinate with engineering and quality teams to ensure alignment with regulatory submissions and data privacy standards.

What we're looking for

  • A Bachelor's degree in a related field with 4 years of experience or a Master's degree with 2 years of experience is required.
  • Candidates must have extensive experience in cloud security, application security, digital platforms, cybersecurity architecture, or regulated software development.
  • Knowledge of cloud-native security, IAM, APIs, PKI, encryption, secrets management, containers, DevSecOps, and data protection is preferred.
  • Experience with threat modeling, SRA, SBOM/SCA, Security-by-Design, Defense-in-Depth, and regulated medical-device environments is preferred.
  • Understanding of medical device regulations and standards such as FDA guidance, ISO 13485, ISO 27001, SOC 2, and HIPAA is preferred.
  • Candidates must possess strong decision-making capabilities to weigh costs and benefits when identifying solutions.
  • High attention to detail with a focus on Good Documentation Practices (GDP) is required.
  • Work authorization at the time of hire and for the duration of employment.

More like this

Similar roles

Senior Product Security Engineer, Post Market Surveillance

Medtronic

Rice Creek East, MN 6 days ago $132,000$198,000
Cybersecurity Vulnerability Management CVSS Threat Modeling SBOM SCA Security Risk Analysis Software Systems ISO 13485 ISO 81001-5-1 EU MDR root-cause analysis CAPA Good Documentation Practices (GDP)
4+ yrs exp

Principal Product Security Engineer

Johnson & Johnson

Remote (Santa Clara, CA) 29 days ago $118,000$203,550
Threat Modeling Vulnerability Management Penetration Testing CVSS SBOM Cloud Security AWS Azure C C++ C# Java Python Cryptography Secure Boot ISO 14971 AAMI TIR57 IEC 62304 IEC 81001-5-1 HIPAA GDPR HITRUST ISO 27001 OWASP Top 10 SOC 2 FedRAMP
8+ yrs exp Remote

Senior Product Security Lead

Nvidia

Santa Clara, CA 7 days ago $224,000$356,500
Linux Firmware Secure Boot Trusted Execution Cryptography Threat Modeling vulnerability-management SBOM C C++ Python Container Security ARM Edge AI NIST SSDF IEC 62443 ISO/SAE 21434 ISO/IEC 27001 ETSI EN 303 645
10+ yrs exp

Senior Product Security Engineer

Adobe

San Jose, CA 13 days ago $180,600$261,450
OWASP Top 10 CVSS v3.1 Burp Suite Python PowerBI JIRA REST API OAuth2 AWS Lambda API Gateway SQL Injection XSS SSRF IDOR SOAR Webhooks curl DevTools
5+ yrs exp

Senior Product Security Engineer

Anduril Industries

Fort Collins, CO 157 days ago $144,000$191,000
C/C++ Golang Rust Python Linux Firmware IoT Embedded Systems Reverse Engineering Anti-tamper Cyber Survivability JSIG ICD 503 CSEIG SSECG NIST SP 800-160 CMMC Programmable Logic Devices
8+ yrs exp

Senior Product Security Engineer

Cloudflare, Inc

Austin, TX 57 days ago
Product Security Application Security AI LLM Threat Modeling STRIDE Vulnerability Management SAST Fuzzing Penetration Testing Bug Bounty JIRA Agile SaaS Distributed Systems
Hybrid