Staff Product Security Engineer

Abbott

Confirmed live yesterday High trust

Quick summary

Work type
On-site
Location
St. Paul, MN
Salary
$113,300–$226,700 / yr
Posted
22 days ago
Freshness
Confirmed live yesterday

Market check

Salary context

Competitive pay

How this pay compares to similar roles

Similar $185k
This role $170k
$100k most similar roles pay here $240k

This role pays less than 54% of similar roles. Most pay $154,914–$216,065 — the shaded band above. At the midpoint, this role pays about $170k versus about $185k for comparable roles.

Based on 240 similar postings.

Employer

About Abbott

Abbott Laboratories is a global healthcare company that manufactures and markets a broad and diversified line of health care products including diagnostics, medical devices, nutritionals, and branded generic pharmaceuticals. Industry: Healthcare & Medical Devices

Abbott currently has 90 open roles on FindRole.

Listed pay typically runs $99,300–$198,700 across 89 roles with salary data.

Most-posted roles

View all roles at Abbott

At a glance

TL;DR · Staff Product Security Engineer

Staff Product Security Engineer As part of the EP division, this role serves as a cybersecurity leader across the product lifecycle to secure next-generation connected medical devices. The engineer will partner with cross-functional teams including software, firmware, hardware, and regulatory departments to ensure security is integrated from concept through deployment. Key responsibilities include leading architecture reviews, designing secure boot systems, managing PKI and certificate lifecycles, and performing threat modeling using STRIDE and OWASP methodologies. The candidate will develop and review security controls in C/C++, Python, and Linux-based environments while managing SBOMs and CVE risks. Technical expertise is required in hardware roots of trust, TPMs, and secure elements to protect patient safety and data integrity. This role addresses the critical challenge of securing embedded systems within highly regulated healthcare technology environments to meet stringent compliance standards.

What you'll do

  • Lead cybersecurity architecture reviews and security-by-design initiatives for connected medical devices.
  • Design and evaluate secure boot, hardware roots of trust, and firmware update mechanisms.
  • Develop and review security controls in C/C++, Python, and Linux-based embedded systems.
  • Conduct threat modeling using STRIDE or OWASP to identify risks to patient safety and data.
  • Manage vulnerability assessments, including CVE analysis, SBOM maintenance, and remediation strategies.
  • Execute cybersecurity assessment plans, including penetration testing and firmware analysis.
  • Prepare technical documentation for customers, auditors, and regulatory agencies regarding compliance.
  • Provide technical leadership and mentorship to cross-functional engineering teams.

What we're looking for

  • Bachelor's degree in Computer Engineering, Electrical Engineering, Computer Science, Software Engineering, Cybersecurity, or a related discipline.
  • 8+ years of experience in cybersecurity engineering, product security, embedded systems, or related fields.
  • 5+ years of hands-on experience securing embedded devices, firmware, medical devices, or IoT products.
  • Proficiency in programming languages including C/C++, Python, and Shell scripting.
  • Expertise in secure boot, hardware root of trust, code signing, PKI, and cryptographic key management.
  • Experience with threat modeling (STRIDE, OWASP), SBOM analysis, CVE management, and penetration testing.
  • Familiarity with ARM-based processors, embedded Linux, RTOS environments, and connected device architectures.
  • Strong technical writing skills to communicate complex cybersecurity risks to engineers, business leaders, and regulators.

More like this

Similar roles

Principal Product Security Engineer

Johnson & Johnson

Remote (Santa Clara, CA) 23 days ago $118,000$203,550
Threat Modeling Vulnerability Management Penetration Testing CVSS SBOM Cloud Security AWS Azure C C++ C# Java Python Cryptography Secure Boot ISO 14971 AAMI TIR57 IEC 62304 IEC 81001-5-1 HIPAA GDPR HITRUST ISO 27001 OWASP Top 10 SOC 2 FedRAMP
8+ yrs exp Remote

Senior Product Security Engineer

Anduril Industries

Fort Collins, CO 151 days ago $144,000$191,000
C/C++ Golang Rust Python Linux Firmware IoT Embedded Systems Reverse Engineering Anti-tamper Cyber Survivability JSIG ICD 503 CSEIG SSECG NIST SP 800-160 CMMC Programmable Logic Devices
8+ yrs exp

Product Security Engineer, Programs

Anduril Industries

Quincy, MA 64 days ago $156,000$253,000
C/C++ Golang Rust Python Linux Firmware IoT Embedded Systems Reverse Engineering Anti-tamper Programmable Logic Devices NIST SP 800-160 JSIG ICD 503 CSEIG SSECG CMMC Cyber Survivability

Embedded Product Cybersecurity Engineer, Embedded Software

GE Aerospace

Evendale, OH 7 days ago
C/C++ Python MATLAB Simulink Embedded Systems Risk Management Framework NIST SP 800-30 RTCA/DO-326A RTCA/DO-356A Linux Unix Agile Scrum LEAN Signal Processing Control Theory Reverse Engineering Cybersecurity Risk Assessment
3+ yrs exp

Staff Product Security Engineer

Reddit

Remote 135 days ago $217,000$303,900
Go Python CI/CD LLM Authentication Authorization Cloud-Native Platforms Product Security Application Security Software Engineering
8+ yrs exp Remote

Staff Product Security Engineer

Qualcomm

San Diego, CA 15 days ago $149,600$224,400
Security Engineering C C++ Java Python System Verilog Risk Assessment Threat Analysis Security Code Review Software Security
4+ yrs exp