Senior Product Security Engineer

NoxPharm

Hyderabad

Hybrid

INR 3,500,000 - 5,500,000

Full time

24 hours ago
Be an early applicant
Application generator

Stand out for this role — generate a tailored resume and cover letter in about a minute.

Get past ATS filters

Benefits offered by this job

Flex work arrangement

Job summary

Medtronic is seeking a Product Security professional based in Hyderabad, India, with 8+ years in cybersecurity for medical devices and connected solutions. You will perform risk assessments, threat modeling, and security testing across product lifecycles, partnering with R&D, Quality, Regulatory, and Product teams to secure architectures and post-market activities.

You will drive SSDLC/DevSecOps initiatives, automate security processes, and support vulnerability management and disclosure as part

Qualifications

  • Bachelor's or Master's degree in Computer Science, Cybersecurity, IT, Software Engineering, or ECE with 8+ years of experience in Product Security/SSDLC/DevSecOps.
  • Experience with connected products, embedded systems, cloud services, IoT platforms, or healthcare tech.
  • Experience with risk assessments, threat modeling, vulnerability assessments, and security testing.
  • Experience with security tools: Burp Suite, OWASP ZAP, Nessus, Nmap, Wireshark, Metasploit.

Responsibilities

  • Perform security risk assessments across the product development lifecycle.
  • Conduct threat modeling using STRIDE, ATT&CK, CVSS and related methods.
  • Define product security requirements and implement security controls.
  • Review architectures for security across systems, software, cloud, and networks.
  • Collaborate with development teams to design secure products and mitigate risks.
  • Plan and execute security testing including vulnerability assessments and pen testing.
  • Track vulnerabilities through remediation and post-market cybersecurity processes.
  • Integrate security into DevSecOps, SSDLC, and security automation practices.

Skills

Security risk assessments
Threat modeling
Security architecture reviews
Vulnerability assessments
Penetration testing
Secure code reviews
Network security testing
Web/API security testing
Python scripting
SSDLC/DevSecOps
Automation of security processes

Education

Bachelor's or Master's in CS/Cybersecurity/ET/EE

Tools

Burp Suite
OWASP ZAP
Nessus
Nmap
Wireshark
Metasploit

Job description

Job Description

Careers that change lives start here. Medtronic is a global leader in healthcare technology with a Mission to alleviate pain, restore health, and extend life. Our 95,000 employees work across more than 150 countries to put patients first — developing innovative medical technologies that improve the lives of 72+ million patients each year. Your unique talents will help shape the future of healthcare while building a career grounded in purpose, growth, and impact. A Day in the Life The Product Security function within Research & Development is responsible for integrating cybersecurity throughout the product lifecycle for medical devices, connected healthcare solutions, software applications, embedded products, and cloud-connected healthcare systems. The team partners closely with R&D, Systems Engineering, Quality, Regulatory, and Product teams to support secure product development, cybersecurity risk management, vulnerability management, regulatory compliance, and post-market cybersecurity activities across Class I, Class II, and Class III medical devices. This position is based in Hyderabad, India and follows a Flex work arrangement. No travel is required.

Primary Responsibilities
  • Perform security risk assessments throughout the product development lifecycle.
  • Conduct threat modeling activities using methodologies such as STRIDE, Attack Trees, MITRE ATT&CK, CVSS, and similar frameworks.
  • Identify product security requirements and support implementation of appropriate security controls.
  • Review system, software, cloud, and network architectures from a security perspective.
  • Collaborate with development teams to design secure products and mitigate identified risks.
  • Plan and execute security testing activities including vulnerability assessments, penetration testing, secure code reviews, security regression testing, protocol security testing, and network security testing.
  • Analyze, prioritize, and track vulnerabilities through remediation and verification activities while supporting coordinated vulnerability disclosure and post-market cybersecurity processes.
  • Integrate cybersecurity activities into product development processes, support security design reviews, security architecture assessments, security impact assessments, security KPIs, security metrics, automation initiatives, and DevSecOps practices.
Required Qualifications
  • Bachelor's degree OR Master's degree in Computer Science, Cybersecurity, Information Technology, Software Engineering, or Electronics & Communication Engineering with 8+ years of experience in Product Security, Application Security, Cybersecurity Engineering, or Medical Device Security.
  • Experience working with connected products, embedded systems, desktop applications, cloud services, Internet of Things (IoT) platforms, or healthcare technology products.
  • Experience in security risk assessments, threat modeling, security architecture reviews, security requirements engineering, vulnerability assessments, penetration testing, secure code reviews, network security testing, and web/API security testing.
  • Experience with security tools including Burp Suite, OWASP ZAP, Nessus, Nmap, Wireshark, Metasploit, or similar application and infrastructure security tools.
  • Experience developing scripts and automation tools using Python and supporting Secure Software Development Lifecycle (SSDLC), DevSecOps, vulnerability management, and security automation activities.
Preferred Qualifications
  • Experience securing Class I, Class II, and Class III medical devices, connected healthcare solutions, Software as a Medical Device (SaMD), or cloud-connected healthcare systems.
  • Knowledge of FDA Cybersecurity Guidance, IEC 81001-5-1, AAMI TIR57, AAMI TIR97, IEC 62304, ISO 14971, and NIST 800-53.
  • Experience with Software Bill of Materials (SBOM), dependency analysis, coordinated vulnerability disclosure, and post-market cybersecurity activities.
  • Knowledge of cloud security in Microsoft Azure and Amazon Web Services (AWS) environments.
  • Knowledge of authentication and authorization technologies, cryptography fundamentals, and secure communication protocols including TLS, HTTPS, and MQTT.
Physical Job Requirements

The above statements are intended to describe the general nature and level of work being performed by employees assigned to this position, but they are not an exhaustive list of all the required responsibilities and skills of this position.

Benefits & Compensation

Medtronic offers a competitive Salary and flexible Benefits Package A commitment to our employees lives at the core of our values. We recognize their contributions. They share in the success they help to create. We offer a wide range of benefits, resources, and competitive compensation plans designed to support you at every career and life stage. This position is eligible for a short-term incentive called the Medtronic Incentive Plan (MIP).

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Product Security Engineer II
Product Security Engineer II

Medtronic • Hyderabad

On-site
INR 1,800,000 - 2,800,000
Senior Product Security Engineer
Senior Product Security Engineer

Medtronic • Hyderabad

Hybrid
INR 4,000,000 - 6,000,000
Flexible work arrangement
Incentives
Senior Product Security Engineer
Senior Product Security Engineer

Medtronic • Hyderabad

Hybrid
INR 2,600,000 - 5,200,000
Flexible Work Arrangement
Principal Product Security Engineer
Principal Product Security Engineer

Medtronic • Hyderabad

On-site
INR 2,500,000 - 4,500,000
Principal Product Security Engineer
Principal Product Security Engineer

medtronic • India

On-site
INR 3,000,000 - 5,500,000
Competitive salary
Incentive plan (MIP)
Benefits package
Systems Engineer II
Systems Engineer II

medtronic • India

On-site
INR 2,500,000 - 4,500,000
Medtronic Incentive Plan (MIP)
Principal PD Project Management Specialist
Principal PD Project Management Specialist

medtronic • India

Hybrid
INR 4,000,000 - 7,000,000
Short-term incentive (MIP)
Senior Enterprise Software Test Engineer
Senior Enterprise Software Test Engineer

Medtronic • Hyderabad

On-site
INR 2,500,000 - 4,000,000
Software Engineering Manager
Software Engineering Manager

Medtronic • Hyderabad

On-site
INR 4,000,000 - 6,000,000
Software Engineering Manager
Software Engineering Manager

medtronic • India

On-site
INR 4,000,000 - 7,000,000
Competitive salary
Flexible benefits package
Medtronic Incentive Plan (MIP)