Principal Product Security Engineer

Scorpion Therapeutics

Santa Clara (CA)

On-site

USD 180,000 - 240,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Vacation: 120 hours/year
Sick time: 40 hours/year
Holiday pay: 13 days/year
Parental Leave: 480 hours

Job summary

Scorpion Therapeutics in Santa Clara, CA is seeking a Principal Product Security Engineer to secure connected medical devices, robotic systems, and cloud services across the product lifecycle. You will guide security requirements, perform risk assessments, and drive remediation with cross-functional teams.

Responsibilities include threat modeling, security-by-design, and coordinating SAST/SCA testing, with extensive expertise in embedded/IoT security, crypto, and authentication/authorization

Qualifications

  • BS in CS/Cybersecurity/Software Engineering or equivalent.
  • 8+ years in cybersecurity/product security/cloud security.
  • Experience with threat modeling, secure development, vulnerability management, pen testing, security design review, and risk assessment.

Responsibilities

  • Serve as cybersecurity technical lead for complex medical device/digital health programs.
  • Lead security design reviews and risk-based mitigations across embedded, cloud, and apps.
  • Coordinate security testing (SAST, SCA, fuzzing, pen testing) and ensure traceability to risks and requirements.
  • Lead vulnerability management and post-market security activities including patching and disclosures.

Skills

Threat modeling
Secure development
Vulnerability management
Pen testing
Security design review
Cybersecurity risk assessment
Embedded/IoT security
Cloud security
Authn/Authz
OS hardening
Cryptography

Education

BS in CS/Cybersecurity/Software Eng

Tools

SAST tools
SCA tools
Threat modeling tools

Job description

Principal Product Security Engineer (Santa Clara, CA) — up to 10% travel.

Relocation to the San Francisco Bay area will be considered on a case-by-case basis.

Position Summary:

Senior technical cybersecurity expert securing connected medical devices, robotic systems, embedded platforms, cloud services, and supporting digital health ecosystems throughout the product lifecycle. Provides hands-on leadership across product teams by identifying risks, defining security requirements, assessing security, guiding remediation, and verifying security controls in regulated medical device products.

Primary Responsibilities:
  • Serve as cybersecurity technical lead for complex medical device/digital health programs.
  • Provide technical direction for security design, implementation, verification, vulnerability remediation, and risk treatment.
  • Drive security-by-design; mentor software/systems/cloud/embedded teams.
  • Develop/review/maintain cybersecurity requirements for embedded systems, apps, cloud, and connected devices.
  • Perform security reviews/assessments, attack surface analysis; evaluate authn/authz, crypto, secure boot, key management, access control, logging/monitoring, updates, and OS hardening.
  • Lead threat modeling and cybersecurity risk assessments; develop risk-based mitigations.
  • Coordinate security testing (SAST, SCA, scanning, fuzzing, pen testing, config review, architecture assessments) and ensure traceability to risks/requirements/release.
  • Lead vulnerability management and post-market security; support disclosure, patching, and surveillance.
  • Provide technical input for releases, quality/regulatory submissions; support audits and customer security materials.
Qualifications:
Required:
  • BS in CS/Cybersecurity/Software Engineering/Computer Engineering or equivalent.
  • 8+ years in cybersecurity/product security/cloud security.
  • Expertise in threat modeling, secure development, vulnerability management, pen testing, security design review, cybersecurity risk assessment.
  • Experience securing embedded/connected medical devices/IoT/robotics/cloud-connected or similar cyber-physical products.
  • Strong knowledge of authn/authz, cryptography, secure boot, key management, OS/network hardening, logging/monitoring, secure updates.
  • Experience writing/reviewing/validating technical cybersecurity requirements.
  • Ability to lead complex initiatives across cross-functional teams and communicate effectively.
Preferred:
  • Medical devices/healthcare tech/surgical robotics/regulated software/connect health experience.
  • FDA/global medical device cybersecurity expectations.
  • Standards/frameworks: ISO 14971, AAMI TIR57, IEC 62304, IEC 81001-5-1, HIPAA, GDPR, HITRUST, ISO 27001, OWASP Top 10, SOC 2, FedRAMP.
  • AWS/Azure and web/cloud security; secure infrastructure design.
  • Coding experience (C/C++/C#/Java/Python or similar).
  • Certifications: CISSP, CSSLP, GIAC, GICSP, or similar.
  • MS degree.
Benefits (time off, subject to policy/date of hire):
  • Vacation: 120 hours/year
  • Sick time: 40 hours/year (CO/Washington: 48/56)
  • Holiday pay (incl. Floating Holidays): 13 days/year
  • Work/Personal/Family Time: up to 40 hours/year
  • Parental Leave: 480 hours
  • Bereavement Leave: 240 hours immediate family (40 extended family/year)
  • Caregiver Leave: 80 hours (52-week rolling)
  • Volunteer Leave: 32 hours/year
  • Military Spouse Time-Off: 80 hours/year
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Principal Product Security Engineer
Principal Product Security Engineer

Johnson & Johnson • Santa Clara (CA)

On-site
USD 118,000 - 204,000
Vacation hours
Parental Leave
Holiday pay
Senior Software Engineer, Product Security,
Senior Software Engineer, Product Security,

Baxter International Inc. • Round Lake (IL)

On-site
USD 120,000 - 170,000
Medical coverage
Dental coverage
Life insurance
+12
Lead Cybersecurity Engineer (Biotech) (FDA)
Lead Cybersecurity Engineer (Biotech) (FDA)

Red Oak Technologies • Pleasanton (CA)

Hybrid
USD 179,000 - 210,000
Product Security Architect (Medical Device)
Product Security Architect (Medical Device)

Beacon Hill • San Diego (CA)

On-site
USD 120,000 - 160,000
Senior Product Security Engineer
Senior Product Security Engineer

Intellias • Newton (MA)

On-site
USD 120,000 - 180,000
Product Security Engineer - Medical Device
Product Security Engineer - Medical Device

BioTalent • San Diego (CA)

Hybrid
USD 90,000 - 120,000
Principal Product Security Engineer
Principal Product Security Engineer

6267-Auris Health Inc. Legal Entity • Santa Clara (CA)

On-site
USD 118,000 - 204,000
Senior Product Security Architect (Medical Devices)
Senior Product Security Architect (Medical Devices)

Pyramid Consulting, Inc • California (MO)

On-site
Health insurance (medical, dental, vision)
Senior Principal Engineer Software - Cyber Security (San Diego CA)
Senior Principal Engineer Software - Cyber Security (San Diego CA)

0090 CORP-Corporate Office • United States

On-site
USD 142,000 - 214,000
401(k) with company match
Health, life, and disability insurance
Paid time off (PTO)
Principal Cybersecurity Assurance Engineer (Remote - United States)
Principal Cybersecurity Assurance Engineer (Remote - United States)

USA SOLVENTUM US LLC • Town of Texas (WI)

Hybrid
USD 124,000 - 171,000
Relocation assistance