An application made for this job — a tailored resume and cover letter that speak straight to the posting.
Medtronic's Neuromodulation and Pelvic Health R&D seeks a Principal Security & Privacy Engineer to advance Privacy by Design across connected medical devices and supporting technology. You will lead privacy risk management, regulatory compliance activities, DPIAs, and incident response, working with product security to embed privacy throughout the lifecycle.
Ideal candidates bring senior privacy program leadership, HIPAA/GDPR familiarity, and experience with medical device regulations.
Onsite
Fridley, Minnesota, United States of America
Full time
R75456
We anticipate the application window for this opening will close on - 23 Sep 2026
Careers that change lives start here. Medtronic is a global leader in healthcare technology with a Mission to alleviate pain, restore health, and extend life. Our 95,000 employees work across more than 150 countries to put patients first — developing innovative medical technologies that improve the lives of 72+ million patients each year. Your unique talents will help shape the future of healthcare while building a career grounded in purpose, growth, and impact.
The Neuromodulation and Pelvic Health Research & Development (R&D) organizations develop and support medical device technologies that address chronic pain, movement disorders, overactive bladder, non-obstructive urinary retention, and other conditions requiring advanced therapeutic solutions. These teams partner across engineering, security, regulatory, quality, and legal functions to deliver products that meet patient, customer, and global regulatory requirements while protecting sensitive health and personal data.
As the Principal Security & Privacy Engineer, you will serve as the technical leader responsible for advancing Privacy by Design practices across a portfolio of connected medical devices and supporting technology systems. This role provides hands‑on leadership for privacy risk management, regulatory compliance activities, privacy assessments, incident response, and cross‑functional collaboration to ensure privacy requirements are embedded throughout the product lifecycle.
Own and continuously mature the Privacy by Design framework, integrating privacy requirements into product development processes, governance activities, and lifecycle management practices.
Lead cross‑functional teams through Privacy by Design activities, identifying privacy risks and defining appropriate technical and procedural controls for products, systems, and third‑party integrations.
Conduct data privacy assessments, including Data Protection Impact Assessments (DPIAs), and drive mitigation planning and implementation.
Develop and maintain privacy documentation, data maps, compliance evidence, policies, procedures, and regulatory submission deliverables.
Lead privacy investigations and corrective actions, coordinating remediation activities and supporting privacy incident response processes.
Partner with product security engineering teams to align privacy requirements with threat assessments, security risk management activities, and product assurance objectives.
Provide privacy consultation and subject matter expertise to engineering, legal, regulatory, and business stakeholders on product‑specific privacy matters.
Mentor privacy and security professionals and contribute to privacy awareness, training, metrics, and continuous improvement initiatives.
Bachelor’s degree with 7 years of relevant experience OR a Master’s degree with 5 years of relevant experience OR a PhD with 3 years of relevant experience
Extensive experience with Privacy by Design principles and integrating privacy into product development lifecycles.
Privacy and security incident management experience
Cybersecurity / Information Security and/or IT background, including understanding of data protection practices, risk management processes, cybersecurity principles, and incident response methodologies.
Expertise in global privacy laws including HIPAA and GDPR.
Experience in the healthcare industry or another heavily regulated industry.
CIPP, CHPC, or similar certification, or proven experience and/or formal education in data privacy and compliance.
Understanding of medical device regulations and standards (e.g., FDA pre‑and post‑market guidance on cybersecurity for medical device manufacturers, ISO 13485, ISO 81001‑5‑1).
For Baccalaureate degrees earned outside of the United States, a degree that satisfies the requirements of 8 C.F.R. § 214.