Our client is seeking a Product Security Engineer to support the security of physical, IoT, and embedded medical devices throughout the engineering and product development lifecycle. The role will focus on products and features built on embedded Linux, Windows, and RTOS-based platforms, as well as connected device technologies.
Working closely with R&D, software engineering, and cross-functional stakeholders, the Product Security Engineer will help identify and reduce security risks while supporting compliance with applicable industry standards and global regulatory requirements. This is a hands‑on engineering role involving threat modeling, vulnerability assessment and remediation, security risk assessments, secure design reviews, and implementation of security controls.
The successful candidate will bring a strong foundation in cybersecurity and embedded systems, a willingness to learn, and the ability to collaborate effectively with software and hardware engineering teams in an Agile development environment.
Key Responsibilities
- Support engineering teams in defining and implementing product security requirements in accordance with applicable industry standards and regulatory expectations.
- Contribute to security controls including encryption, authentication, audit logging, system hardening, Software Bills of Materials (SBOM), patch management, vulnerability monitoring, and endpoint protection.
- Help incorporate security requirements throughout the product development lifecycle.
- Support the selection and implementation of appropriate cryptographic algorithms, protocols, and modes.
- Assist with key management and secure key‑storage practices.
- Support certificate lifecycle management, including issuance, renewal, and revocation.
- Apply foundational knowledge of Public Key Infrastructure (PKI), certificate authorities, certificate chains, CRLs, and OCSP.
- Evaluate and support secure communications between devices, applications, networks, and cloud services.
- Assist with validating TLS/mTLS configurations and related security controls.
- Support security considerations for medical, proprietary, and device‑specific communication protocols.
- Support hardening of embedded Linux, Windows Embedded/IoT, and RTOS‑based platforms.
- Contribute to secure boot, firmware integrity, attack‑surface reduction, and other embedded security practices.
- Help identify and address security risks associated with physical, IoT, and connected devices.
- Participate in firmware and product security activities throughout the development lifecycle.
- Assist in identifying and addressing security risks within cloud‑connected device architectures and APIs.
- Evaluate authentication and authorization mechanisms.
- Support protection of sensitive data both in transit and at rest.
- Participate in product security risk assessments, threat modeling, security testing, and vulnerability remediation.
- Analyze security vulnerabilities and work with engineering teams to develop appropriate remediation strategies and compensating controls.
- Support security and hazard analysis activities as required.
- Participate in technical design reviews and code inspections.
- Provide security feedback to software engineers and R&D teams.
- Promote secure coding practices and security‑by‑design principles.
- Support vulnerability scanning, analysis, remediation, and ongoing monitoring activities.
- Participate in product security incident response activities as appropriate.