Sr. Cybersecurity Engineer

Boston Scientific

Arden Hills (MN)

Hybrid

USD 85,000 - 162,000

Full time

3 days ago
Be an early applicant
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Benefits offered by this job

Hybrid work model
Relocation assistance

Job summary

Boston Scientific is seeking a Senior Cybersecurity Engineer with DevSecOps expertise to drive security across its product lifecycle, including IoT cloud integration. You will lead threat modeling, risk assessments, and embedding security into CI/CD processes while collaborating with Regulatory, IT, and Quality teams.

The role emphasizes compliance with FDA guidance and defense-in-depth practices within a regulated medical device context, with a hybrid/onsite work model in Maple Grove, MN.

Qualifications

  • Bachelor’s or master's degree in Cybersecurity, Computer Science, Computer Engineering, or related field.
  • 5+ years in cybersecurity engineering with product security, including IoT cloud relevance.
  • Knowledge of DevSecOps tools and security risk assessments.
  • Experience with NIST or similar cybersecurity frameworks and defense in depth.
  • Excellent written and verbal communication for cross-functional teams.

Responsibilities

  • Integrate security into product development lifecycle across multiple product lines.
  • Lead threat modeling and risk assessments for security strategies.
  • Embed security controls in CI/CD pipelines with collaboration across teams.
  • Automate vulnerability detection, secure coding, and patch management.
  • Maintain incident response plans and risk management documentation.

Skills

DevSecOps
Security design
Threat modeling
CI/CD security
Regulatory compliance

Education

Bachelor’s or Master’s degree in Cybersecurity

Tools

Azure
AWS
Yocto
Linux
Active Directory / SSO

Job description

Additional Location(s): N/A

Diversity - Innovation - Caring - Global Collaboration - Winning Spirit - High Performance

At Boston Scientific, we’ll give you the opportunity to harness all that’s within you by working in teams of diverse and high-performing employees, tackling some of the most important health industry challenges. With access to the latest tools, information and training, we’ll help you in advancing your skills and career. Here, you’ll be supported in progressing – whatever your ambitions.

About the role:

Boston Scientific is seeking a Senior Cybersecurity Engineer with a background in DevSecOps and the design, development, and testing of cybersecurity features and controls in a regulated industry. This individual will be responsible for driving the cybersecurity strategy and DevSecOps throughout the product lifecycle, ensuring compliance with relevant standards and regulations.

Be a part of the Interventional Cardiology team, one of Boston Scientific’s most product-diverse divisions, supporting R&D in the design of exciting products and business development activities.

Work Mode:

At Boston Scientific, we value collaboration. This role follows a hybrid or onsite work model, requiring employees to be in our Maple Grove (Arbor Lakes), MN office at least three days per week.

Relocation:

Relocation assistance may be available for select out-of-state candidates.

Your responsibilities will include:
  • Integrate security into the product development lifecycle of multiple product lines.
  • Foster a collaborative security culture from conception to decommission.
  • Collaborate with product development teams to embed security controls throughout the CI/CD pipeline.
  • Lead threat modeling using STRIDE and security risk assessments, identifying, and evaluating potential threats and safety issues.
  • Elicit and define product security needs and requirements; define product security requirements, design specifications, and verification and validation strategies.
  • Establish best practices and automate processes for vulnerability detection, secure coding, configuration management, and patching.
  • Implement risk mitigation strategies and maintain risk management documentation.
  • Oversee and enhance incident response plans and processes, ensuring rapid and effective resolution of security incidents.
  • Manage secrets, identity and access management to ensure least privilege access.
  • Stay current with emerging regulations and standards related to medical device security (e.g., FDA Premarket Guidance, Post-market Cybersecurity Guidance, TIR 57).
  • Collaborate closely with internal stakeholders (Software Development, Quality, Regulatory, IT) to align security goals and requirements.
  • Model resiliency and show leadership by presenting topics to the Security Champions program.
Required qualifications:
  • Bachelor’s or master’s degree in Cybersecurity, Computer Science, Computer Engineering, or a related field.
  • Mininum of 5 years of experience in cybersecurity engineering, with a recent focus on product security as it extends to the IoT cloud.
  • Knowledge of DevSecOps tools.
  • Proven experience in design and architecture reviews for complex, embedded medical devices or similar technologies.
  • Demonstrated history of creating and executing security risk assessments and mitigation strategies.
  • In-depth understanding of cybersecurity frameworks (e.g., NIST Cybersecurity Framework) including best practices for defense in depth.
  • Excellent written and verbal communication skills for interfacing technical teams, stakeholders, and executive leadership.
  • Ability to work collaboratively across multidisciplinary teams, bridging gaps between technical, regulatory, and business functions.
Preferred qualifications:
  • 4+ years of experience working in the medical device industry or a similarly regulated environment; security architecture or medical device administration experience in healthcare settings is also a plus.
  • Development experience in securing Yocto and desktop Linux, Windows IoT, or Android
  • Deep knowledge of the deployment environment for medical devices into health delivery organizations, including Active Directory (AD) or Single Sign On (SSO) integrations.
  • Hands-on experience with IoT cloud deployments such as Azure or AWS.
  • Experience writing code, with secure coding practices, vulnerability scanning tools, and penetration testing methodologies.
  • Knowledge of embedded systems security, network security, endpoint protections, wireless communications, network protocols, HSM and PKI.
  • Experience supporting VA Handbook 6500 compliance.
  • Relevant certifications (e.g., GIAC, ISSEP, ISSAP, CRISC) are a plus.
  • Experience with vulnerability and risk assessments including use of CVSS.

Requisition ID: 634840

Minimum Salary: $ 85000

Maximum Salary: $ 161500

The anticipated compensation listed above and the value of core and optional employee benefits offered by Boston Scientific (BSC) – see www.bscbenefitsconnect.com—will vary based on actual location of the position and other pertinent factors considered in determining actual compensation for the role. Compensation will be commensurate with demonstrable level of experience and training, pertinent education including licensure and certifications, among other relevant business or organizational needs. At BSC, it is not typical for an individual to be hired near the bottom or top of the anticipated salary range listed above.

Compensation for non-exempt (hourly), non-sales roles may also include variable compensation from time to time (e.g., any overtime and shift differential) and annual bonus target (subject to plan eligibility and other requirements).

Compensation for exempt, non-sales roles may also include variable compensation, i.e., annual bonus target and long-term incentives (subject to plan eligibility and other requirements).

For MA positions: It is unlawful to require or administer a lie detector test for employment. Violators are subject to criminal penalties and civil liability.

Boston Scientific transforms lives through innovative medical technologies that improve the health of patients around the world. As a global medical technology leader for more than 45 years, we advance science for life by providing a broad range of high-performance solutions that address unmet patient needs and reduce the cost of healthcare. Our portfolio of devices and therapies helps physicians diagnose and treat complex cardiovascular, respiratory, digestive, oncological, neurological and urological diseases and conditions. Learn more at www.bostonscientific.com and follow us on LinkedIn.

Boston Scientific Corporation has been and will continue to be an equal opportunity employer. To ensure full implementation of its equal employment policy, the Company will continue to take steps to assure that recruitment, hiring, assignment, promotion, compensation, and all other personnel decisions are made and administered without regard to race, religion, color, national origin, citizenship, sex, sexual orientation, gender identity, gender expression, veteran status, age, mental or physical disability, genetic information or any other protected class.

Please be advised that certain US based positions, including without limitation field sales and service positions that call on hospitals and/or health care centers, require acceptable proof of COVID-19 vaccination status. Candidates will be notified during the interview and selection process if the role(s) for which they have applied require proof of vaccination as a condition of employment. Boston Scientific continues to evaluate its policies and protocols regarding the COVID-19 vaccine and will comply with all applicable state and federal law and healthcare credentialing requirements. As employees of the Company, you will be expected to meet the ongoing requirements for your roles, including any new requirements, should the Company’s policies or protocols change with regard to COVID-19 vaccination.

Among other requirements, Boston Scientific maintains specific prohibited substance test requirements for safety-sensitive positions. This role is deemed safety-sensitive and, as such, candidates will be subject to a prohibited substance test as a requirement. The goal of the prohibited substance testing is to increase workplace safety in compliance with the applicable law.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Senior Software Test Engineer (Cybersecurity)
Senior Software Test Engineer (Cybersecurity)

Boston Scientific Gruppe • Maple Grove (MN)

Hybrid
USD 85,000 - 162,000
Software Engineer III
Software Engineer III

Boston Scientific • Marlboro (MA)

Hybrid
USD 82,000 - 156,000
Sr. R&D Compliance Engineer
Sr. R&D Compliance Engineer

Boston Scientific • Maple Grove (MN)

On-site
USD 85,000 - 162,000
Senior Software Test Engineer (Cybersecurity)
Senior Software Test Engineer (Cybersecurity)

Boston Scientific • Maple Grove (MN)

Hybrid
USD 85,000 - 162,000
Sr. R&D Compliance Engineer
Sr. R&D Compliance Engineer

Nalu Medical • Maple Grove (MN)

Hybrid
USD 85,000 - 162,000
Hybrid work model
Principal Software Engineer - Mobile Development
Principal Software Engineer - Mobile Development

Boston Scientific • Santa Clara (CA)

Hybrid
USD 107,000 - 203,000
Principal Medical Safety Specialist - CRMDx
Principal Medical Safety Specialist - CRMDx

Boston Scientific • Marlborough (MA)

Hybrid
USD 102,000 - 194,000
Hybrid work model
Data Engineering Intern
Data Engineering Intern

Boston Scientific • Maple Grove (MN)

Hybrid
USD 43,000 - 74,000
Relocation assistance
Hybrid work model
Housing assistance (eligibility)
Principal Systems Engineer - P5
Principal Systems Engineer - P5

Boston Scientific • Arden Hills (MN)

Hybrid
USD 102,100 - 194,000
Senior Design Quality Engineer - Electrophysiology
Senior Design Quality Engineer - Electrophysiology

Boston Scientific • Waltham (MA)

Hybrid
USD 89,000 - 170,000
Relocation assistance