Sr DevSecOps Engineer

Medtronic

Louisiana (MO)

On-site

USD 125,000 - 187,000

Full time

2 days ago
Be an early applicant
Application generator

Stand out for this role — generate a tailored resume and cover letter in about a minute.

Get past ATS filters

Benefits offered by this job

Health insurance
401(k) plan

Job summary

Medtronic is seeking a Sr DevSecOps Engineer to define and govern secure embedded software platform practices for regulated medical device programs. You will lead CI/CD automation, security of embedded Linux, and software supply chain controls across multiple products.

The role partners with OS, product security, quality, regulatory, and program teams to deliver secure, maintainable platform solutions and provide technical leadership for engineers and DevOps practitioners.

Qualifications

  • Experience with DevSecOps in regulated environments such as medical devices.
  • Strong knowledge of CI/CD, vulnerability management and software supply chain controls.
  • Experience with secure boot, firmware signing and embedded Linux security.

Responsibilities

  • Define and own the DevSecOps architecture and roadmap for embedded platforms.
  • Establish secure software supply chain practices and remediation workflows.
  • Develop reusable CI/CD templates and evidence capture for cybersecurity compliance.
  • Lead threat modeling and risk analysis for embedded components.
  • Collaborate with cross-functional teams to deliver secure platform solutions.

Tools

Yocto
Docker
Snyk
SonarQube
GitHub
GitLab
Bitbucket
Jira
Bamboo
Confluence

Job description

We anticipate the application window for this opening will close on - 29 Sep 2026

Careers that change lives start here. Medtronic is a global leader in healthcare technology with a Mission to alleviate pain, restore health, and extend life. Our 95,000 employees work across more than 150 countries to put patients first — developing innovative medical technologies that improve the lives of 72+ million patients each year. Your unique talents will help shape the future of healthcare while building a career grounded in purpose, growth, and impact.

A Day in the Life

The Sr DevSecOps Engineer defines, implements, and governs secure embedded software platform practices for regulated medical device programs. This role provides technical leadership across CI/CD automation, embedded Linux security, software supply chain controls, vulnerability management, cybersecurity risk analysis, and release evidence generation to support safe, secure, and compliant medical device development.

The Sr DevSecOps Engineer will join the Embedded OS Platforms and DevOps Team to implement secure embedded platform DevOps workflows for new and existing medical device development programs. The Embedded OS Platforms and DevOps Team delivers the software infrastructure and foundational system components that enable operation of product application software. This role is responsible for advancing reusable DevSecOps frameworks, secure CI/D pipelines and software supply chain practices, embedded Linux security capabilities, and cybersecurity lifecycle processes across multiple products.

The successful candidate will serve as a technical lead who partners with OS and application software developers, systems, product security, quality, regulatory, and program teams to deliver secure, maintainable, and compliant platform solutions.

Key Responsibilities

  • Define and own the DevSecOps architecture and roadmap for embedded capital equipment platforms, including secure CI/CD pipelines, build infrastructure, security automation, and release evidence.

  • Establish secure software supply chain practices, including SBOM generation, SOUP/OTS component tracking, license awareness, vulnerability monitoring, end-of-support tracking, and remediation workflows.

  • Develop reusable CI/CD templates and pipeline controls for static analysis, software composition analysis, unit test automation, artifact signing, provenance tracking, cybersecurity evidence capture, and release readiness.

  • Lead threat modeling and cybersecurity risk analysis for embedded platform components, including asset identification, attack surface analysis, exploitability assessment, security controls, and traceability to risk mitigations.

  • Drive CVE intake, enrichment, asset mapping, triage, risk scoring, remediation planning, validation, and reporting in partnership with Product Security, SWQA, Systems, and program teams.

  • Design and implement secure boot, firmware signing, cryptographic configuration, key/certificate lifecycle support, authenticated update mechanisms, and secure device communication patterns.

  • Define runtime security monitoring requirements and support post-market cybersecurity monitoring and vulnerability response workflows. Review reported anomalies, assess cybersecurity impact, and support incident-response activities as needed.

  • Support regulatory submissions and audits by ensuring cybersecurity, software lifecycle, and DevSecOps evidence is complete, traceable, reproducible, and aligned with internal quality system expectations.

  • Collaborate with external vendors and internal partners to evaluate security tooling, embedded Linux support models, vulnerability intelligence, penetration testing outputs, and long-term maintenance approaches.

  • Provide technical leadership and mentoring to software engineers, DevOps engineers, and platform teams on secure coding, build automation, vulnerability handling, and regulated software development practices.

  • Technologies & Tools

  • AMD Zynq and Zynq UltraScale+ SoCs, NVIDIA ORIN, SafeRTOS, FreeRTOS

  • Yocto-based embedded Linux package development

  • Embedded hypervisors, Linux device drivers, BSPs, and boot flows

  • Custom build systems and CI/CD pipelines

  • Docker, Snyk, SonarQube, and software composition analysis tools

  • Static analysis, software composition analysis, artifact signing, and vulnerability management tools

  • Python, Bash, and Go

  • Atlassian tools including Bitbucket, Jira, Bamboo, and Confluence

  • GitHub and GitLab

  • Networking security, secure boot, firmware signing, and secure update technologies

  • Preferred Qualifications

  • Hands-on experience with cloud infrastructure (AWS or similar) and modern DevOps practices.

  • Proficiency with infrastructure-as-code and secure CI/CD tooling.

  • Familiarity with monitoring, observability, and incident management.

  • Experience with security technologies and practices including certificates, secrets management, and compliance support.

  • Experience developing DevSecOps workflows in regulated safety-critical environments such as aerospace, medical, automotive, or industrial controls.

  • Understanding of FDA cybersecurity expectations, IEC 62304, ISO 14971, ISO 13485, SOUP/OTS software management, SBOM practices, and software lifecycle evidence generation.

  • Experience implementing security automation in CI/CD pipelines, including SAST, SCA, container scanning, artifact signing, build reproducibility, traceability, and vulnerability reporting.

  • Experience with threat modeling, vulnerability assessment, cybersecurity risk analysis, and secure-by-design architecture reviews.

  • Ability to collaborate across hardware, software, systems, product security, quality, regulatory, program management, and product management stakeholders.

  • Strong debugging, problem-solving, and root-cause analysis skills.

  • Strong technical communication skills with the ability to translate cybersecurity and DevSecOps risks into actionable engineering and leadership decisions.

  • TECHNICAL SPECIALIST CAREER STREAM: An individual contributor with responsibility in technical functions to advance existing technology or introduce new technology and therapies. Formulates, delivers, and manages projects assigned, and works with stakeholders to achieve desired results. May act as a mentor to colleagues or direct the work of other professionals. The majority of time is spent delivering R&D, systems, or initiatives related to new technologies or therapies from design to implementation while adhering to policies and using specialized knowledge and skills.

For Baccalaureate degrees earned outside of the United States, a degree that satisfies the requirements of 8 C.F.R. § 214.2(h)(4)(iii)(A) is required.

Physical Job Requirements

The above statements are intended to describe the general nature and level of work being performed by employees assigned to this position, but they are not an exhaustive list of all the required responsibilities and skills of this position.

The physical demands described within the Responsibilities section of this job description are representative of those that must be met by an employee to successfully perform the essential functions of this job. Reasonable accommodations may be made to enable individuals with disabilities to perform the essential functions. For Office Roles: While performing the duties of this job, the employee is regularly required to be independently mobile. The employee is also required to interact with a computer, and communicate with peers and co-workers. Contact your manager or local HR to understand the Work Conditions and Physical requirements that may be specific to each role.

U.S. Work Authorization & Sponsorship

At Medtronic, we are committed to fostering an environment where employees can thrive and make a meaningful impact. In alignment with our enterprise-wide workforce planning approach, U.S. work authorization sponsorship (H-1B, TN, J, etc.) is offered exclusively for Principal-level roles and above, where specialized expertise aligns with long-term business needs. Roles below the Principal level require candidates to possess unrestricted U.S. work authorization at the time of hire and for the duration of employment.

Recruitment Fraud Alert

We are aware of phishing scams targeting job seekers. Please keep the following in mind:

Medtronic will never ask for payment or sensitive personal information (such as bank account or Social Security details) during early stages of the hiring process. Any such requests are not legitimate.

If you receive a suspicious message claiming to be from Medtronic, do not respond, click links, or open attachments.

If you have any questions, concerns regarding the authenticity of a communication alleged to have been made by or on behalf of Medtronic, please contact us immediately at AskHR@medtronic.com.

Benefits & Compensation

Medtronic offers a competitive Salary and flexible Benefits Package
A commitment to our employees lives at the core of our values. We recognize their contributions. They share in the success they help to create. We offer a wide range of benefits, resources, and competitive compensation plans designed to support you at every career and life stage.

Salary ranges for U.S (excl. PR) locations (USD):$124,800.00 - $187,200.00

This position is eligible for a short-term incentive called the Medtronic Incentive Plan (MIP).

The base salary range is applicable across the United States, excluding Puerto Rico and specific locations in California. The offered rate complies with federal and local regulations and may vary based on factors such as experience, certification/education, market conditions, and location. Compensation and benefits information pertaining solely to candidates hired within the United States (local market compensation and benefits will apply for others).

The following benefits and additional compensation are available to those regular employees who work 20+ hours per week: Health, Dental and vision insurance,Health Savings Account,Healthcare Flexible Spending Account,Life insurance, Long-term disability leave,Dependent daycare spending account,Tuition assistance/reimbursement, andSimple Steps (global well-being program).

The following benefits and additional compensation are available to all regular employees:Incentive plans, 401(k) plan plus employer contribution and match,Short-term disability,Paid time off,Paid holidays,Employee Stock Purchase Plan,Employee Assistance Program,Non-qualified Retirement Plan Supplement (subject to IRS earning minimums), andCapital Accumulation Plan (available to Vice Presidents and above, or subject to IRS earning minimums).

Regular employees are those who are not temporary, such as interns. Temporary employees are eligible for paid sick time, as required under applicable state law, and the Employee Stock Purchase Plan. Please note some of the above benefits may not apply to workers in Puerto Rico.

Further details are available at the link below:

Medtronic benefits and compensation plans

It is the policy of Medtronic to provide equal employment opportunity (EEO) to all persons regardless of age, color, national origin, citizenship status, physical or mental disability, race, religion, creed, gender, sex, sexual orientation, gender identity and/or expression, genetic information, marital status, status with regard to public assistance, veteran status, or any other characteristic protected by federal, state or local law. In addition, Medtronic will provide reasonable accommodations for qualified individuals with disabilities.

If you are applying to perform work for Medtronic, Inc. ("Medtronic") in any position which will involve performing at least two (2) hours of work on average each week within the unincorporated areas of Los Angeles County, you can find here a list of all material job duties of the specific job position which Medtronic reasonably believes that criminal history may have a direct, adverse and negative relationship potentially resulting in the withdrawal of a conditional offer of employment. Medtronic will consider for employment qualified job applicants with arrest or conviction records in accordance with the Los Angeles County Fair Chance Ordinance for Employers and the California Fair Chance Act.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Principal Software Engineer - Embedded OS
Principal Software Engineer - Embedded OS

Cobioscience • Lafayette (CO), Northern (KY)

Hybrid
USD 153,000 - 229,000
Prin Software Engineer
Prin Software Engineer

Medtronic • Lafayette (CO)

On-site
USD 153,000 - 229,000
Software Engineering Mgr
Software Engineering Mgr

Medtronic • Lafayette (CO)

On-site
USD 150,000 - 226,000
Health, Dental and Vision
401(k) with employer match
Paid time off
+1
Senior Principal Cyber Security Specialist, Culture Lead
Senior Principal Cyber Security Specialist, Culture Lead

Medtronic • Mounds View (MN)

On-site
USD 170,400 - 255,600
Health, Dental and vision insurance
Health Savings Account
Tuition assistance
Sr. Clinical Quality Manager
Sr. Clinical Quality Manager

Medtronic • Lafayette (CO)

On-site
USD 162,000 - 244,000
Health insurance
Dental and vision insurance
401(k) plan
Manufacturing Engineer II - Automation & Equipment
Manufacturing Engineer II - Automation & Equipment

Medtronic • North Haven (CT)

On-site
USD 83,000 - 125,000
Health, Dental and Vision Insurance
401(k) with company match
Paid time off
+2
Sr Software Engineer
Sr Software Engineer

Medtronic • Minneapolis (MN)

On-site
USD 125,000 - 187,000
Health insurance
Dental insurance
Vision insurance
+2
Design Quality Engineer I
Design Quality Engineer I

BioCT Innovation Commons • North Haven (CT)

On-site
USD 66,000 - 100,000
Quality Systems Manager - Plymouth, MN
Quality Systems Manager - Plymouth, MN

Medtronic • Iowa (LA)

On-site
USD 120,000 - 180,000
Health insurance
401(k) plan with employer match
Paid time off
+1
Sr. Principal Regulatory Affairs Strategy Specialist
Sr. Principal Regulatory Affairs Strategy Specialist

Medtronic • Mounds View (MN)

On-site
USD 158,000 - 236,000