Sr. Product Security Engineer

Pentangle Tech Services | P5 Group

Lake Forest (CA)

Hybrid

USD 130,000 - 170,000

Full time

3 hours ago
Be an early applicant
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Job summary

Pentangle Tech Services | P5 Group is seeking an experienced security developer to work with embedded software teams, ensuring security-by-design across electromechanical medical devices. You will define secure implementations, review findings, and guide cryptographic and PKI solutions within real-time environments.

The role emphasizes collaboration with product teams, security architects, and developers, supporting audits and continuous monitoring to uphold compliance and device safety.

Qualifications

  • Bachelor's degree or equivalent in CS/CE or related field.
  • 8+ years in software development or related fields.
  • 5+ years in product security design/development for embedded systems.
  • 3 years with C/C++, Python, Linux and RTOS security design.

Responsibilities

  • Define secure implementations aligned with the Application Security Program mandates.
  • Implement secure code solutions and guidelines meeting security and privacy requirements.
  • Govern security projects with scheduling, planning and prioritization.
  • Drive security solutions with development leads, security architects and product owners.
  • Review and mitigate SAST/DAST/SCA findings with developers on medical devices.
  • Support post-market analysis and continuous security monitoring.
  • Collaborate on SOC2 and HiTrust audits for products.

Skills

Security by design
Secure coding
Agile/SAFe
Threat modeling
OWASP Top10
Secure architecture

Education

Bachelor's degree in CS/CE
Equivalent experience

Tools

C/C++
Python
Linux
RTOS
PKI

Job description

Job Description


  • Work directly with embedded software developers in building a security-by-design mindset by defining implementations and coding inline with the Application Security Program mandates

  • Implement embedded secure code solutions, design patterns, and coding guidelines that meet security and privacy requirements defined in the security plans, risk assessments, policies, and procedures

  • Support security project governance through scheduling activities, planning and prioritization

  • Proactively drive security solutions implementation in-alignment with the development leads, security architects and product owner(s)

  • Drive feature implementations in line with the architecture via designs, coding, reviews and tests. Perform Proof of Concept (POC) activities as necessary

  • Review, Analyze and mitigate SAST, DAST, SCA and penetration test findings in collaboration with the developers for various electromechanical medical devices product lifecycles

  • Review current software security control measures and implement security enhancements across multiple medical devices

  • Participate in post-market product analysis to support vulnerability investigations as required as well as be engaged in continuous security monitoring

  • Work collaboratively with product teams on annual SOC2 and HiTrust audits for products.


What you will be doing


  • Work directly with embedded software developers in building a security-by-design mindset by defining implementations and coding inline with the Application Security Program mandates

  • Implement embedded secure code solutions, design patterns, and coding guidelines that meet security and privacy requirements defined in the security plans, risk assessments, policies, and procedures

  • Support security project governance through scheduling activities, planning and prioritization

  • Proactively drive security solutions implementation in-alignment with the development leads, security architects and product owner(s)

  • Drive feature implementations in line with the architecture via designs, coding, reviews and tests. Perform Proof of Concept (POC) activities as necessary

  • Review, Analyze and mitigate SAST, DAST, SCA and penetration test findings in collaboration with the developers for various electromechanical medical devices product lifecycles

  • Review current software security control measures and implement security enhancements across multiple medical devices

  • Participate in post-market product analysis to support vulnerability investigations as required as well as be engaged in continuous security monitoring

  • Work collaboratively with product teams on annual SOC2 and HiTrust audits for products.


What You Will Bring


  • Experienced security developer able to interpret and guide medical device software development teams on secure coding practices and application security test report interpretation for various coding languages and operating environments

  • Strong knowledge of secure software development lifecycle and practices including SAFe/ Agile methodologies for software development

  • Understanding of security by design principles and architecture level security concepts

  • Sound understanding and experience in implementing security technologies/techniques such as, Cryptographic Algorithms/Cipher Suites, Public key Infrastructure (PKI), Hardware/embedded authentication protocols, Secure Boot, and data-at-rest encryption methods

  • Experience implementing OWASP Top10 application security guidelines in embedded systems

  • Knowledge of embedded system architecture and security controls (e.g., firewall and border router configurations, wireless communication architectures, messaging authentication protocols

  • Experienced in generating, defining, and reviewing penetration test results through knowledge standard methodologies and tools including environmental configuration definition, security analysis, threat modeling, and system security audits

  • Expertise in designing secure networks, systems, and application architectures

  • Knowledge of current and emerging security threats and techniques for exploiting security vulnerabilities

  • Proficiency with industry standards and guidance such as IEC TR 80001, NIST 800-53, ISO IEC 27001 & 27002, etc.

  • Exposure to international privacy requirements & cross-industry trends

  • Certification in security such as CAP, CSSLP, or equivalent desired but not required.


Qualifications And Skills


  • Bachelor's degree in Computer Science, Computer Engineering, a related field or equivalent demonstrated experience and knowledge

  • Minimum 8+ years of experience in software development or related fields.

  • Minimum 5 years technical experience working with product security design/development for embedded systems

  • 3 years working with each of the following:

  • Experience with C/C++, Python, Linux and/or security design within real-time operating systems

  • Experience analyzing, interpreting, and mitigating security findings from multiple sources including SAST, DAST, SCA and penetration tests

  • Embedded data at rest security implementations including Code Signing, Secure boot, and flash encryption implementations

  • Embedded/IoT wired and wireless secure networking implementations within multiple layers of the OSI stack

  • IoT/Embedded PKI solutions and implementation.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Product Security Engineer
Product Security Engineer

Cypress HCM • Irvine (CA)

On-site
USD 130,000 - 180,000
Senior Embedded Software Engineer
Senior Embedded Software Engineer

INOVIO Pharmaceuticals, Inc. • San Diego (CA)

On-site
USD 140,000 - 180,000
Senior Software Engineer - Embedded Security
Senior Software Engineer - Embedded Security

Terumo Blood and Cell Technologies • Lakewood (CO)

Hybrid
USD 140,000 - 190,000
Senior Product Security Consultant
Senior Product Security Consultant

Zappsec Inc. • Tewksbury (MA)

On-site
USD 140,000 - 200,000
Senior Product Security Consultant
Senior Product Security Consultant

Zappsec • Tewksbury (MA), Northern (KY)

On-site
USD 150,000 - 190,000
Principal Embedded Software Engineer
Principal Embedded Software Engineer

Cutera, Inc. • Raleigh (NC)

On-site
USD 170,000 - 210,000
Embedded Security Architect (Lead)
Embedded Security Architect (Lead)

Ktek Talent Solutions • United States

Remote
USD 140,000 - 190,000
Product Security Engineer - Medical Device
Product Security Engineer - Medical Device

BioTalent • San Diego (CA)

On-site
USD 90,000 - 120,000
Principal Software system Engineer (Medical Device)
Principal Software system Engineer (Medical Device)

ITMC Systems, Inc • Raleigh (NC)

On-site
USD 100,000 - 130,000
Embedded Software Testing
Embedded Software Testing

TechDigital Group • Milpitas (CA)

On-site
USD 140,000 - 170,000