Stand out for this role — generate a tailored resume and cover letter in about a minute.
Medtronic, a global leader in medical technologies, is seeking a Senior Product Security Engineer for Post Market Surveillance. You will own vulnerability surveillance, field event assessment, security risk analysis, and post-market compliance across fielded devices and systems.
In this role you will partner with Risk Management and Systems Engineering to update threat models and residual risk, support security operations, and assist with regulatory activities and customer inquiries.
We anticipate the application window for this opening will close on - 29 Sep 2026
Careers that change lives start here. Medtronic is a global leader in healthcare technology with a Mission to alleviate pain, restore health, and extend life. Our 95,000 employees work across more than 150 countries to put patients first - developing innovative medical technologies that improve the lives of 72+ million patients each year. Your unique talents will help shape the future of healthcare while building a career grounded in purpose, growth, and impact.
The Neuromodulation and Pelvic Health R&D organizations, bring together a large set of Medtronic's Neurosciences therapies and their project teams to employ the full breadth of our talent, technologies, products, services, and solutions to address the needs of customers and patients across the globe. These operating units offer devices and therapies to treat chronic pain, movement disorders, overactive bladder, non-obstructive urinary retention, and much more.
The Senior Product Security Engineer - Post Market Surveillance leads cybersecurity activities for fielded medical devices and supporting systems. The role owns vulnerability surveillance, field security event assessment, security impact and risk analysis, post-market compliance, security operations support, and issue disposition through closure.
Vulnerability, Field Event & Security Impact Management
Monitor and assess vulnerability signals, field complaints, anomalous behavior, and suspected security events affecting released products.
Determine applicability, exploitability, severity, product impact, and required escalation; coordinate investigation, remediation, and disposition.
Partner with Risk Management and Systems Engineering to update Security Risk Analysis, threat models, hazard analyses, and residual-risk assessments.
Security Operations & Product Security Assets
Maintain visibility of security assets across fielded products, including keys, certificates, credentials, trust anchors, and signing infrastructure.
Support secure provisioning, certificate/key distribution, rotation, revocation, and retirement with manufacturing and operations teams.
Maintain Defense-in-Depth, Security-by-Design, security requirements, and SBOM expectations throughout the post-market lifecycle.
Regulatory, Standards & Customer Compliance
Assess evolving FDA, EU MDR, China and other cybersecurity requirements and support fielded-product recertification and remediation.
Map cybersecurity standards and best practices into internal processes and represent Product Security in standards and technical forums.
Support HCP/customer security and privacy questionnaires, onboarding, and automation of recurring assurance activities.
Audit, FCA & CAPA
Represent Product Security during regulatory audits, FCA, CAPA, quality reviews, and risk-management boards.
Support root-cause analysis, corrective actions, effectiveness verification, and closure.
The above statements are intended to describe the general nature and level of work being performed by employees assigned to this position, but they are not an exhaustive list of all the required responsibilities and skills of this position.
The physical demands described within the Responsibilities section of this job description are representative of those that must be met by an employee to successfully perform the essential functions of this job. Reasonable accommodations may be made to ena