Medtronic logo

Principal Product Security Engineer

Medtronic
NewPosted today

LOCATION

Nanakramguda · Hybrid

EXPERIENCE

12 - 16 Years

TYPE

FullTime

SKILLS REQUIRED

API SecurityThreat ModelingSecure Coding PracticesIncident responseCVSS ScoringDependency-Track

Job description

Overview

As a Principal Product Security Engineer, you will lead product security vulnerability management activities, create and maintain software bills of materials (SBOMs), and support remediation and compliance efforts.

What you'll do

  • Contribute towards triaging all vulnerabilities, regardless of severity, across all SBOMs in the tool.
  • Generate SBOMs according to FDA requirements.
  • Include end-of-support and software level-of-support information for each component in SBOMs.
  • Continuously monitor, review, and triage newly identified vulnerabilities from SBOM monitoring activities.
  • Own and automate SBOM generation.
  • Analyze identified vulnerabilities and provide patching recommendations and other appropriate remediation actions.
  • Technically lead a group of engineers working on Product Security and vulnerabilities.
  • Propose solutions.
  • Create and maintain SBOMs for products and related software components.
  • Review, analyze, and triage vulnerabilities identified by SBOM scanning tools.
  • Partner with cross-functional teams to assess risk and prioritize remediation efforts.
  • Monitor and track vulnerability status to ensure timely and effective resolution.
  • Develop or use scripts to automate and improve vulnerability management processes.
  • Maintain thorough and accurate documentation of findings, actions taken, and outcomes.
  • Provide recommendations for component upgrades based on vulnerability findings and observed trends.

What you'll need

  • Bachelor’s degree in computer science, software engineering, or equivalent.
  • 12 to 16 years of relevant experience in product security, threat modelling, threat analysis, and CVSS scoring.
  • Understanding of product architecture, identification of security gaps, security-enabled technical proposals, and risk assessment.
  • Proficiency in Python or another scripting language.
  • Experience developing Python scripts and automation utilities to improve vulnerability management workflows.
  • Experience in vulnerability management.
  • Vulnerability assessment and triage experience.
  • Experience working in a regulated industry.
  • Familiarity with SBOM management tools such as Dependency-Track.
  • Medical device cybersecurity guidance documentation and audit readiness.

Nice to have

  • Experience in medical device cybersecurity or other regulated industries.
  • Familiarity with FDA Cybersecurity Guidance, IEC 62304, IEC 81001-5-1, or similar standards.
  • Experience supporting product security compliance initiatives.
  • Knowledge of software composition analysis (SCA) tools and open-source governance.

Details

  • Location: Nanakramguda, Hyderabad, India.

Read the full description and apply on the company’s own careers page.

Stay safe

Hiring on Abekus is free for applicants

We never charge a fee, and employers are prohibited from doing so. If a recruiter asks for payment, please report them right away.

Principal Product Security Engineer