Senior Product Security Engineer
Medtronic
At Medtronic you can begin a life-long career of exploration and innovation, while helping champion healthcare access and equity for all. You’ll lead with purpose, breaking down barriers to innovation in a more connected, compassionate world.
A Day in the Life
We are seeking a highly skilled and experienced Senior Mobile Application Security Engineer to lead the security efforts for our mobile platforms (iOS and Android). You will be responsible for identifying vulnerabilities, implementing security best practices, and working closely with development teams to ensure secure mobile application design and deployment.Responsibilities may include the following and other duties may be assigned
- Conduct security assessments and code reviews of mobile applications (iOS and Android).
- Perform in-depth security assessments of mobile applications using static and dynamic analysis tools.
- Perform threat modeling and risk assessments for mobile app features and architecture.
- Integrate security tools and processes into the CI/CD pipeline for mobile development.
- Deep understanding of OWASP Mobile Top 10 and mobile attack vectors.
- Collaborate with developers to remediate vulnerabilities and implement secure coding practices.
- Lead penetration testing efforts and coordinate with third-party security vendors.
- Expert knowledge of iOS and Android security architectures and frameworks
- Proficiency in mobile security testing tools (OWASP ZAP, Burp Suite, MobSF, etc.)
- Strong understanding of mobile apps reverse engineering and binary analysis
- Monitor and respond to mobile security incidents and vulnerabilities (e.g., OWASP MASVS, CVEs).
- Stay updated on the latest mobile security threats, tools, and trends.
- Develop and maintain mobile security policies, standards, and guidelines.
- Mentor junior security engineers and provide technical leadership.
- Participate in incident response activities for mobile security events.
- Leads or participates in security architecture and design review meetings.
Required Knowledge and Experience
- An undergraduate (bachelors) or graduate degree in computer science, computer engineering, electrical engineering, or similar discipline.
- Experience in embedded devices vulnerability assessment, especially medical devices and Threat Modelling and risk scoring
- Formal education in cybersecurity and information assurance.
- Minimum 7-year experience & 4 years of technical, cybersecurity-related experience,
- Experience in analyzing security posture and vulnerability assessment.
- experience in penetration testing, fuzz testing of Web, enterprise cloud and Desktop solutions, (Black box, gray box and Whitebox testing)
- Demonstrated understanding of information security practices, risk management processes, cybersecurity principles, and incident response methodologies.
Nice to Have:
- Proficiency in mobile development languages (Swift, Objective-C, Java, Kotlin)
- Security Certifications (i.e. CEH, CISA, CISM, Security+, GSEC, OSCP, etc.)
- Familiarity of embedded environments, vulnerability scanning tools, and common attack routes
- Strong technical and troubleshooting skills.
- Capability to research and evaluate emerging technologies.
- Innovative thinker with the ability to think outside of the current norms and processes.
- Demonstrated ability to be flexible.
- Excellent written and verbal communication skills
- Demonstrated ability to develop and grow productive, trusting, and open relationships with a wide variety of constituencies.
- Demonstrated leadership and teamwork skills.
- Demonstrated ability to communicate complexity in a clear manner.
- Demonstrated experience interfacing with customers and other external stakeholders regarding cybersecurity system design and behavior.
- Demonstrated strong analytical, critical thinking skills.
Physical Job Requirements
The above statements are intended to describe the general nature and level of work being performed by employees assigned to this position, but they are not an exhaustive list of all the required responsibilities and skills of this position.
Benefits & Compensation
Medtronic offers a competitive Salary and flexible Benefits Package
A commitment to our employees lives at the core of our values. We recognize their contributions. They share in the success they help to create. We offer a wide range of benefits, resources, and competitive compensation plans designed to support you at every career and life stage.
This position is eligible for a short-term incentive called the Medtronic Incentive Plan (MIP).
About Medtronic
We lead global healthcare technology and boldly attack the most challenging health problems facing humanity by searching out and finding solutions.
Our Mission — to alleviate pain, restore health, and extend life — unites a global team of 95,000+ passionate people.
We are engineers at heart— putting ambitious ideas to work to generate real solutions for real people. From the R&D lab, to the factory floor, to the conference room, every one of us experiments, creates, builds, improves and solves. We have the talent, diverse perspectives, and guts to engineer the extraordinary.
Learn more about our business, mission, and our commitment to diversity here