Product Security Engineer - Embedded
Core
Supporting the security of physical, IoT, and embedded medical devices across the engineering lifecycle, ensuring compliance with global regulatory requirements.
Role type
Product Security Engineer (Embedded)
Builds
Secure medical devices, embedded Linux/Windows platforms, and cloud-connected components
Domain
Medical Technology / Embedded Systems / Cybersecurity
Deliverable
production ML models | product features | infrastructure
Required skills
Embedded Linux/Windows/RTOS security, C/C++ in embedded context, threat modeling, vulnerability scanning, cryptography & PKI, secure boot, firmware integrity, TLS/mTLS validation, cloud & API security, incident response, static code analysis
Preferred skills
Firmware image analysis, JTAG/SWD debugging, 510(k)/PMA regulatory knowledge, STRIDE/PASTA/NIST/OWASP methods, medical protocols (HL7/FHIR/Bluetooth LE), cybersecurity tooling (Black Duck/Coverity/Veracode/Nessus/Snyk/Metasploit), agile methodology
Technologies
Embedded Linux, Windows Embedded/IoT, RTOS, C, C++, TLS, mTLS, HL7, FHIR, Bluetooth LE, Black Duck, Coverity, Veracode, Nessus, Snyk, Metasploit
Responsibilities
Define and implement security requirements (encryption, authentication, SBOM), manage cryptographic algorithms and key lifecycle, evaluate secure communications, harden embedded platforms, assess cloud/API security risks, participate in design reviews and code inspections, execute security risk assessments and remediation, support incident response, contribute to security documentation, implement automated vulnerability testing
Seniority
Mid-level, hands-on IC
