Verified today
Principal Product Security Engineer
About the role
Medtronic seeks a Principal Product Security Engineer in Hyderabad to lead product security initiatives and automate Software Bill of Materials (SBOM) generation. The role involves triaging vulnerabilities, analyzing risks, and partnering with cross-functional teams to ensure compliance with FDA requirements and medical device standards. This full-time position requires extensive experience in threat modeling and vulnerability management within regulated industries.
What you’ll do
- Generate and maintain SBOMs compliant with FDA requirements
- Triage all vulnerabilities across SBOMs regardless of severity
- Analyze vulnerabilities and provide patching recommendations
- Automate SBOM generation and vulnerability management processes
- Partner with teams to assess risk and prioritize remediation
- Technically lead a group of engineers on product security tasks
- Monitor and track vulnerability status for timely resolution
- Maintain documentation of findings, actions, and outcomes
What you’ll bring
- Bachelor’s degree in computer science, software engineering, or equivalent
- 12 to 16 years of relevant experience in product security
- Expertise in threat modelling, threat analysis, and CVSS scoring
- Proficiency in Python or similar scripting languages for automation
- Experience with vulnerability assessment, triage, and management
- Familiarity with SBOM management tools like Dependency-Track
Nice to have
- Experience in medical device cybersecurity or other regulated industries
- Knowledge of FDA Cybersecurity Guidance and IEC 62304/81001-5-1 standards
- Understanding of software composition analysis (SCA) tools
- Ability to technically lead engineers and propose security solutions
Skills
Benefits
- Competitive salary and flexible benefits package
- Short-term incentive plan (MIP)
- Wide range of resources supporting career and life stages
Education
Bachelor’s degree in computer science software engineering or equivalent