Sr. Product Security Engineer - Cloud Digital Solutions
Medtronic
- Location
- Fridley, Minnesota, United States of America
- Work model
- On-Site
- Level
- Senior
- H-1B history
- 106 approvals (FY2023)
- Posted
- Sep 11, 2026
Skills
About this role
We anticipate the application window for this opening will close on - 18 Sep 2026 Careers that change lives start here. Medtronic is a global leader in healthcare technology with a Mission to alleviate pain, restore health, and extend life. Our 95,000 employees work across more than 150 countries to put patients first — developing innovative medical technologies that improve the lives of 72+ million patients each year. Your unique talents will help shape the future of healthcare while building a career grounded in purpose, growth, and impact. A Day in the Life The Neuromodulation and Pelvic Health R&D organizations, bring together a large set of Medtronic’s Neurosciences therapies and their project teams to employ the full breadth of our talent, technologies, products, services, and solutions to address the needs of customers and patients across the globe. These operating units offer devices and therapies to treat chronic pain, movement disorders, overactive bladder, non-obstructive urinary retention, and much more. The Senior Product Security Engineer – Cloud & Digital Solutions leads cybersecurity architecture for Digital Health Platforms, cloud services, web/mobile applications, APIs, remote monitoring, and digital ecosystems supporting connected medical devices.
Primary Responsibilities
Cloud & Digital Security Architecture Define Security-by-Design and Defense-in-Depth architecture for Digital Health Platforms, cloud-native services, web/mobile applications, APIs, and remote-monitoring solutions. Define security requirements for identity, authentication, authorization, secrets, encryption, data protection, network segmentation, logging, and service-to-service communication. Design secure interfaces between connected medical-device ecosystems and cloud/digital platforms. Threat Modeling & Security Risk Lead threat modeling, Security Risk Analysis, attack-surface analysis, and security requirements definition for cloud and digital solutions. Translate threats into architecture controls, security requirements, verification activities, and risk-control evidence. Maintain SBOM and software/component security requirements across cloud applications, services, containers, APIs, and third-party dependencies. Data, Provisioning & Connected Services Define security requirements for data-at-rest, data-in-transit, transient data, retention, access control, and privacy across digital-health workflows. Design secure identity, provisioning, certificate, credential, and secrets-management strategies for cloud-connected products and services. Support secure eFOTA orchestration, remote monitoring, device-service authentication, telemetry, and secure digital-service integration. Cloud Security Operations, Assurance & Compliance Define cloud security monitoring, logging, vulnerability management, configuration security, and DevSecOps requirements. Develop the application-security assurance roadmap and lead readiness, certification/attestation, and recertification activities for programs such as SOC 2, ISO/IEC 27001, HIPAA compliance, and other applicable security/privacy frameworks . Coordinate control implementation, evidence collection, gap remediation, audit support, and continuous compliance across engineering, IT, quality, privacy, and business stakeholders. Support regulatory submissions and alignment with medical-device cybersecurity, cloud-security, privacy, and digital-health requirements.
Required Qualifications
Bachelor’s degree in related field with 4 years of relevant experience OR masters degree in related field with 2 years of relevant experience (Computer Engineering, Electrical Engineering, Computer Science, Cybersecurity) Extensive experience in cloud security, application security, digital platforms, cybersecurity architecture, or regulated software development.
Preferred Qualifications
Strong knowledge of cloud-native security, IAM, APIs, PKI, encryption,