Jobs Companies Abbott Staff Product Security Engineer

Über diese Staff Product Security Engineer Stelle bei Abbott

Abbott · Vor Ort · United States - Minnesota - St. Paul
Abbott is a global healthcare leader that helps people live more fully at all stages of life. Our portfolio of life-changing technologies spans the spectrum of healthcare, with leading businesses and products in diagnostics, medical devices, nutritionals and branded generic medicines. Our 122,000 colleagues serve people in more than 160 countries.

     

JOB DESCRIPTION:

Working at Abbott

At Abbott, you can do work that matters, grow, and learn, care for yourself and your family, be your true self, and live a full life. You’ll also have access to:

  • Career development with an international company where you can grow the career you dream of.
  • Employees can qualify for free medical coverage in our Health Investment Plan (HIP) PPO medical plan in the next calendar year.
  • An excellent retirement savings plan with a high employer contribution
  • Tuition reimbursement, the Freedom 2 Save student debt program, and FreeU education benefit - an affordable and convenient path to getting a bachelor’s degree.
  • A company recognized as a great place to work in dozens of countries worldwide and named one of the most admired companies in the world by Fortune.
  • A company that is recognized as one of the best big companies to work for as well as the best place to work for diversity, working mothers, female executives, and scientists.

The Opportunity

At Abbott, we develop life-changing technologies that improve patient outcomes around the world. We are seeking a Senior Product Cybersecurity Engineer who combines strong technical expertise with excellent communication and collaboration skills to help secure next-generation connected medical devices.

This position is part of our EP division and will be located onsite at our Tech Center in St. Paul, MN.

In this role, you will serve as a cybersecurity leader across the product lifecycle, partnering with software, firmware, hardware, systems engineering, quality, regulatory, and product management teams to ensure security is designed into products from concept through deployment and sustainment.

The ideal candidate is a hands-on technical expert in embedded systems, firmware, hardware security, threat modeling, vulnerability management, and security architecture who can also effectively communicate cybersecurity risks, strategies, and compliance requirements to internal stakeholders, customers, auditors, and regulatory agencies.

What You’ll Work On

Cybersecurity Architecture & Secure Product Design

  • Lead cybersecurity architecture reviews and security-by-design initiatives for connected and embedded medical devices.
  • Drive design discussions and ensure security considerations are incorporated into product architecture, development, and deployment decisions.
  • Design and evaluate secure boot architectures, hardware roots of trust, device identity frameworks, code-signing solutions, certificate management, and secure firmware update mechanisms.
  • Create, review, and maintain security architecture documentation, design specifications, and cybersecurity reports.
  • Collaborate with cross-functional engineering teams to implement secure design practices across software, firmware, hardware, and cloud-connected systems.

Embedded Firmware & Hardware Security

  • Develop and review security controls implemented in C/C++, Python, Linux-based systems, and embedded platforms.
  • Assess embedded firmware, operating systems, bootloaders, and hardware platforms for potential security weaknesses.
  • Review and validate:
    • Secure boot implementations
    • Firmware authentication and validation
    • Cryptographic services
    • PKI and certificate management
    • Secure key storage
    • Secure provisioning processes
  • Evaluate hardware security controls, including:
    • Trusted Platform Modules (TPMs)
    • Secure Elements
    • Hardware Security Modules (HSMs)
    • Trusted Execution Environments (TEEs)
    • JTAG/SWD protection
    • Anti-tamper technologies

Threat Modeling & Risk Management

  • Conduct threat modeling using STRIDE, OWASP, Attack Trees, and similar methodologies.
  • Identify threats and vulnerabilities impacting patient safety, product integrity, and data protection.
  • Perform cybersecurity risk assessments and document risks in accordance with company and regulatory requirements.
  • Assess CVEs, evaluate product exposure, and recommend mitigation strategies.
  • Maintain and review Software Bills of Materials (SBOMs) and support vulnerability management processes.

Security Testing & Validation

  • Develop and execute cybersecurity assessment plans and security test strategies.
  • Support or coordinate penetration testing, fuzz testing, firmware analysis, and vulnerability assessments.
  • Review internal and third-party security findings and drive remediation efforts.
  • Define security acceptance criteria and support secure product releases.
  • Validate compliance with established cybersecurity requirements and standards.

Regulatory, Customer & External Engagement

  • Partner with Regulatory Affairs, Quality, and Product Security teams to support cybersecurity submissions and compliance activities.
  • Prepare and present cybersecurity documentation for customers, auditors, and regulatory agencies.
  • Serve as a cybersecurity subject matter expert during customer discussions, security assessments, and audits.
  • Clearly communicate technical risks, mitigation strategies, and compliance status to both technical and non-technical audiences.
  • Support responses to customer cybersecurity questionnaires and security requirements.

Leadership & Collaboration

  • Provide technical leadership and mentoring to engineering teams.
  • Influence stakeholders across engineering, quality, product management, regulatory, and executive leadership functions.
  • Drive continuous improvement of cybersecurity processes, assessment methodologies, and engineering practices.
  • Foster a culture of collaboration, accountability, and secure product development.

Required Qualifications

  • Bachelor's degree in Computer Engineering, Electrical Engineering, Computer Science, Software Engineering, Cybersecurity, or related discipline.
  • 8+ years of experience in cybersecurity engineering, product security, embedded systems, or related fields.
  • 5+ years of hands-on experience securing embedded devices, firmware, medical devices, or IoT products.
  • Strong knowledge of:
    • Secure Boot
    • Hardware Root of Trust
    • Code Signing
    • PKI and Certificate Management
    • Cryptographic Key Management
    • Firmware Authentication and Validation
    • Vulnerability Assessment and Remediation
  • Experience with:
    • Threat Modeling (STRIDE, OWASP)
    • SBOM generation and analysis
    • CVE management and NVD scoring
    • Penetration testing and security assessments
    • Linux administration and embedded platforms
  • Programming experience in C/C++, Python, Shell scripting, or similar languages.
  • Familiarity with ARM-based processors, embedded Linux, RTOS environments, and connected device architectures.
  • Strong written communication and technical documentation skills.
  • Proven ability to explain complex cybersecurity concepts to engineers, business leaders, customers, and regulators.

Preferred Qualifications

  • Experience in medical devices, healthcare technology, or other highly regulated industries.
  • Knowledge of:
    • FDA Cybersecurity Guidance
    • IEC 62304
    • ISO 14971
    • ISO 27001
    • UL 2900
    • AAMI TIR57/TIR97
    • NIST Cybersecurity Framework
    • NIST SP 800-53
    • HIPAA and GDPR
  • Experience with NXP i.MX platforms, Wind River/VxWorks, Secure Elements, TPM technologies, and hardware security testing.
  • Familiarity with hardware attack techniques including fault injection, voltage glitching, side-channel analysis, and physical tampering assessments.
  • Experience interacting directly with customers, assessors, auditors, and regulatory agencies.

Success Profile

The ideal candidate is a technically strong cybersecurity engineer who can:

  • Architect and validate secure embedded systems.
  • Lead technical discussions and influence design decisions.
  • Translate cybersecurity risks into business and regulatory impacts.
  • Build trusted relationships with engineering teams, customers, and regulators.
  • Communicate confidently with audiences ranging from developers to executive leadership.

Apply Now

Learn more about our health and wellness benefits, which provide the security to help you and your family live full lives:  www.abbottbenefits.com

Follow your career aspirations to Abbott for diverse opportunities with a company that can help you build your future and live your best life. Abbott is an Equal Opportunity Employer, committed to employee diversity.

Connect with us at www.abbott.com, on Facebook at www.facebook.com/Abbott, and on Twitter @AbbottNews.

     

The base pay for this position is

$113,300.00 – $226,700.00

In specific locations, the pay range may vary from the range posted.

     

JOB FAMILY:

Product Development

     

DIVISION:

EP Electrophysiology

        

LOCATION:

United States > Minnesota > St. Paul > Tech Center : One St Jude Medical Drive

     

ADDITIONAL LOCATIONS:

     

WORK SHIFT:

Standard

     

TRAVEL:

Yes, 10 % of the Time

     

MEDICAL SURVEILLANCE:

No

     

SIGNIFICANT WORK ACTIVITIES:

Continuous sitting for prolonged periods (more than 2 consecutive hours in an 8 hour day), Continuous standing for prolonged periods (more than 2 consecutive hours in an 8 hour day), Keyboard use (greater or equal to 50% of the workday)

     

Abbott is an Equal Opportunity Employer of Minorities/Women/Individuals with Disabilities/Protected Veterans.

     

EEO is the Law link - English: http://webstorage.abbott.com/common/External/EEO_English.pdf

     

EEO is the Law link - Espanol: http://webstorage.abbott.com/common/External/EEO_Spanish.pdf
Bereit, sich bei Abbott zu bewerben?
Bei Abbott bewerben

Wie sich dieses Gehalt für Application Security vergleicht

Diese Stelle zahlt $170,000/yrim Einklang mit der üblichen Spanne für Application Security Stellen.

$115,660 dem Median $180,000 $262,300

Übliche Spanne $146,652–$227,500/yr, aus 248 vergleichbaren Application Security Anzeigen auf JobsRadar (Vergütung auf USD hochgerechnet). Gehaltseinblicke für Application Security ansehen →

Über Abbott

​ Abbott is about the power of health. For more than 135 years, Abbott has been helping people reach their potential — because better health allows people and communities to achieve more. With a diverse, global network serving customers in more than 160 countries, we create new solutions — across the spectrum of health, around the world, for all stages of life. Whether it’s next-generation diagnostics, life-changing devices, science-based nutrition, or novel reformulations, we are advancing some of the most innovative and revolutionary technologies in healthcare, helping people live their best lives through better health. The people of Abbott come to work each day with relentless energy, ent

Alle Jobs bei Abbott ansehen →

Ähnliche Jobs

PA
Senior Product Security Engineer
PayPal
⚡ Früh bewerben Austin, Texas, United States o... Hybrid $130,500–$193,600
● Neu 👁 Gesehen ✓ Beworben vor 1 Std.
PA
Sr. Staff Product Security Engineer- AI
PayPal
⚡ Früh bewerben Chicago, Illinois, United Stat... Hybrid $178,500–$265,100
● Neu 👁 Gesehen ✓ Beworben vor 1 Std.
Astranis
Senior Product Security Engineer (Applications)
Astranis
⚡ Früh bewerben San Francisco Hybrid $180,000–$285,000
● Neu 👁 Gesehen ✓ Beworben vor 10 Std.
Astranis
Product Security Engineer
Astranis
⚡ Früh bewerben San Francisco Vor Ort $130,000–$215,000
● Neu 👁 Gesehen ✓ Beworben vor 10 Std.
TT
Application Security Engineer II
The Trade Desk
⚡ Früh bewerben Bellevue; Ventura Vor Ort $103,200–$189,200
● Neu 👁 Gesehen ✓ Beworben vor 10 Std.
Intercom
Application Security Engineer
Intercom
⚡ Früh bewerben London, England Vor Ort
● Neu 👁 Gesehen ✓ Beworben vor 11 Std.
Intercom
Application Security Engineer
Intercom
⚡ Früh bewerben Dublin, Ireland Vor Ort
● Neu 👁 Gesehen ✓ Beworben vor 11 Std.
KnowBe4
Product Security Engineer (remote in Brazil)
KnowBe4
⚡ Früh bewerben Brazil Vor Ort
● Neu 👁 Gesehen ✓ Beworben vor 13 Std.
MrBeast
Staff Embedded Mobile & Product Security Engineer
MrBeast
⚡ Früh bewerben San Mateo, CA Vor Ort $170,000–$250,000
● Neu 👁 Gesehen ✓ Beworben vor 13 Std.

Registrieren für Vorschläge, die auf die von Ihnen geöffneten Jobs und gespeicherten Suchen zugeschnitten sind.

Mehr Jobs bei Abbott

Alle Jobs bei Abbott ansehen →

Jetzt bewerben
🤖

Moment — langsam

JobsRadar wurde für echte Menschen gebaut, die eine schwere Zeit bei der Jobsuche haben — nicht für automatisierte Anfragen. Sie klicken viel zu schnell und sind jetzt vorübergehend blockiert.

Kommen Sie später wieder. Wenn Sie wirklich auf Jobsuche sind, stehen wir hinter Ihnen — verhalten Sie sich einfach wie ein Mensch.

Catch your next role the second it’s posted.

Create a free account and we’ll watch the boards for you — the instant a job matches your search, it lands in your inbox or Telegram. No digging, no refreshing.

Create free account

Free forever · takes 30 seconds · already have one?

Verschaffe dir einen Vorsprung bei der Jobsuche.

Tritt unserem Telegram-Kanal bei für das, was dir hilft, die Stelle zu bekommen — Gehaltsbenchmarks, den wöchentlichen Marktpuls und neue Feature-Drops. Kein Spam, nur Signal.

Dem Kanal beitreten — kostenlos