Sr Product Security Engineer - Exempt

LanceSoft Inc

Mounds View, MN

JOB DETAILS
SALARY
$65–$70 Per Hour
SKILLS
Access Control, Best Practices, CISSP - Certified Information Systems Security Professional, Cardiology, Cloud Computing, CompTIA - Computing Technology Industry Association, CompTIA Security+, Computer Engineering, Computer Firmware, Computer Science, Computer Security, Cross-Functional, Embedded Systems, Establish Priorities, FDA (Food and Drug Administration), FDA Requirements, Healthcare, Healthcare Software, ISO (International Organization for Standardization), Information/Data Security (InfoSec), International Electro-Technical Commission (IEC), Internet Security, Medical Equipment, Medical Protocols, Mentoring, Product Engineering, Product Lifecycle, Product Strategy, Realtime Operating System, Regulatory Submissions, Research & Development (R&D), Risk Management, Security Architecture, Software Administration, Software Development Lifecycle (SDLC), System Integration (SI), Technical Leadership, Threat Modeling, Threat and risk analysis (TRA), U.S. National Institute of Standards and Technology (NIST)
LOCATION
Mounds View, MN
POSTED
8 days ago

Cardiac Ablation Solutions (CAS) is seeking a Senior Product Security Engineer to join our R&D organization and help secure cardiac ablation medical device solutions. This role focuses on cybersecurity for medical devices and embedded systems. It is not an IT security, compliance, or GRC-focused position. The ideal candidate will bring strong experience partnering with engineering teams to integrate cybersecurity into real-time systems, embedded firmware, connected devices, and other product security contexts.

The selected candidate will support the integration of advanced cybersecurity controls, identify and mitigate vulnerabilities, and contribute to initiatives that improve cyber resilience across the product lifecycle. This person will serve as a technical subject matter expert, mentor others, collaborate across functions, and help drive long-term improvements in product security posture.

Primary Responsibilities

  • Product Security - Implement security requirements across the medical device development lifecycle by partnering with cross-functional teams and applying best practices from design through deployment.
  • Risk Assessment - Conduct threat modeling and vulnerability assessments to identify, prioritize, and help mitigate security risks throughout the product lifecycle.
  • Security Architecture - Support the design and delivery of secure medical devices through implementation of capabilities such as secure boot, secure communications, data protection, software update mechanisms, system integration protections, and access controls.
  • Security Standards - Apply medical device cybersecurity standards and guidance, including NIST, OWASP, and IEC 81001-5-1, and partner with development teams to strengthen security practices.
  • Technical Leadership - Stay current on cybersecurity trends affecting medical devices and health software, share best practices, and help advance long-term product security strategy.

Minimum Qualifications

  • Bachelor’s degree in engineering, computer science, computer engineering, or a related technical field with 4 years of experience; or an advanced degree with 2 years of relevant experience.

Preferred Qualifications

  • Experience in embedded device security within a regulated industry.
  • Strong understanding of cybersecurity concepts and frameworks such as NIST and OWASP.
  • Working knowledge of secure software development lifecycle principles and security-by-design practices.
  • Experience collaborating with engineering teams to identify and address product security risks.
  • Familiarity with medical device cybersecurity standards and guidance, including IEC 81001-5-1, ISO 14971, and FDA premarket and post market cybersecurity guidance.
  • Experience supporting FDA and other regulatory cybersecurity submissions.
  • Experience with connected healthcare systems or cloud-connected medical devices.
  • Security certifications such as CompTIA Security+, CISSP, or similar.

Location

This exciting opportunity is based in Mounds View, MN, a vibrant community offering a great quality of life and a supportive environment for professionals. Join us and be a part of a team that is making a difference in healthcare technology.

About the Company

L

LanceSoft Inc

We are a $125 Million, NMSDC-certified Minority & Woman owned Workforce Solutions Company headquartered in the DC metro area with presence across US with global presence - Canada, Mexico, India, UK, Malaysia, Indonasia, Hongkong, Singapore, UAE. We are specialized in providing Workforce Solutions, SOW project delivery, Engineering Solutions, Creative Services. We currently support 100+ Fortune companies globally and across multiple industry segments. We are currently supporting several massive programs across industry segment nationally/globally (Intel, Ally, AMD, QUALCOMM, Morgan Stanley, Kraft/ Mondelez, MNP, Amdocs, Dell, SanDisk, Medtronic, Becton Dickinson, GE, Lockheed Martin, UTC, L-3 Communications, Caterpillar, BMW, Mercedes Benz, National Grid, Dominion, Energy Future Holdings, PSEG, 3M, Fidelity, Aetna, Humana, Johnson & Johnson, Pfizer, Merck etc). 

All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender, identity, national origin, disability, or protected veteran status.

COMPANY SIZE
2,000 to 2,499 employees
INDUSTRY
Staffing/Employment Agencies
FOUNDED
2000
WEBSITE
http://www.lancesoft.com/