Boston Scientific

Sr. Cybersecurity Engineer

Boston Scientific
Apply
11 days ago
Maple Grove, MN, USASenior
H1B sponsor

Base Salary

$85k - $162k/yr

Responsibilities

  • Integrate security into the product development lifecycle across multiple product lines.
  • Drive cybersecurity strategy and DevSecOps practices throughout the product lifecycle.
  • Embed security controls in CI/CD pipelines and automate vulnerability detection, secure coding, configuration management, and patching processes.
  • Lead STRIDE threat modeling and security risk assessments, including identification and evaluation of threats and safety issues.
  • Define product security requirements, design specifications, and verification and validation strategies.
  • Implement risk mitigation strategies and maintain risk management documentation.
  • Oversee and enhance incident response plans and processes.
  • Manage secrets, identity and access management, and least-privilege access.
  • Monitor and apply medical-device cybersecurity regulations and standards, including FDA guidance and TIR 57.
  • Collaborate with Software Development, Quality, Regulatory, and IT stakeholders to align security requirements.
  • Present security topics and provide leadership to the Security Champions program.

Requirements

  • Bachelor’s or master’s degree in Cybersecurity, Computer Science, Computer Engineering, or a related field.
  • At least 5 years of cybersecurity engineering experience with recent focus on product security extending to IoT cloud environments.
  • Knowledge of DevSecOps tools and experience with security design and architecture reviews for complex embedded medical devices or similar technologies.
  • Demonstrated experience creating and executing security risk assessments and mitigation strategies.
  • In-depth understanding of cybersecurity frameworks, including the NIST Cybersecurity Framework and defense-in-depth practices.
  • Preferred: 4 or more years in the medical-device industry or a similarly regulated environment, or security architecture or medical-device administration experience in healthcare settings.
  • Preferred: experience securing Yocto, desktop Linux, Windows IoT, or Android systems.
  • Preferred: experience with Active Directory or Single Sign-On integrations and IoT cloud deployments using Azure or AWS.
  • Preferred: coding experience, secure coding practices, vulnerability scanning, and penetration testing methodologies.
  • Preferred: knowledge of embedded systems security, network security, endpoint protection, wireless communications, network protocols, HSM, PKI, VA Handbook 6500 compliance, and CVSS.
  • Relevant GIAC, ISSEP, ISSAP, or CRISC certifications are preferred.
  • Strong written and verbal communication skills and ability to collaborate across technical, regulatory, business, and executive stakeholders.

Benefits

  • Hybrid or onsite work model requiring at least three days per week in the Maple Grove, Minnesota office.
  • Relocation assistance may be available for select out-of-state candidates.
  • Boston Scientific offers core and optional employee benefits, with eligibility varying by role and plan requirements.
  • Exempt non-sales roles may be eligible for annual bonus targets and long-term incentives, subject to plan eligibility and requirements.

Tech Stack

Categories

Boston Scientific

About Boston Scientific

10,000+ employees

Boston Scientific designs and manufactures implantable and minimally invasive medical devices used by physicians to diagnose and treat cardiovascular, endoscopic, urological, neurological, and other conditions. It sells these products and related therapies to hospitals and health systems worldwide through a direct sales model and distributors. Founded in 1979 and headquartered in Marlborough, Massachusetts, it is publicly traded on the NYSE (BSX) with offerings spanning stents, catheters, electrophysiology, and neuromodulation systems.

Contact me