8 days ago
Base Salary
$99k - $199k/yr
Responsibilities
- Lead cybersecurity architecture reviews and secure-by-design initiatives for connected and embedded medical devices.
- Design and evaluate secure boot, hardware roots of trust, device identity, code signing, certificate management, and secure firmware update mechanisms.
- Develop and review security controls in C/C++, Python, Shell, Linux-based systems, and embedded platforms.
- Assess firmware, operating systems, bootloaders, hardware platforms, cryptographic services, secure key storage, and provisioning processes.
- Conduct threat modeling, cybersecurity risk assessments, CVE and vulnerability analysis, SBOM review, and mitigation planning.
- Develop and execute security assessment plans, penetration testing and fuzz testing strategies, firmware analysis, and security validation.
- Support cybersecurity submissions, customer assessments, audits, regulatory activities, and compliance with cybersecurity requirements and standards.
- Provide technical leadership and mentoring while influencing engineering, quality, product management, regulatory, and executive stakeholders.
Requirements
- Bachelor's degree in Computer Engineering, Electrical Engineering, Computer Science, Software Engineering, Cybersecurity, or a related discipline.
- At least 8 years of experience in cybersecurity engineering, product security, embedded systems, or related fields.
- At least 5 years of hands-on experience securing embedded devices, firmware, medical devices, or IoT products.
- Strong knowledge of Secure Boot, Hardware Root of Trust, Code Signing, PKI and Certificate Management, Cryptographic Key Management, Firmware Authentication and Validation, and Vulnerability Assessment and Remediation.
- Experience with STRIDE and OWASP threat modeling, SBOM generation and analysis, CVE management, NVD scoring, penetration testing, security assessments, Linux administration, and embedded platforms.
- Programming experience in C/C++, Python, Shell scripting, or similar languages.
- Familiarity with ARM-based processors, embedded Linux, RTOS environments, and connected device architectures.
- Preferred experience includes medical devices or regulated industries, FDA Cybersecurity Guidance, IEC 62304, ISO 14971, ISO 27001, UL 2900, AAMI TIR57/TIR97, NIST Cybersecurity Framework, NIST SP 800-53, HIPAA, and GDPR.
- Preferred familiarity includes NXP i.MX platforms, Wind River/VxWorks, Secure Elements, TPM technologies, hardware security testing, fault injection, voltage glitching, side-channel analysis, and physical tampering assessments.
- Strong technical documentation and communication skills, including the ability to explain cybersecurity concepts to engineers, business leaders, customers, auditors, regulators, and executives.
Benefits
- Career development opportunities with an international company.
- Potential eligibility for free medical coverage through the Health Investment Plan PPO medical plan in the next calendar year.
- Retirement savings plan with a high employer contribution.
- Tuition reimbursement, the Freedom 2 Save student debt program, and the FreeU education benefit.
- Onsite position at Abbott's Tech Center in St. Paul, Minnesota.
About Abbott
Abbott is a NYSE‑listed healthcare company that develops diagnostics, medical devices, nutrition products, and branded generic medicines for clinicians and consumers. Founded in 1888 and headquartered in Abbott Park, Illinois, it sells products in more than 160 countries, including the FreeStyle Libre continuous glucose monitoring system. Revenue comes primarily from product sales to hospitals, clinics, and retail channels.
