
Sr. Cybersecurity Engineer
Boston Scientific24 hours ago
Base Salary
$85k - $162k/yr
Responsibilities
- Integrate security controls into the product development lifecycle across multiple product lines.
- Lead STRIDE threat modeling, security risk assessments, risk mitigation, and risk-management documentation.
- Define product-security requirements, design specifications, and verification and validation strategies.
- Embed security controls throughout CI/CD pipelines and automate vulnerability detection, secure coding, configuration management, and patching processes.
- Oversee incident-response plans and processes for rapid resolution of security incidents.
- Manage secrets, identity and access management, and least-privilege access.
- Monitor emerging medical-device cybersecurity regulations and standards, including FDA guidance and TIR 57.
- Collaborate with Software Development, Quality, Regulatory, IT, and other stakeholders to align security requirements.
- Present security topics and promote the Security Champions program.
Requirements
- Bachelor’s or master’s degree in Cybersecurity, Computer Science, Computer Engineering, or a related field.
- At least 5 years of cybersecurity engineering experience, with recent product-security experience extending to IoT cloud environments.
- Knowledge of DevSecOps tools and cybersecurity frameworks, including the NIST Cybersecurity Framework and defense-in-depth practices.
- Experience with design and architecture reviews for complex embedded medical devices or similar technologies.
- Demonstrated experience creating and executing security risk assessments and mitigation strategies.
- Strong written and verbal communication skills and the ability to collaborate across technical, regulatory, business, and executive stakeholders.
- Preferred experience includes 4 or more years in the medical-device industry or a similarly regulated environment.
- Preferred development experience includes securing Yocto, desktop Linux, Windows IoT, or Android.
- Preferred knowledge includes Active Directory, Single Sign-On integrations, IoT cloud deployments, embedded and network security, endpoint protection, wireless communications, network protocols, HSM, and PKI.
- Preferred experience includes secure coding, vulnerability scanning, penetration-testing methodologies, VA Handbook 6500 compliance, CVSS-based assessments, and certifications such as GIAC, ISSEP, ISSAP, or CRISC.
Benefits
- Hybrid or onsite work model requiring at least three days per week in the Maple Grove, Minnesota office.
- Relocation assistance may be available for select out-of-state candidates.
- Employee benefits are available through Boston Scientific’s core and optional benefits programs.
- Variable compensation may include annual bonuses and long-term incentives for eligible exempt non-sales roles, or overtime and shift differentials for eligible non-exempt roles.
About Boston Scientific
Boston Scientific designs and manufactures implantable and minimally invasive medical devices used by physicians to diagnose and treat cardiovascular, endoscopic, urological, neurological, and other conditions. It sells these products and related therapies to hospitals and health systems worldwide through a direct sales model and distributors. Founded in 1979 and headquartered in Marlborough, Massachusetts, it is publicly traded on the NYSE (BSX) with offerings spanning stents, catheters, electrophysiology, and neuromodulation systems.