Hiring.Camp

Product Cybersecurity Engineer (Medical Devices)

Analogdevices

·

5 days ago

Salary
$135k – $202k
Location
US, MA, Wilmington, United States of America
Type
Full-time
Department
Engineering
Experience
7+ years
Education
PhD
Source
Workday

Description

About Analog Devices

Analog Devices, Inc. (NASDAQ: ADI) is a global semiconductor leader that bridges the physical and digital worlds to enable breakthroughs at the Intelligent Edge. ADI combines analog, digital, AI, and software technologies into solutions that combat climate change, reliably connect humans and the world, and help drive advancements in automation and robotics, mobility, healthcare, energy and data centers. With revenue of more than $11 billion in FY25, ADI ensures today's innovators stay Ahead of What's Possible. Learn more at www.analog.com and on LinkedIn and X.

          

Product Cybersecurity Engineer – Medical Devices

The Health Solutions Business Unit at Analog Devices is seeking a Product Cybersecurity Engineer to lead cybersecurity activities across the medical device product lifecycle. This role focuses on ensuring the security, privacy, and regulatory compliance of connected medical devices and Software as a Medical Device (SaMD) solutions. The candidate will collaborate with internal and external teams to drive cybersecurity risk management activities, secure product design, threat modeling, vulnerability management, and cybersecurity compliance throughout the product lifecycle, from concept and development through post-market support.

A significant portion of this role involves performing threat modeling and supporting cybersecurity risk management activities aligned with FDA cybersecurity guidance. The successful candidate will also contribute to cybersecurity documentation supporting FDA regulatory submissions, including 510(k) activities, while helping to establish and maintain post-market cybersecurity processes and secure development lifecycle (SDL) practices for regulated medical devices.

Key Responsibilities

  • Perform product security risk assessments and threat modeling for medical devices and SaMD platforms.
  • Lead cybersecurity risk management activities throughout the product lifecycle in alignment with FDA guidance and industry best practices.
  • Support cybersecurity documentation for FDA regulatory submissions, including cybersecurity risk management files, SBOM requirements, and other regulatory deliverables.
  • Conduct security architecture reviews and evaluate system designs against secure architecture principles, cybersecurity frameworks, and regulatory expectations.
  • Develop and maintain cybersecurity risk management documentation, vulnerability management processes, and incident response procedures.
  • Partner with internal and external teams to integrate secure-by-design principles into product development and lifecycle management activities.
  • Participate in secure development lifecycle (SDL/SSDLC) activities, including security requirements definition, design reviews, and cybersecurity verification activities.
  • Analyze results from vulnerability assessments, static analysis, dynamic analysis, penetration testing, and security scanning activities.
  • Support SBOM generation, third-party software assessments, and supply chain cybersecurity risk evaluations.
  • Investigate and support remediation of cybersecurity vulnerabilities affecting medical devices, software platforms, and connected product ecosystems.
  • Participate in vulnerability management, coordinated vulnerability disclosure, product security incident response, and post-market cybersecurity monitoring activities.
  • Support internal audits, external assessments, FDA inspections, and cybersecurity reviews related to medical device security and regulatory compliance.
  • Serve as a cybersecurity subject matter expert (SME) for cross-functional teams and product cybersecurity initiatives.

Requirements

  • Master’s or Ph.D. degree in Cybersecurity, Computer Science, Computer Engineering, Software Engineering, or a related technical discipline. Ph.D. preferred.
  • 7+ years of experience in cybersecurity, product security, software security, or related engineering roles.
  • Experience supporting cybersecurity activities for medical devices, connected healthcare products, or Software as a Medical Device (SaMD).
  • Demonstrated experience supporting FDA-regulated medical devices, including 510(k) submissions.
  • Demonstrated experience performing threat modeling for complex systems using methodologies such as STRIDE, attack trees, misuse cases, or equivalent frameworks.
  • Experience defining security controls, cybersecurity requirements, and mitigation strategies based on identified threats and risks.
  • Familiarity with cybersecurity standards and frameworks such as NIST Cybersecurity Framework, ISO 14971, IEC 62304, AAMI TIR57, and OWASP guidance.
  • Experience with vulnerability management, security testing, penetration testing, and remediation processes.
  • Familiarity with Software Bill of Materials (SBOM), third-party software risk management, and supply chain cybersecurity concepts.
  • Experience integrating cybersecurity requirements into Secure Development Lifecycle (SDL/SSDLC) processes.
  • Strong analytical, technical writing, communication, and cross-functional collaboration skills.

Additional Desired Skills and Qualifications

    • Experience with connected medical devices, SaMD, cloud-connected platforms, or AI/ML-enabled medical products.
    • Experience with post-market cybersecurity monitoring, vulnerability disclosure, and incident response processes.
    • Experience with connected medical devices, cloud-connected platforms, IoMT, or digital health solutions.
    • Professional certifications such as CISSP, CSSLP, HCISPP, GICSP, Security+, or equivalent.

    For positions requiring access to technical data, Analog Devices, Inc. may have to obtain export  licensing approval from the U.S. Department of Commerce - Bureau of Industry and Security and/or the U.S. Department of State - Directorate of Defense Trade Controls.  As such, applicants for this position – except US Citizens, US Permanent Residents, and protected individuals as defined by 8 U.S.C. 1324b(a)(3) – may have to go through an export licensing review process.

    Analog Devices is an equal opportunity employer. We foster a culture where everyone has an opportunity to succeed regardless of their race, color, religion, age, ancestry, national origin, social or ethnic origin, sex, sexual orientation, gender, gender identity, gender expression, marital status, pregnancy, parental status, disability, medical condition, genetic information, military or veteran status, union membership, and political affiliation, or any other legally protected group.

    EEO is the Law: Notice of Applicant Rights Under the Law.

    Job Req Type: Experienced

              

    Required Travel: Yes, 10% of the time

              

    Shift Type: 1st Shift/Days

    The expected wage range for a new hire into this position is $134,644 to $201,966.
    • Actual wage offered may vary depending on work location, experience, education, training, external market data, internal pay equity, or other bona fide factors.

    • This position qualifies for a discretionary performance-based bonus which is based on personal and company factors.

    • This position includes medical, vision and dental coverage, 401k, paid vacation, holidays, and sick time, and other benefits.

    Skills

    CybersecurityPenetration TestingFDARisk ManagementComplianceTechnical WritingCISSP

    Similar Jobs

    30

    Cybersecurity Product Engineer

    Leidos · 2682 Huntsville AL, United States of America

    1 week ago

    Cybersecurity Product Engineer

    Leidos · 2682 Huntsville AL, United States of America

    1 week ago

    Product Cybersecurity Engineer

    Maymobility · Remote, USA +1 · Remote

    1 week ago

    Product Cybersecurity Engineer

    Stoneridge Careers · Barneveld, Netherlands +1

    3 months ago

    Product Cybersecurity Engineer

    Stoneridge Careers · Novi, United States of America

    4 months ago

    Senior Product Cybersecurity Engineer

    General Motors · GM Global Technical Center - Cole Engineering Center Tower, United States of America +1 · Hybrid

    1 week ago

    Assoc. Director, Commercial Embedded Systems Product Cybersecurity Engineer (Onsite – Cedar Rapids, IA) Secret Clearance required

    RTX · US-IA-CEDAR RAPIDS-107 ~ 400 Collins Rd NE ~ BLDG 107, United States of America · Onsite

    1 month ago

    Cybersecurity Engineer, Product Security

    Chaosindustries · Washington, District of Columbia, United States +2

    1 month ago

    Cybersecurity Engineer, Product Security

    Chaosindustries · San Francisco, California, United States +2

    1 month ago

    Cybersecurity Engineer, Product Security

    Chaosindustries · El Segundo, California, United States +3

    1 month ago

    Product Cybersecurity Engineer / Specialist

    Agilent · UK-Harwell, United Kingdom +1 · Hybrid, Onsite

    1 month ago

    Cybersecurity Engineer, Product Security

    Chaosindustries · Washington, District of Columbia, United States +2

    1 month ago

    Cybersecurity Engineer, Product Security

    Chaosindustries · San Francisco, California, United States +2

    1 month ago

    Cybersecurity Engineer, Product Security

    Chaosindustries · Hawthorne, California, United States +3

    1 month ago

    Principal Product Cybersecurity Engineer (Boston Hybrid - 3 days on site)

    Haemonetics · Boston, MA, US, United States of America

    2 months ago

    Embedded Product Cybersecurity Engineer II (Onsite - Cedar Rapids, IA)

    RTX · US-IA-CEDAR RAPIDS-107 ~ 400 Collins Rd NE ~ BLDG 107, United States of America · Onsite

    2 months ago

    Embedded Product Cybersecurity Engineer – Embedded Software

    Geaerospace · Evendale, United States of America

    2 months ago

    Senior or Lead Product Cybersecurity Engineer

    Boeing · USA - Everett, WA, United States of America +1 · Onsite

    3 months ago

    Senior or Lead Product Cybersecurity Engineer

    Boeing · USA - Everett, WA, United States of America +1 · Onsite

    3 months ago

    Principal Engineer, Product Cybersecurity

    Baxter · ILRL12 - RL Technology II, United States of America +1

    3 months ago

    Sr. Product Cybersecurity Engineer - Vehicle Security

    General Motors · Milford Proving Ground - Bldg 24, United States of America +1 · Hybrid

    3 months ago

    Senior Cybersecurity Engineer - Product Cyber Security (Onsite)

    RTX · US-NY-BINGHAMTON-288 ~ 31 Lewis Rd ~ LEWIS, United States of America · Onsite

    3 months ago

    Staff Product Cybersecurity Engineer - Vehicle Security

    General Motors · GM Global Technical Center - Cole Engineering Center Podium, United States of America +1 · Hybrid

    5 months ago

    Product Compliance Engineer – Product Safety & Cybersecurity

    Ralliant · Fairport, NY, United States, US · Hybrid

    3 days ago

    Product Compliance Engineer – Product Safety & Cybersecurity

    Ralliant · Fairport, NY,US, US

    3 days ago

    Senior Software Quality Engineer, Product/Software Cybersecurity (Medical Device Software)

    Edwards · USA IRV-1921 East Alton Ave, United States of America

    1 month ago

    Cryptography Engineer - Product Security, Cybersecurity (Remote)

    Crowdstrike · USA TX Remote, United States of America · Remote

    2 months ago

    Cybersecurity Engineer II - Product Cyber Security (Onsite)

    RTX · US-NY-BINGHAMTON-288 ~ 31 Lewis Rd ~ LEWIS, United States of America · Onsite

    3 months ago

    Specialist Product Design Verification Software Engineer Cybersecurity

    Solventum · US, Texas, San Antonio, United States of America · Hybrid

    4 months ago

    Cybersecurity Product Engineering Team Leader

    Thales · Tubize, Belgium · Hybrid

    1 month ago