Demo

Embedded Product Security Engineer

Mason-Grey Corporation
Raynham, MA Full Time
POSTED ON 2/13/2025
AVAILABLE BEFORE 5/7/2025

Job Description

Job Description

POSITION :  Embedded Product Security Engineer (Medical Devices & Embedded Systems)

POSTING : 69182 (JNJNJP00069182)

LOCATION : REMOTE (Must Be US Based)

COMPENSATION : The hourly rate is a maximum range of $58.00 to $62.00. This will annualize to an estimated range of $116,000 to $124,000 based on 40 hour work weeks and 50 of 52 working weeks per year. OT is payable at 1.5X base rate and will add to the overall compensation based on actual hours worked.

JOB DESCRIPTION / EXPERIENCE :

The Product Security Engineer will be responsible for the implementation of client’s enterprise Product Security strategy and framework throughout the orthopedics portfolio. This includes identifying key strategy and goals, collaborating with internal organizations to enhance existing processes and policies, creating and communicating metrics to senior management, and driving overall awareness of the capability. Specific responsibilities include supporting the client's R&D teams throughout new product development phases, reviewing product security requirements, and recommending security design solutions. The role also involves assisting with the completion of Quality documentation, performing threat modeling, penetration testing, software architecture review, and providing design recommendations. The engineer will conduct code analysis and other security testing as needed. Additionally, post-market responsibilities for client marketed devices include monitoring for new vulnerabilities, assisting with patching and remediation plans, and responding to customer security questionnaires and reviewing security language within contractual agreements.

Key Responsibilities :

  • Support Global Product Security Framework : Contribute to and enhance the global security strategy, frameworks, and initiatives to ensure embedded medical devices are developed with the highest security standards.
  • Collaboration & Process Improvement : Partner with internal organizations (engineering, product management, compliance) to improve existing security processes and policies related to medical device development and post-market support.
  • Metrics & Reporting : Create, track, and present Product Security metrics to senior management, providing insights into security posture and progress towards goals.
  • Governance & Compliance : Help carry out the Product Security governance model for both pre-market and post-market devices, ensuring compliance with regulatory standards (FDA, 510k, etc.) and industry best practices.
  • Vulnerability Management & Remediation : Manage and prioritize vulnerabilities across the product portfolio, assisting engineering teams in developing and executing effective remediation plans.
  • Due Diligence & Threat Modeling : Conduct due diligence activities, threat modeling, and risk assessments for new and existing products to identify potential security gaps.
  • Secure Software Development : Provide recommendations on secure coding practices, review code, and advise engineering teams on securing embedded applications (e.g., C / C , C#).
  • Customer & Vendor Interactions : Respond to customer security questionnaires, contractual language requirements, and ensure compliance with relevant security standards.
  • Security Awareness & Communication : Lead and deliver Product Security awareness campaigns, training, and communications across the organization.
  • Post-Market Security Activities : Monitor and respond to new vulnerabilities in DePuy marketed devices, assist with patching and remediation efforts, and collaborate on customer security questionnaires and contractual obligations.

Qualifications :

  • Education : Minimum of a Bachelor's degree in Computer Science, Engineering, or a related field is required; MS or advanced degree is preferred.
  • Experience : A minimum of 6 years in security and / or embedded software engineering functions, with a focus on product security in regulated environments (medical devices is a plus).
  • Technical Skills :

    o In-depth knowledge of real-time operating systems (e.g., QNX, Linux, Windows Embedded) and hardening techniques.

    o Strong understanding of embedded systems security, including secure software development, secure coding practices, and vulnerability management.

    o Experience with vulnerability scanning, penetration testing, and risk assessment tools (CVSS, OWASP, etc.).

    o Proficiency in at least one programming language (e.g., C, C , C#) and experience with secure code reviews.

    o Knowledge of Software Bill of Materials (SBOM) and how it relates to security and compliance.

    Security & Regulatory Expertise :

    o Understanding of medical device security requirements, including FDA regulations, 510k submissions, and Quality Design Control processes.

    o Familiarity with threat modeling, risk management frameworks, and vulnerability management for medical devices.

    Communication & Leadership Skills :

    o Strong interpersonal and collaboration skills with the ability to communicate complex technical concepts to non-technical stakeholders.

    o Proven ability to influence cross-functional teams to drive security improvements and achieve desired outcomes.

    o Experience creating and presenting security metrics and reports to senior management.

    Certifications (preferred, not required) :

    o CISSP, CEH, MCSD, CSSLP, or similar security certifications.

    Additional Skills :

    o Familiarity with cloud-based IoT solutions is preferred.

    o Creative problem-solving skills with a customer-focused mindset (both internal and external).

    o A strategic thinker with strong attention to detail and the ability to align tactical initiatives with broader organizational goals.

    All candidates shall be legally authorized to work in the US and are subject to background screening, drug testing and verification of legal status in the United States using eVerify.

    Company Description

    The Mason-Grey Corporation provides engineering solutions and services to process industry clients in energy, metals, plastics, biotech, pharmaceutical, and other key process markets. Today Mason-Grey executes projects and provides services to the Fortune 500 and mid-tier companies from coast to coast. Mason-Grey employees live and work in support of our mission from Massachusetts to California. Mason-Grey is headquartered in Atlanta, Georgia.

    Company Description

    The Mason-Grey Corporation provides engineering solutions and services to process industry clients in energy, metals, plastics, biotech, pharmaceutical, and other key process markets. Today Mason-Grey executes projects and provides services to the Fortune 500 and mid-tier companies from coast to coast. Mason-Grey employees live and work in support of our mission from Massachusetts to California. Mason-Grey is headquartered in Atlanta, Georgia.

    Salary : $116,000 - $124,000

    If your compensation planning software is too rigid to deploy winning incentive strategies, it’s time to find an adaptable solution. Compensation Planning
    Enhance your organization's compensation strategy with salary data sets that HR and team managers can use to pay your staff right. Surveys & Data Sets

    What is the career path for a Embedded Product Security Engineer?

    Sign up to receive alerts about other jobs on the Embedded Product Security Engineer career path by checking the boxes next to the positions that interest you.
    Income Estimation: 
    $87,720 - $106,708
    Income Estimation: 
    $108,098 - $130,480
    Income Estimation: 
    $145,630 - $167,634
    Income Estimation: 
    $162,729 - $194,659
    Income Estimation: 
    $80,479 - $90,779
    Income Estimation: 
    $90,609 - $105,383
    Income Estimation: 
    $90,609 - $105,383
    Income Estimation: 
    $117,524 - $131,245
    Income Estimation: 
    $117,524 - $131,245
    Income Estimation: 
    $145,630 - $167,634
    View Core, Job Family, and Industry Job Skills and Competency Data for more than 15,000 Job Titles Skills Library

    Job openings at Mason-Grey Corporation

    Mason-Grey Corporation
    Hired Organization Address Irvine, CA Full Time
    POSITION: Regulatory Compliance Lead POSTING: 69404 (JNJNJP00069404) LOCATION: Client Site, Irvine, CA COMPENSATION: The...
    Mason-Grey Corporation
    Hired Organization Address Spring, PA Full Time
    Job Description Job Description POSITION : CAR-T Research Scientist POSTING : 69382 (JNJNJP00069382) LOCATION : Client S...
    Mason-Grey Corporation
    Hired Organization Address Titusville, NJ Full Time
    POSITION: PharmD Medical Information Specialist POSTING: 69379 (JNJNJP00069379) LOCATION: Client Site, Titusville NJ* (H...
    Mason-Grey Corporation
    Hired Organization Address Somerville, NJ Full Time
    Job Description Job Description POSITION : Data Scientist (R Shiny Developer) POSTING : 69315 (JNJNJP00069315) LOCATION ...

    Not the job you're looking for? Here are some other Embedded Product Security Engineer jobs in the Raynham, MA area that may be a better fit.

    Product Security Engineer (Medical Devices & Embedded Systems)

    Abacus Service Corporation, Raynham, MA

    AI Assistant is available now!

    Feel free to start your new journey!