Principal Product Security Engineer

 

Description:

As a Principal Product Security Engineer, Mobile Applications, you will serve as a technical leader helping software teams build secure mobile applications and connected digital health solutions that support life-changing medical technologies. You will work closely with software engineers, architects, quality, regulatory, and clinical partners to embed security across the software development lifecycle.

This role is ideal for someone who enjoys solving complex technical problems, influencing engineering direction, mentoring others, and translating security and regulatory requirements into practical, risk-based solutions. You will help ensure products are secure by design while balancing patient safety, usability, regulatory expectations, and engineering efficiency.

In this role, no two days are the same. You may be:
 

  • Leading threat models and cybersecurity risk assessments for new mobile applications and connected software systems
  • Reviewing application and system architecture and recommending security controls
  • Helping teams interpret results from security testing tools such as SAST, SCA, IAST, and DAST
  • Supporting regulatory submissions and responses to cybersecurity questions from regulators
  • Leading vulnerability investigations, remediation planning, and postmarket security activities
  • Driving improvements in security tooling, automation, and engineering processes
  • Mentoring Product Security Engineers and influencing secure development practices across teams

     

You will support multiple software development programs at once and serve as a trusted security leader throughout the product lifecycle, from concept through release and post market support.

Application and Product Security
 

  • Serve as a lead Product Security partner for engineering teams developing mobile apps, Software as a Medical Device, APIs, and cloud-connected software ecosystems
  • Lead secure design and architecture reviews
  • Advise on authentication, authorization, secure communications, API security, and application resilience
  • Guide teams on mobile security controls such as secure storage, certificate validation, runtime protections, and application hardening
  • Translate technical findings into practical, risk-based recommendations developers can act on

     

Risk Assessment and Lifecycle Security
 

  • Lead threat modeling, cybersecurity risk assessments, and vulnerability analysis
  • Define security requirements and support secure design decisions across the product lifecycle
  • Review penetration testing results and guide remediation efforts
  • Help ensure compliance with FDA guidance, IEC 81001-5-1, and evolving global cybersecurity standards and regulations

     

Regulatory and Compliance Support
 

  • Develop and maintain cybersecurity documentation for regulatory submissions, audits, and lifecycle activities, including:
  • Threat models
  • Security risk assessments
  • Security test plans and reports
  • Software Bills of Materials
  • Security architecture documentation
  • Vulnerability assessments and dispositions
  • Support responses to regulatory questions, customer security assessments, inspections, and audits

     

Incident Response and Continuous Improvement
 

  • Support Product Security Incident Response, Coordinated Vulnerability Disclosure, and postmarket vulnerability investigations
  • Assess exploitability, product impact, and remediation options to support risk-based decision making
  • Improve security workflows through automation, tooling, and process enhancements
  • Share knowledge, mentor less experienced engineers, and help teams strengthen secure software development practices

     

Key Skills & Experience
 

  • Application Security or Product Security experience
  • Mobile application security, including iOS, Android, .NET MAUI, or Xamarin
  • Secure Software Development Lifecycle
  • API security
  • OWASP Top 10 and OWASP MASVS
  • Threat modeling
  • SAST, SCA, IAST, DAST, and SBOM analysis
  • PKI, JWT, TLS, and secure communications
  • Python or PowerShell
  • Cloud-connected applications
  • Understanding of FDA cybersecurity guidance and IEC 81001-5-1
  • Experience in medical device cybersecurity, PSIRT, or coordinated vulnerability disclosure
  • Demonstrated ability to lead complex cross-functional cybersecurity activities, influence technical direction, and mentor other engineers

Organization Medtronic
Industry Engineering
Occupational Category Principal Product Security Engineer
Job Location Galway,Ireland
Shift Type Morning
Job Type Full Time
Gender No Preference
Career Level Intermediate
Experience 2 Years
Posted at 2026-08-20 8:06 pm
Expires on 2026-10-04