Senior Staff Product Security Engineer, Embedded (REMOTE)

    • Stryker
  • Portage, MI
  • Posted 13 days ago | Updated 10 hours ago

Overview

Remote
On Site
Hybrid
USD 112,000.00 - 239,000.00 per year
Full Time

Skills

Research and development
C++
Medical devices
Healthcare information technology
Professional development
Use cases
Embedded software
Project planning
Risk analysis
Risk management
Product design
Product development
Security controls
Software security
Hardening
Penetration testing
Vulnerability scanning
Design review
Code review
Security QA
Incident management
Security analysis
Threat modeling
Computer science
Software engineering
Electrical engineering
Embedded systems
Health care
TCP/IP
Wireless communication
3G
Embedded Linux
Logic analyzer
Collaboration
Research
Leadership
Management
Productivity
Cyber security
Software development methodology
Facets
Design
Software deployment
Marketing
Computer hardware
IMPACT
POC
Planning
Documentation
Legal
Sales
SAP BASIS
MDS
Operations support systems
WAR
IoT
FIPS
Encryption
Total productive maintenance
TLS
PKI
Communication
Ethernet
Bluetooth
C
Wireshark
Metasploit
Insurance
Finance

Job Details

Why engineering at Stryker?

At Stryker we are dedicated to improving lives, with a passion for researching and developing new medical device products. As an engineer at Stryker, you will be proud of the work that you will be doing, using cutting-edge technologies to make healthcare better. Here, you will work in a supportive culture with other incredibly talented and intelligent people, creating industry-leading medical technology products. You will also have growth opportunities as we have a culture that supports your personal and professional development.

Need another reason to apply? Check out these 8 reasons to join Stryker's engineering team:

We are proud to be named one of the World's Best Workplaces and a Best Workplace for Diversity by Fortune Magazine! Learn more about our award-winning organization by visiting stryker.com

Who We Want:
  • Dedicated achievers - People who thrive in a fast-paced environment and will stop at nothing to ensure a project is complete and meets regulations and expectations.
  • Curious learners - People who seek out cutting-edge research and information to expand and enhance their ability to be ready for what's next.
  • Self-directed initiators - People who take ownership of their work and need no prompting to drive productivity, change, and outcome and will stop and nothing to ensure a project is complete and meets regulations and expectations.
  • Collaborative partners - People who build and leverage cross-functional relationships to bring together ideas, information, use cases, and industry analyses to develop best practices.


What You Will Do:

Product Security is driven to make healthcare better by ensuring that Stryker designs, develops, and maintains industry leading cyber secure products for our customers. As a Senior Staff Product Security Engineer, you will improve the safety, integrity, and resilience of medical devices developed by the Acute Care business unit at Stryker Medical and their embedded software. You will participate in project planning, product cybersecurity risk analysis, and risk mitigation strategies. You will lead various product cybersecurity tasks and activities established by product design controls and SDLC procedures and you will be involved in all facets of the product development life cycle. The ideal candidate is excited to protect our customers and their patients through the design and implementation of effective security controls.

Key Responsibilities:
  • Understand the overall technical capabilities of our products, typical deployment scenarios, and drive platform security posture improvement.
  • Collaborate with product teams to create comprehensive product cybersecurity threat models. Guide security risk analysis including threat identification, severity scoring, and selection of appropriate controls to mitigate risks.
  • Work closely with cross-functional teams, including Quality, Regulatory, and Marketing in driving alignment around medical device cybersecurity standards and regulations.
  • Support all facets of product hardware and software security including system hardening, automated and manual penetration testing, vulnerability scanning, and issue remediation.
  • Identify product vulnerabilities through design review, code review, and security testing.
  • Lead and own vulnerability and incident response activities through assessing applicability, exploitability, and impact with product teams; developing POC exploits; and planning and executing mitigation and remediation to closure.
  • Leverage and implement DevSecOps to create efficiencies in managing security posture of our products.
  • Support cybersecurity documentation requests from legal and sales teams on an as-needed basis.
  • Lead product teams on conversations from a security PoV. Author and contribute artifacts such as Security Assessment, MDS2, Security Risk, Threat Model, SBOM, OSS etc.
  • Coordinate security war gaming activities with R&D product teams to enhance security practices and overall security posture throughout life of a product.


What You Will Need:

Basic Qualifications:
  • Bachelor's degree in Computer Science, Software Engineering, Electrical Engineering, Cybersecurity, or related discipline
  • Minimum 6 years of related experience
  • Demonstrated experience designing and securing embedded systems
  • Strong understanding of embedded/IOT security relevant technologies (e.g. secure boot, FIPS 140-2 encryption, anti-tamper, TPM, code signing, TLS, PKI)


Preferred Qualifications:
  • Experience working in medical device, health care, or other regulated industry.
  • Knowledge of communication protocols and technologies like TCP/IP, Ethernet, Wi-Fi, Bluetooth, 3G, UWB, and CAN.
  • Experience with Embedded Linux
  • Proficiency with C/C++
  • Familiarity with use of embedded security tools such as logic analyzers, protocol analyzers, disassemblers, Wireshark, Bus Pirate, ChipWhisperer, IDA, MetaSploit, etc.


  • $112k - $239k salary plus bonus eligible + benefits. Actual minimum and maximum may vary based on location. Individual pay is based on skills, experience, and other relevant factors.


About Stryker

Our benefits:

  • 12 paid holidays annually
  • Health benefits include: Medical and prescription drug insurance, dental insurance, vision insurance, critical illness insurance, accident insurance, hospital indemnity insurance, personalized healthcare support, wellbeing program and tobacco cessation program.
  • Financial benefits include Health Savings Account (HSA), Flexible Spending Accounts (FSAs), 401(k) plan, Employee Stock Purchase Plan (ESPP), basic life and AD&D insurance, and short-term disability insurance.

For a more detailed overview of our benefits or time off, please follow this link to learn more: US Stryker employee benefits

About Stryker
Stryker is a global leader in medical technologies and, together with its customers, is driven to make healthcare better. The company offers innovative products and services in MedSurg, Neurotechnology, Orthopaedics and Spine that help improve patient and healthcare outcomes. Alongside its customers around the world, Stryker impacts more than 130 million patients annually. More information is available at stryker.com.

Know someone at Stryker?
Be sure to have them submit you as a referral prior to applying for this position. Learn more about our employee referral program on our referral page

Stryker is driven to work together with our customers to make healthcare better. Employees and new hires in sales and field roles that require access to customer accounts as a function of the job may be required, depending on customer requirements, to obtain various vaccinations as an essential function of their role.