Arthrex, Inc. is a global medical device company and a leader in new product development and medical education. We are a privately held company that strives to accomplish our corporate mission of Helping Surgeons Treat Their Patients Better . We are committed to delivering uncompromising quality to the health care professionals who use our products, and ultimately, the millions of patients whose lives we impact.
Arthrex Benefits
Medical, Dental and Vision Insurance
Company-Provided Life Insurance
Voluntary Life Insurance
Flexible Spending Account (FSA)
Supplemental Insurance Plans (Accident, Cancer, Hospital, Critical Illness)
Matching 401(k) Retirement Plan
Annual Bonus
Wellness Incentive Program
Free, Onsite Medical Clinics
Free Lunch
Tuition Reimbursement Program
Trip of a Lifetime
Paid Parental Leave
Paid Time Off
Volunteer PTO
Employee Assistance Provider (EAP)
Please note, most benefits are for regular, full time employees.
All qualified applicants will receive consideration for employment without regard to race, color, religion, age, sex, sexual orientation, gender identity, national origin, disability, protected veteran status, or any other status protected by law.
Seeking a Engineer II - Product Security (SecOps - Cloud) with an interest in cybersecurity wanting a career that positively impacts people lives!!
Arthrex is a global medical device manufacturer, and our mission is Helping Surgeons Treat Their Patients Better . As our Engineer II - Product Security (SecOps - Cloud) you will support the security of Arthrex's Engineering software delivery environment by assisting in cloud security monitoring and triage, detection rule maintenance, tooling health, and pipeline and infrastructure security across AWS and Azure. This role works within the Global Product Security Engineering team and is well-suited for a security engineer with a foundation in cloud security and detection engineering who is building depth across the engineering security discipline. The ideal candidate would work from our Naples, FL, Boston, MA, or Santa Barbara, CA locations; however, we are open to full-time remote anywhere in the United States.
Essential Duties and Responsibilities:
* Cloud Security Monitoring & Detection - Monitor and triage security findings across Arthrex's Engineering environments using CSPM/CNAPP tooling (Wiz), AWS Security Hub, GuardDuty, and Azure Defender for Cloud; assess severity, distinguish true from false positives, and escalate confirmed findings per established procedures. Support the maintenance and tuning of detection rules, alert policies, and thresholds to reduce noise and improve signal fidelity, surfacing coverage gaps and recommending adjustments to senior team members.
* Tooling & Log Pipeline Health - Monitor the health of Engineering security tooling and log ingestion pipelines, ensuring log sources are active, complete, and flowing correctly. Verify that cloud security services are properly enabled and configured across all in-scope Engineering accounts and subscriptions; assist in maintaining security dashboards and alerting configurations; escalate coverage gaps or tool degradation as needed.
* Incident Response & Runbook Development - Contribute to the development and upkeep of incident response playbooks and triage runbooks for Engineering security events; participate in incident response activities including triage, containment support, evidence collection, and post-incident documentation.
* Compliance & Reporting - Support Engineering compliance activities related to SOC 2 and HIPAA audit readiness including evidence collection, control documentation, and gap tracking. Contribute to security reporting including finding summaries, remediation tracking, and tool health status for Engineering leadership and compliance stakeholders.
* Designs security architecture of components or functional systems and modifies existing designs to develop or improve products.
* Recommends alterations to development and design to improve the security of products and/or procedures.
* Contributes to a broader design perspective and considers how an application interacts with the underlying infrastructure or external resources.
* Conducts structured threat modeling (e.g., STRIDE) to identify potential threats and vulnerabilities, rates associated risks, and designs mitigations. Ensures outputs are documented in DHF and linked to security requirements and ISO14971 risk assessments.
* Maintains security relevant design history file documentation for assigned projects, adhering to Arthrex s ISO13485 based design control procedures.
* Determines the necessity of security testing and manages testing of assigned products.
* Provides Regulatory Affairs technical support for assigned projects in support of global product approvals.
* Supports Marketing and Product Management with technical support for training and marketing of assigned products.
* Partners with Software Engineering to design and develop components, processes, and training using Security-by-Design and Privacy-by-Design principles.
* Supports surgeon and distributor customers in the sales process by educating and demonstrating security-focused aspects of assigned products as needed.
* Collaborate with Legal, Compliance (Global Privacy and AI Governance), and IT to ensure products comply with applicable laws, regulations, and company policies.
* Reports on progress and status of assigned projects on a timely basis.
* May be required to travel; International travel may be required.
Knowledge:
* Frequent use and general knowledge of industry practices, techniques, and standards. General application of concepts and principles.
Skills:
* Cloud Threat Detection & Visibility(required): Hands-on experience monitoring and investigating security findings and incidents in a cloud environment, including working experience with AWS and/or Azure security services (Security Hub, GuardDuty, Azure Defender for Cloud), CSPM or CNAPP platforms, and security log management including log source validation, ingestion health monitoring, and coverage gap identification across AWS and Azure. Wiz experience is strongly preferred.
* Identity & Access Security(required): Experience with identity federation, lifecycle management, and RBAC using Okta and/or Microsoft Entra ID (SAML/SSO).
* Automation & Scripting(required): Scripting skills in Python, Bash, or PowerShell for automation and tooling.
* Experience with detection engineering fundamentals: alert tuning, false positive analysis, detection rule management, and runbook development preferred.
* Experience with Kubernetes, Argo, and Terraform security best practices preferred.
* AWS Security Specialty or Microsoft Azure Security Engineer (AZ-500) certification preferred.
* Knowledgeable of System and Software Development Processes and Lifecycles required.
* Knowledgeable of application security best practices required.
Education and Experience:
* 2+ years of related experience required; preferably in cloud security, security operations, or a related security engineering role.
* Bachelor degree required preferably in Engineering (Mechanical, Biomedical, Electrical or Software Engineering), Computer Science, Information Security, or Cybersecurity.