Principal Product Security Engineer – Architecture & Engineering (REMOTE)

Return to Search
Apply Now
  • Lansing, MI, 48911, US
  • Remote-US
  • United States of America-California-San Francisco
  • United States of America-Massachusetts-Boston
  • United States of America-New York-New York
  • United States of America-Texas-Austin
  • United States of America-Washington-Seattle
Job details
Work flexiblity: Remote Req ID: R534289 Employee type: Full Time Job category: Engineering Travel: 10% Relocation: No

Related content

Why join Stryker?

Looking for a place that values your unique talents? Discover Stryker's award-winning culture.

We are proud to offer you our total rewards package which includes bonuses, healthcare, insurance benefits, retirement programs, wellness programs, as well as service and performance awards – not to mention various social and recreational activities, all of which are location specific.

Job description

The Product Security Principal Architect is a valued professional within the Stryker organization. They work with product development team members during the digital systems development processes on effective security controls. Stryker has products that reside on bespoke embedded devices, applications on mobile devices (iOS, and Android) or personal computers, along with services deployed in the clouds (Azure, AWS, GCP). This person has the ability to shape the security of Stryker products before release to market, and the responsibility to guide teams to build Security by Default, enabling products to be resilient in the marketplace.

This role will help through consistent generation of threat models with risk scoring, identifying the effective security controls during requirements, refined during design, then applied at build and configuration, provide oversight through verification and validation. Once the product is on-market, this team also aids others with the security investigations and response, as needed throughout the product life.

What You Will Do:

 Technical Responsibilities:

  • Collaborate with product teams to assess security risks and drive design decisions for new and evolving products and related systems, ensuring secure by design.
  • Guide product development teams in completing threat models towards security as it relates to product risk.
  • Assemble Security requirements applicable to the new or evolving product under consideration.
  • Working with product teams to remediate issues or vulnerabilities found by security tooling or reports for Stryker’s variety of medical device technologies.
  • Support product security incident response (PSIRT) teams, when needed, so they can effectively address (contain or remediate) and then document security incidents.
  • Draft internal and external communications summarizing details concerning security concepts used in requirements, design, and build phases related to medical products and related systems.
  • Provide product security guidance to internal taskforce teams.

Knowledge and Capabilities:

  • Understanding of the current revisions from FDA, NIST, ISO, IEC on the related security topics.
  • Expertise in applying security control frameworks, threat modeling, and scoring the severity of security threats and vulnerabilities.
  • Experience analyzing and supporting enablement of security controls, along with designing secure products, as part of a broad eco-system (embedded devices + clouds + mobile devices) in the IoT ecosystems that healthcare providers need and expect to support safety.
  • Driven to stay up to date on vulnerabilities and exploits that may affect the Stryker eco-system across several areas of computing such as cloud, distributed applications, embedded systems, or IoT.

What You Will Need:

Basic Qualifications:

  • Bachelor's Degree in product security, computer science, mathematics, statistics, or related field
  • 8+ years of applicable (product) security work experience

Preferred Qualifications:

  • Master’s degree in security related discipline
  • Understands quality management systems in the healthcare, medical device, or industries that leverage cyber-physical systems.
  • Experience implementing secure technologies in embedded devices, clouds and mobile devices using secure controls, including but not limited to transport and communication protocols.
  • One or more active, industry recognized, and relevant cybersecurity certifications.


 

  • $129k - $286k salary plus bonus eligible + benefits. Actual minimum and maximum may vary based on location. Individual pay is based on skills, experience, and other relevant factors.

Health benefits include: Medical and prescription drug insurance, dental insurance, vision insurance, critical illness insurance, accident insurance, hospital indemnity insurance, personalized healthcare support, wellbeing program and tobacco cessation program. Financial benefits include: Health Savings Account (HSA), Flexible Spending Accounts (FSAs), 401(k) plan, Employee Stock Purchase Plan (ESPP), basic life and AD&D insurance, and short-term disability insurance. Stryker offers innovative products and services in MedSurg, Neurotechnology, Orthopaedics and Spine that help improve patient and healthcare outcomes. Alongside its customers around the world, Stryker impacts more than 150 million patients annually. Depending on customer requirements employees and new hires in sales and field roles that require access to customer accounts as a function of the job may be required to obtain various vaccinations as an essential function of their role. Apply Now
Globe Icon An icon representing a globe