Principal Cyber Security Engineer
Additional Location: US-MN-Arden Hills
About The Role
Boston Scientific is seeking a Product Cybersecurity Engineer to operationalize and support various post-market cybersecurity activities within the Cardiac Rhythm Management (CRM) Research and Development (R&D) organization. Responsibilities include understanding and documenting the security posture of the company’s products, applications, and supporting infrastructure as well as compliance to the Quality systems and processes. The cybersecurity engineer will assist in implementing the individual CRM product cybersecurity plan. The ideal candidate must have a combination of strong communication and technical skills in order to implement and support the functional and technical aspects of the cybersecurity plan and work collaboratively with a team of internal staff and consultants to execute its components.
As part of the CRM R&D organization, the engineer will work alongside a team of analysts, IT/R&D engineers, and architects, supporting pre- and post-market product security activities, such as application security, vulnerability assessments, threat modeling, penetration testing, security analysis tools, hospital cybersecurity inquiries, and contract reviews, among other areas.
This role follows an onsite work model. Employees are expected to work from our Arden Hills, MN office at least four days per week. Boston Scientific will not offer sponsorship or take over sponsorship of an employment visa for this position. Relocation assistance is not available for this position.
Responsibilities
- Support and manage applicable tools for pre- and post-market security testing; support integration of the tools into the quality processes.
- Support post-market activities to identify known/unknown vulnerabilities associated with Boston Scientific’s products, including new/sustaining products, providing inputs/technical expertise to multiple teams to eliminate/mitigate identified cybersecurity risks.
- Monitor for change in security controls of products and update the product inventory and tracking database as needed and communicate to stakeholders.
- Support negotiations of hospital cybersecurity agreements by reviewing technical clauses with Legal and Research & Development subject matter experts.
- Support, as needed, security risk assessment and threat modeling services for CRM products businesses and product development life cycle.
- Support, as needed, application security reviews and vulnerability/penetration testing of Boston Scientific’s medical devices and software.
Qualifications
Required qualifications:
- Bachelor’s degree or higher.
- 10+ years in Research & Development and/or Information Technology experience, preferably in cybersecurity roles in medical device development or healthcare organizations.
- Drive for learning cybersecurity and a passion for securing products.
- Experience with vulnerability analysis of Windows and Linux operating systems as well as software.
- Experience across various OS platforms such as Windows, macOS, Linux, and Mobile (iOS, Android).
- General understanding of cybersecurity techniques, controls, and methodologies from frameworks such as NIST Special Publications and ISO standards.
Preferred Qualifications:
- Cybersecurity certifications (e.g., Network+, Security+, CSSLP, HCISPP, CEH, CISSP) a plus.
Pay
Minimum Salary: $102,100
Maximum Salary: $194,000
The anticipated compensation listed above and the value of core and optional employee benefits offered by Boston Scientific (BSC) — see www.bscbenefitsconnect.com — will vary based on actual location of the position and other pertinent factors considered in determining actual compensation for the role. Compensation will be commensurate with demonstrable level of experience and training, pertinent education including licensure and certifications, among other relevant business or organizational needs. At BSC, it is not typical for an individual to be hired near the bottom or top of the anticipated salary range listed above. Compensation for non-exempt (hourly), non-sales roles may also include variable compensation from time to time (e.g., any overtime and shift differential) and annual bonus target (subject to plan eligibility and other requirements). Compensation for exempt, non-sales roles may also include variable compensation, i.e., annual bonus target and long-term incentives (subject to plan eligibility and other requirements).