Senior Product Security Engineer - Vulnerability Management
Full-time AssociateJob Overview
Primary Function:
The Product Cybersecurity Team is responsible for the security lifecycle of medical devices, software
products, infrastructure, cloud services, and IoMT solutions that generate, collect and analyze medical
device machine data from thousands of systems deployed world-wide.
The ideal candidate for the position of Senior Product Security Engineer is an accomplished security engineer,
with demonstrated experience in the secure design, development, and management of complex medical
device applications and systems. The candidate has solid cybersecurity knowledge, comprising detailed
understanding of cybersecurity threats, secure software design principles, secure coding practices and
knowledge of cryptographic tools and libraries. The candidate can review product cybersecurity
vulnerabilities; can recommend improvements in security design, and can support remediation. The
candidate routinely conducts threat modeling, vulnerability management, and product line security
management activities.
This position requires a candidate with strong technical and interpersonal skills, the ability to work
effectively and collaboratively with the business and peer Engineering teams to deliver high quality
solutions that ensure patient safety
What you’ll do
- Own and operate the post-market vulnerability management lifecycle across Intuitive products and services, from intake through remediation and closure
- Perform and operationalize ongoing vulnerability scanning for internal and external assets, including medical devices, digital applications, infrastructure, cloud services, and IoMT solutions
- Manage monthly, quarterly, and annual vulnerability scans and penetration tests, including coordination with third-party providers to meet regulatory and compliance requirements
- Define scan scope, rules of engagement, and schedules with external vendors to ensure coverage, quality, and on-time delivery
- Analyze vulnerability findings to assess real-world risk, prioritizing issues based on exploitability, exposure, patient safety, and business impact
- Review and synthesize results from scans and penetration tests, delivering clear, prioritized remediation guidance to engineering and product stakeholders
- Track remediation activities to completion, ensuring alignment with compliance obligations and internal risk acceptance criteria
- Maintain vulnerability inventories, repositories, and metrics to support ongoing reporting and audits
- Prepare and deliver vulnerability reports, dashboards, and technical risk evaluations for monthly, quarterly, and annual reviews
- Support risk-based vulnerability assessments across the post-market product portfolio
- Conduct ad-hoc vulnerability scans and analyses in support of incident response, customer inquiries, and emerging threat activity
- Identify vulnerability trends and patterns to inform preventative controls and long-term risk reduction
- Advise remediation teams on effective mitigation strategies and secure engineering practices
- Support the development, maintenance, and monitoring of Software Bills of Materials (SBOMs) as part of vulnerability tracking and reporting
- Contribute to the design, improvement, and operation of vulnerability management processes, standards, and security policies
- Maintain vulnerability management procedures and playbooks, supporting leadership, service teams, and audit stakeholders
- Partner closely with Product Security, Engineering, Quality, Incident Response, and service teams through regular check-ins and coordinated execution
- Support incident response activities and investigations related to product vulnerabilities
- Help elevate organizational awareness of emerging threats and in-market vulnerabilities, and how Intuitive proactively manages risk
What you’ll bring
- Hands-on experience owning post-market vulnerability management or product security workflows in a regulated or safety-critical environment
- Strong understanding of vulnerability lifecycles, including intake, triage, validation, prioritization, remediation tracking, verification, and reporting
- Practical experience assessing real-world risk using frameworks such as CVE, CVSS, CWE, OWASP Top 10, and SANS guidance
- Experience coordinating third-party security assessments, including vulnerability scanning and penetration testing engagements
- Ability to translate technical findings into clear, actionable remediation guidance for engineering and product teams
- Strong judgment in balancing security risk, compliance requirements, and product realities
- Familiarity with secure software design principles, secure coding practices, and threat modeling
- Working knowledge of cryptographic tools, libraries, and common security controls
- Experience supporting audit, compliance, and regulatory reporting related to product security
- Exposure to SBOMs, third-party component risk, and software supply chain security
- Comfort operating across hardware, software, firmware, and cloud environments, with the ability to learn new domains quickly
- Strong analytical skills with a track record of solving complex technical and operational problems
- Excellent collaboration and communication skills, with the ability to influence cross-functional teams without direct authority
- Ability to manage multiple workstreams, vendors, and stakeholders while maintaining responsiveness and operational rigor
- A mindset oriented toward continuous improvement, adaptability, and building scalable security processes
Make Your Resume Now