What are the responsibilities and job description for the Product Security Engineer position at Intellias?
Important Note: for this position, we're currently considering candidate available to work in a hybrid model (4 days/week) in the following locations: Newton (Massachusetts), and Minneapolis (Minnesota).
We are seeking a Senior Product Security Engineer to join a growing R&D organization developing next-generation connected medical device solutions. In this role, you will work closely with engineering teams to build secure, reliable, and resilient products throughout the development lifecycle.
This role focuses on Product Security Engineering for embedded and connected products within a regulated environment. It is not a traditional IT Security, SOC, Infrastructure, Compliance, or GRC role. The ideal candidate has hands-on experience integrating security into software, firmware, or embedded product development and enjoys working closely with engineering teams to identify security risks, implement secure-by-design practices, and improve overall product security.
Experience in medical devices is a plus but not required. Candidates from other regulated or safety-critical industries such as Automotive, Aerospace, Defense, or Industrial IoT are encouraged to apply.
Requirements:
- Bachelor's degree in Computer Science, Computer Engineering, Cybersecurity, Electrical Engineering, or a related technical field.
- 4 years of experience in Product Security, Embedded Security, or Cybersecurity Engineering.
- Hands-on experience securing embedded systems, connected devices, or other software-driven products, preferably in regulated or safety-critical industries.
- Strong understanding of:
- Secure Software Development Lifecycle (SSDLC)
- Threat Modeling
- Vulnerability Management & Risk Assessment
- Security-by-Design principles
- Experience identifying, assessing, and mitigating product security risks throughout the product development lifecycle.
- Familiarity with security frameworks and standards such as NIST, OWASP, and secure product development best practices.
- Ability to collaborate effectively with software, firmware, hardware, and systems engineering teams to integrate security into product development.
- Strong communication and stakeholder collaboration skills.
Nice to Have
- Experience with cybersecurity for medical devices or other regulated industries (Automotive, Aerospace, Defense, Industrial/IoT, or similar).
- Experience with:
- SBOM generation and management
- Software Composition Analysis (SCA)
- CVE triage and remediation
- Security tooling and vulnerability assessment
- Familiarity with IEC 81001-5-1, ISO 14971, and FDA cybersecurity guidance.
- Basic scripting or automation experience (Python, Bash, or similar).
- Security certifications such as CISSP, GIAC, Security , or equivalent.
Responsibilities:
- Partner with software, firmware, hardware, and systems engineering teams to integrate security throughout the product development lifecycle.
- Perform product security assessments, threat modeling, and risk analysis for embedded and connected products.
- Identify, prioritize, and support remediation of product security vulnerabilities and security risks.
- Drive secure-by-design and Secure Software Development Lifecycle (SSDLC) practices across engineering teams.
- Support vulnerability management activities, including SBOM, Software Composition Analysis (SCA), and CVE assessment and remediation.
- Contribute to the implementation and validation of product security controls, including authentication, encryption, secure communications, secure boot, and software update mechanisms.
- Apply industry security standards and best practices (NIST, OWASP, IEC 81001-5-1, FDA guidance) where appropriate.
- Provide practical security guidance to engineering teams and help improve the overall product security posture.
- Stay current with emerging cybersecurity threats, vulnerabilities, and technologies relevant to connected and embedded products.