Shire Jobs

Mobile Shire Logo

Job Information

Stryker Senior Staff Product Security Engineer, Embedded (REMOTE) in Seattle, Washington

We are excited to be named one of the World’s Best Workplaces by Fortune Magazine! We are proud to offer you 12 paid holidays annually, as well other great perks. For an overview of our benefits and time off, please follow this link to learn more: US Stryker employee benefits. (https://d25zu39ynyitwy.cloudfront.net/oms/000000/document/2024/6/SMVZW_USStrykerEmployeebenefits/USStrykerEmployeebenefits.pdf)

Who We Want:

  • Dedicated achievers - People who thrive in a fast-paced environment and will stop at nothing to ensure a project is complete and meets regulations and expectations. 

  • Curious learners - People who seek out cutting-edge research and information to expand and enhance their ability to be ready for what’s next. 

  • Self-directed initiators – People who take ownership of their work and need no prompting to drive productivity, change, and outcome and will stop and nothing to ensure a project is complete and meets regulations and expectations. 

  • Collaborative partners - People who build and leverage cross-functional relationships to bring together ideas, information, use cases, and industry analyses to develop best practices. 

What You Will Do:

Product Security is driven to make healthcare better by ensuring that Stryker designs, develops, and maintains industry leading cyber secure products for our customers. As a Senior Staff Product Security Engineer , you will improve the safety, integrity, and resilience of medical devices developed by the Acute Care business unit at Stryker Medical and their embedded software. You will participate in project planning, product cybersecurity risk analysis, and risk mitigation strategies. You will lead various product cybersecurity tasks and activities established by product design controls and SDLC procedures and you will be involved in all facets of the product development life cycle. The ideal candidate is excited to protect our customers and their patients through the design and implementation of effective security controls. 

Key Responsibilities:

  • Understand the overall technical capabilities of our products, typical deployment scenarios, and drive platform security posture improvement. 

  • Collaborate with product teams to create comprehensive product cybersecurity threat models. Guide security risk analysis including threat identification, severity scoring, and selection of appropriate controls to mitigate risks. 

  • Work closely with cross-functional teams, including Quality, Regulatory, and Marketing in driving alignment around medical device cybersecurity standards and regulations.  

  • Support all facets of product hardware and software security including system hardening, automated and manual penetration testing, vulnerability scanning, and issue remediation. 

  • Identify product vulnerabilities through design review, code review, and security testing. 

  • Lead and own vulnerability and incident response activities through assessing applicability, exploitability, and impact with product teams; developing POC exploits; and planning and executing mitigation and remediation to closure. 

  • Leverage and implement DevSecOps to create efficiencies in managing security posture of our products. 

  • Support cybersecurity documentation requests from legal and sales teams on an as-needed basis. 

  • Lead product teams on conversations from a security PoV. Author and contribute artifacts such as Security Assessment, MDS2, Security Risk, Threat Model, SBOM, OSS etc. 

  • Coordinate security war gaming activities with R&D product teams to enhance security practices and overall security posture throughout life of a product.

What You Will Need:

Basic Qualifications:

  • Bachelor's degree in Computer Science, Software Engineering, Electrical Engineering, Cybersecurity, or related discipline 

  • Minimum 6 years of related experience 

  • Demonstrated experience designing and securing embedded systems 

  • Strong understanding of embedded/IOT security relevant technologies (e.g. secure boot, FIPS 140-2 encryption, anti-tamper, TPM, code signing, TLS, PKI) 

Preferred Qualifications:

  • Experience working in medical device, health care, or other regulated industry. 

  • Knowledge of communication protocols and technologies like TCP/IP, Ethernet, Wi-Fi, Bluetooth, 3G, UWB, and CAN. 

  • Experience with Embedded Linux 

  • Proficiency with C/C++ 

  • Familiarity with use of embedded security tools such as logic analyzers, protocol analyzers, disassemblers, Wireshark, Bus Pirate, ChipWhisperer, IDA, MetaSploit, etc.

  • $112k - $239ksalary plus bonus eligible + benefits. Actual minimum and maximum may vary based on location. Individual pay is based on skills, experience, and other relevant factors.

Health benefits include: Medical and prescription drug insurance, dental insurance, vision insurance, critical illness insurance, accident insurance, hospital indemnity insurance, personalized healthcare support, wellbeing program and tobacco cessation program. Financial benefits include: Health Savings Account (HSA), Flexible Spending Accounts (FSAs), 401(k) plan, Employee Stock Purchase Plan (ESPP), basic life and AD&D insurance, and short-term disability insurance. Stryker offers innovative products and services in MedSurg, Neurotechnology, Orthopaedics and Spine that help improve patient and healthcare outcomes. Alongside its customers around the world, Stryker impacts more than 150 million patients annually. Depending on customer requirements employees and new hires in sales and field roles that require access to customer accounts as a function of the job may be required to obtain various vaccinations as an essential function of their role.

Stryker Corporation is an equal opportunity employer. Qualified applicants will receive consideration for employment without regard to race, ethnicity, color, religion, sex, gender identity, sexual orientation, national origin, disability, or protected veteran status. Stryker is an EO employer – M/F/Veteran/Disability.

DirectEmployers