Let’s get started
By clicking ‘Next’, I agree to the Terms of Service
and Privacy Policy
Jobs / Job page
Senior Product Security Engineer - Security Analysis image - Rise Careers
Job details

Senior Product Security Engineer - Security Analysis

Company Description

At Intuitive, we are united behind our mission: we believe that minimally invasive care is life-enhancing care. Through ingenuity and intelligent technology, we expand the potential of physicians to heal without constraints.

As a pioneer and market leader in robotic-assisted surgery, we strive to foster an inclusive and diverse team, committed to making a difference. For more than 25 years, we have worked with hospitals and care teams around the world to help solve some of healthcare's hardest challenges and advance what is possible.

Intuitive has been built by the efforts of great people from diverse backgrounds. We believe great ideas can come from anywhere. We strive to foster an inclusive culture built around diversity of thought and mutual respect. We lead with inclusion and empower our team members to do their best work as their most authentic selves.

Passionate people who want to make a difference drive our culture. Our team members are grounded in integrity, have a strong capacity to learn, the energy to get things done, and bring diverse, real world experiences to help us think in new ways. We actively invest in our team members to support their long-term growth so they can continue to advance our mission and achieve their highest potential.

Join a team committed to taking big leaps forward for a global community of healthcare professionals and their patients. Together, let's advance the world of minimally invasive care.

Job Description

Primary Function of Position:

The Sr Product Security Engineer is primarily responsible for conducting security analysis of Intuitive Surgical products, developing recommended security mitigations, and deriving security requirements for surgical systems in Intuitive Surgical product portfolio, including SinglePort, MultiPort daVinci Surgical Systems, ION system and associated peripherals and instruments.

Responsibilities:

  • Work closely with the product teams and understand our products in depth to review and document the security attack surface, trust boundaries and data flows. 
  • Develop threat models that enumerate cybersecurity risks and threats.
  • Document and verify the existing security mitigations and identify if additional mitigations are required for our products.
  • Work with the product teams to provide guidance during mitigation design and development.
  • Contribute to development and implementation of security controls, test and verification protocols. Assist in conducting security verification and validation efforts. 

Qualifications

Required Skills and Experience

  • Minimum of 8 years of related experience and a Bachelor’s degree; or 6 years of experience and a Master's degree; or a PhD with 3 years of experience; or equivalent experience
  • In-depth knowledge of security concepts regarding embedded systems, operating systems, firmware, and software security
  • Hands-on experience with Python, Bash or other scripting languages
  • Understanding of current and emerging security technologies and threats
  • In-depth knowledge of security risks and threats associated with wired and wireless device interfaces including USB, JTAG, serial ports, UART, SPI, Ethernet, Bluetooth and Wi-Fi
  • Proficient with methodologies, tools, best practices, and processes across various cybersecurity areas
  • Knowledge of common security flaws and resolution as published by SANS, MITRE (CVE, CWE)
  • Proven experience with threat modeling and risk analysis with ability to understand and score using the CVSS method
  • Ability to work with Software Bill of Materials (SBOM) and vulnerability assessment of components in the SBOM
  • Ability to gather written and verbal information from multiple sources, assess and consolidate risks to provide appropriate recommendations
  • Hands-on experience with penetration testing and vulnerability analysis frameworks and tools
  • Experience in developing test routines and protocols to validate security mitigations
  • Excellent documentation and communication skills

Preferred Skills and Experience

  • Embedded development experience with C/C++
  • Experience with security analysis of medical devices and products
  • Experience with medical device cybersecurity regulations (FDA, NMPA, EU MDR, MDCG, HIPAA)
  • Experience developing hardware level security controls such as secure boot and firmware verification
  • Experience in Cybersecurity related data analytics, machine learning, anomaly detection and incident response

Additional Information

Due to the nature of our business and the role, please note that Intuitive and/or your customer(s) may require that you show current proof of vaccination against certain diseases including COVID-19.  Details can vary by role.

Intuitive is an Equal Employment Opportunity / Affirmative Action Employer. We provide equal employment opportunities to all qualified applicants and employees, and prohibit discrimination and harassment of any type, without regard to race, sex, pregnancy, sexual orientation, gender identity, national origin, color, age, religion, protected veteran or disability status, genetic information or any other status protected under federal, state, or local applicable laws.

EEO and AA Policy

We will consider for employment qualified applicants with arrest and conviction records in accordance with fair chance laws.

Preference will be given to qualified candidates who do not reside, or plan to reside, in Alabama, Arkansas, Delaware, Florida, Indiana, Iowa, Louisiana, Maryland, Mississippi, Missouri, Oklahoma, Pennsylvania, South Carolina, or Tennessee.

We provide market-competitive compensation packages, inclusive of base pay, incentives, benefits, and equity. It would not be typical for someone to be hired at the top end of range for the role, as actual pay will be determined based on several factors, including experience, skills, and qualifications. The target salary ranges are listed.

Average salary estimate

$140000 / YEARLY (est.)
min
max
$120000K
$160000K

If an employer mentions a salary or salary range on their job, we display it as an "Employer Estimate". If a job has no salary data, Rise displays an estimate if available.

What You Should Know About Senior Product Security Engineer - Security Analysis, Intuitive

Are you passionate about enhancing healthcare technology? At Intuitive in Sunnyvale, CA, we are on the lookout for a talented Senior Product Security Engineer specializing in Security Analysis. In this crucial role, you'll dive deep into the security analysis of our innovative robotic-assisted surgical systems, like our SinglePort and MultiPort da Vinci Surgical Systems, to ensure they remain safe and secure. Your primary mission will be to evaluate security attack surfaces, document trust boundaries, and flow data securely within our products. You'll develop robust threat models to highlight potential cybersecurity risks, all while collaborating closely with our product teams to implement effective security mitigations. With over eight years of experience—or a combination of relevant education and experience—you’ll leverage your in-depth knowledge of embedded systems and cutting-edge security technologies. Important skills include hands-on experience with scripting languages like Python or Bash, as well as familiarity with medical device cybersecurity regulations. Your insights will also guide the development of security controls and validation efforts, empowering our teams to take significant strides forward in minimally invasive care. Join us at Intuitive, where your expertise will help shape the future of healthcare technology. Let's work together to make a difference and create solutions that truly enhance lives!

Frequently Asked Questions (FAQs) for Senior Product Security Engineer - Security Analysis Role at Intuitive
What are the responsibilities of a Senior Product Security Engineer at Intuitive?

As a Senior Product Security Engineer at Intuitive, your primary responsibilities will include conducting in-depth security analyses, documenting the security attack surfaces of our products, developing threat models, and working hand-in-hand with product teams to implement security mitigations. You'll play a vital role in enhancing the cybersecurity posture of our robotic systems, ensuring that risks are effectively managed and mitigated.

Join Rise to see the full answer
What qualifications are needed for a Senior Product Security Engineer role at Intuitive?

To qualify for the Senior Product Security Engineer position at Intuitive, candidates should possess a minimum of eight years of related experience along with a Bachelor's degree, or a combination of a Master's degree with six years of experience, or a PhD with three years of experience. Expertise in security concepts related to embedded systems, hands-on experience with scripting languages, and thorough knowledge of security threats and methodologies are essential.

Join Rise to see the full answer
What skills are essential for a Senior Product Security Engineer at Intuitive?

Essential skills for the Senior Product Security Engineer role at Intuitive include proficiency in Python or Bash scripting, knowledge of cybersecurity risks concerning device interfaces, experience with threat modeling and risk analysis, and hands-on skills in penetration testing and vulnerability analysis frameworks. Strong documentation and communication abilities are also critical to effectively collaborate with teams.

Join Rise to see the full answer
What technologies will a Senior Product Security Engineer at Intuitive work with?

In the Senior Product Security Engineer position at Intuitive, you will work with technologies associated with embedded systems, cybersecurity tools, and frameworks. You'll deal with various wired and wireless interfaces, develop and validate security controls, and assess the vulnerability of components in the Software Bill of Materials (SBOM). A solid understanding of medical device cybersecurity regulations is also beneficial.

Join Rise to see the full answer
How does Intuitive support the growth of its Senior Product Security Engineers?

Intuitive actively invests in the growth of its Senior Product Security Engineers by providing opportunities for professional development, access to ongoing training, and encouraging participation in industry conferences. The inclusive corporate culture promotes collaboration and idea-sharing, thereby ensuring that team members continually advance their skills and career trajectories.

Join Rise to see the full answer
Common Interview Questions for Senior Product Security Engineer - Security Analysis
Can you explain your experience with threat modeling?

When addressing this question, be sure to provide specific examples of how you have developed threat models in previous positions. Discuss the frameworks you used, the types of risks you identified, and how these models influenced the secure design of products. It helps to mention any tools or methodologies that you are well-versed in.

Join Rise to see the full answer
What cybersecurity vulnerabilities have you encountered in medical devices?

To answer effectively, discuss specific vulnerabilities you've identified, such as those related to wireless communications or software interfaces in medical devices. Explain how you assessed these vulnerabilities, what measures were taken to address them, and your role in ensuring compliance with relevant regulations.

Join Rise to see the full answer
How do you stay current with emerging security threats and trends?

Explain the steps you take to remain updated, such as following industry blogs, participating in webinars, attending cybersecurity conferences, or engaging with professional networks. Mention any certifications you pursue and how they enhance your understanding of the cybersecurity landscape.

Join Rise to see the full answer
How do you prioritize security vulnerabilities?

Discuss your methodology for prioritizing vulnerabilities, which might include assessing risks based on potential impact, exploitability, and company resources. Mention tools or frameworks you use, such as CVSS scoring, and describe how prioritizing vulnerabilities has led to improved product security in the past.

Join Rise to see the full answer
What role does communication play in your work as a Senior Product Security Engineer?

Highlight the importance of communication in this role by discussing how you collaborate with product teams and stakeholders. Emphasize your ability to translate technical security concepts into understandable communication, ensuring all parties are aligned in addressing security issues.

Join Rise to see the full answer
Can you give an example of a security mitigation you developed?

Prepare to detail a specific mitigation effort, including the challenges you faced, the solution you proposed, and the results achieved. Explain the methodology behind the mitigation and how it was implemented, assessed, and validated.

Join Rise to see the full answer
What experience do you have with embedded systems security?

Provide details about specific embedded systems you've worked on, describing what security measures were implemented and any lessons learned. Discuss how this experience contributes to your understanding of embedded systems security risks.

Join Rise to see the full answer
Describe a time when you had to advocate for a security initiative.

Share a specific instance where you identified a security gap and successfully advocated for a solution. Describe how you communicated the importance of the initiative to stakeholders and the positive outcome that resulted.

Join Rise to see the full answer
How do you approach documentation of security processes?

Emphasize your attention to detail and your commitment to maintaining accurate and thorough documentation of security processes. Explain how you create and organize documentation to facilitate easy access for team members and support compliance tracking.

Join Rise to see the full answer
What tools do you use for vulnerability assessment?

Discuss specific tools you are familiar with for vulnerability assessment, such as static and dynamic analysis tools, and how you integrate them into your security workflow. Elaborate on your experience using these tools to identify, prioritize, and remediate vulnerabilities effectively.

Join Rise to see the full answer
Similar Jobs
Photo of the Rise User
Posted 12 days ago
Photo of the Rise User
Posted 10 days ago
Jobot Remote Lincoln, NE
Posted 10 days ago
Photo of the Rise User
Inclusive & Diverse
Mission Driven
Collaboration over Competition
Growth & Learning
Photo of the Rise User
gpac Hybrid Flowery Branch, GA
Posted 10 days ago
Photo of the Rise User
Kalepa Remote (New York, NY. Remote US.)
Posted 3 days ago
Dental Insurance
Vision Insurance
Photo of the Rise User
Posted 5 days ago
Photo of the Rise User
Posted 11 days ago
Mission Driven
Social Impact Driven
Passion for Exploration
Reward & Recognition

Founded in 1995, Intuitive Surgical, Inc develops, manufactures and markets robotic technologies designed to improve clinical outcomes and help patients return more quickly to active and productive lives. The company is headquartered in Sunnyvale,...

129 jobs
MATCH
Calculating your matching score...
FUNDING
DEPARTMENTS
SENIORITY LEVEL REQUIREMENT
TEAM SIZE
EMPLOYMENT TYPE
Full-time, on-site
DATE POSTED
December 24, 2024

Subscribe to Rise newsletter

Risa star 🔮 Hi, I'm Risa! Your AI
Career Copilot
Want to see a list of jobs tailored to
you, just ask me below!