Haystack
← Back to Jobs
Technology

Product Security Engineer

eNGINE LLCUnited States🇺🇸United StatesPosted 21 Jul 2026

Why This Role Stands Out

This hybrid Product Security Engineer role offers a unique opportunity to directly influence the security of innovative medical devices and provides significant growth potential through hands-on collaboration with engineering teams. You'll thrive here

Quick Overview

Work Type
Hybrid
Level
Mid Senior

Job Description

Advisory Product Security Engineer

Location: Hybrid | Pittsburgh, PA (or Remote for the Right Candidate)

About eNGINE

eNGINE builds Technical Teams. We are a Solutions and Placement firm shaped by decades of interaction with Technical professionals. Our inspiration is continuous learning and engagement with the markets we serve, the talent we represent, and the teams we build. Our Consulting Workforce is encouraged to enjoy career fulfillment in the form of challenging projects, schedule flexibility, and paid training/certifications. Successful outcomes start and finish with eNGINE.


Role Overview

eNGINE is seeking an Advisory Product Security Engineer to support the development of next-generation network-connected medical devices. This role is ideal for a security engineer who enjoys working directly with embedded software developers to build secure products rather than simply reviewing or auditing them.

You will serve as the cybersecurity subject matter expert for multiple engineering teams, partnering throughout the software development lifecycle to implement secure design principles, address vulnerabilities, and meet evolving medical device cybersecurity regulations. This is a hands-on role where you''ll contribute technical solutions, develop automation, and provide coding assistance to embedded development teams when security-related features or remediation efforts require implementation.


Duties & Responsibilities

  • Partner directly with embedded software engineers to design, develop, and implement security features within medical devices.
  • Provide hands-on technical assistance to development teams, including Python scripting, proof-of-concept development, automation, and security-focused coding support.
  • Collaborate with engineering teams to remediate vulnerabilities and integrate security controls into existing and new products.
  • Lead threat modeling exercises and translate findings into practical engineering solutions.
  • Drive Software Bill of Materials (SBOM) and Vulnerability Exploitability eXchange (VEX) activities using enterprise security tooling.
  • Assist with vulnerability management, security assessments, and coordinated vulnerability disclosure (CVD) efforts.
  • Guide teams on secure coding practices, authentication, encryption, certificate management, secure communications, and access control implementation.
  • Support the creation of cybersecurity documentation required for regulatory submissions, including security risk assessments, testing evidence, and mitigation plans.
  • Work alongside R&D teams to integrate cybersecurity throughout the product development lifecycle.
  • Help establish and improve secure development processes, standards, and engineering best practices.
  • Evaluate emerging cybersecurity threats impacting connected medical devices and help development teams proactively address them.
  • Review and contribute to internal secure development policies and engineering standards.

Qualifications

  • Bachelor''s degree in Computer Science, Computer Engineering, Electrical Engineering, Cybersecurity, or a related technical discipline.
  • 5+ years of experience in Product Security, Application Security, or Embedded Security.
  • Experience supporting cybersecurity initiatives within medical devices, healthcare technology, or other regulated embedded systems.
  • Strong understanding of embedded Linux environments and embedded software development.
  • Hands-on experience writing Python for automation, tooling, scripting, or security workflow improvements.
  • Comfortable contributing code or technical implementations alongside software engineering teams.
  • Knowledge of secure networking concepts including TCP/IP, TLS, certificates, encryption, authentication, and secure communications.
  • Experience performing threat modeling and translating findings into engineering requirements.
  • Familiarity with SBOM management, vulnerability remediation, and software supply chain security.
  • Excellent communication skills with the ability to work effectively with software engineers, architects, quality teams, and regulatory stakeholders.

Preferred Experience

  • Experience developing or securing embedded medical devices.
  • Familiarity with AWS or cloud-connected embedded products.
  • Knowledge of FDA cybersecurity guidance, IEC 62304, AAMI TIR57, NIST Cybersecurity Framework, EU MDR, NMPA, and other medical device cybersecurity standards.
  • Experience with SAST, DAST, IAST, Software Composition Analysis (SCA), fuzz testing, and related application security tools.
  • Experience implementing secure boot, secure firmware updates, cryptographic services, or hardware-based security features.
  • Background working within Agile product development environments.
  • Experience supporting security activities throughout the entire SDLC.

What Makes This Role Unique

This is not a governance or compliance-only security position. The ideal candidate enjoys rolling up their sleeves and working directly with software engineers to solve security challenges. You''ll be expected to architect solutions, write scripts and tooling, assist with implementation, and help development teams build secure products—not simply identify issues for others to fix.


Next Steps

No C2C, relocation, referral, or sponsorship candidates for this role.

For finer details on how eNGINE can impact your career, apply today!

 

Skills

AWS
Embedded Systems
Encryption
TCP/IP
Agile
Python

Similar jobs