Smith & Nephew

Principal Product Security Engineer

Smith & Nephew • $125K — $198K *
Healthcare
5 - 7 years of experience
Job Overview by Ladders

Qualifications

  • Bachelor's degree in life science, computer science, information systems, or equivalent experience
  • 5+ years of hands-on experience in product, device, application, or IT security
  • Proficient in vulnerability management, penetration testing, and security governance
  • Familiar with medical device regulations and cybersecurity frameworks (HIPAA, FDA, ISO 27001, NIST CSF, OWASP)
  • Strong ability to design and implement innovative security solutions across teams
  • Excellent communication, prioritization, and problem-solving skills
  • Preferred certifications: CISM, CISSP, CRISC, or equivalent

Responsibilities

  • Lead the implementation of cybersecurity requirements across various technologies and applications
  • Create and maintain cybersecurity risk registers and threat models
  • Conduct security testing and assessments, including vulnerability and penetration testing
  • Recommend and integrate automated tools to reduce security vulnerabilities
  • Develop and enhance the Global Product Security Strategy and Secure Software Development Life Cycle
  • Support cybersecurity incident response activities according to industry standards
  • Provide technical leadership in engagements with regulators, customers, and industry groups

Benefits

  • Medical, dental, and vision coverage
  • 401k plan
  • Tuition reimbursement
  • Medical leave programs
  • Variety of wellness offerings
Full Job Description
Join our Global Product Security team in Pittsburgh and help protect medical technologies, connected devices, digital solutions, and the data they rely on. You will provide cybersecurity leadership across the full product lifecycle while partnering with Global IT, Research and Development, and Compliance teams. **This position does not offer visa sponsorship now or in the future** What will you be doing? • Lead the definition and implementation of cybersecurity requirements and controls across technologies, capital devices, digital accessories, connected infrastructure, and software applications • Create and maintain product cybersecurity risk registers and threat models, identifying and addressing security risks throughout the development lifecycle • Lead security testing and assessment activities, including vulnerability testing, penetration testing, code analysis, software composition analysis, and endpoint protection • Recommend technical solutions and support the integration of automated tools and processes that reduce security vulnerabilities • Help develop and mature the Global Product Security Strategy and Secure Software Development Life Cycle • Support product cybersecurity incident response activities in line with relevant industry practices and standards • Provide technical leadership when engaging with regulators, customers, auditors, industry groups, and security researchers What will you need to be successful? • A bachelor's degree in life science, computer science, information systems, or equivalent formal training or professional experience • At least five years of hands on experience in product security, device security, application security, or information technology security • Experience with vulnerability management, penetration testing, code security, security governance, risk assessments, network infrastructure, and cloud security • Knowledge of medical device regulations and cybersecurity frameworks, including HIPAA, FDA requirements, ISO 27001 and 27002, NIST CSF, and OWASP • The ability to design and guide the implementation of innovative security solutions while working independently across multiple teams and business areas • Excellent written and verbal communication, prioritization, customer service, and problem resolution skills • A current CISM, CISSP, CRISC, or equivalent certification is preferred You. Unlimited. We anticipate the application window for this opening to close on 10.10.2026 The anticipated base compensation range for this position is $125,500.00 - $198,000.00 USD annually and the compensation offered will depend on the candidate's qualifications, job-related knowledge/skills, geographical location. You will be entitled to receive bonus and benefits, which include medical, dental, and vision coverage, 401k, tuition reimbursement, medical leave programs, and a variety of wellness offerings. #LI-HYBRID #LI-SB2 #LI-DNI

About Smith & Nephew

Smith & Nephew is a global medical technology company headquartered in London, England. The company designs, manufactures, and sells medical devices and products for orthopedic reconstruction, sports medicine, and trauma. Smith & Nephew operates in more than 100 countries and employs over 17,500 people worldwide. The company was founded in 1856 by Thomas James Smith and his nephew, Horatio Nelson Smith, and has grown through a series of mergers and acquisitions. Smith & Nephew's products include joint replacement systems, wound care products, and surgical instruments. The company is listed on the London Stock Exchange and is a constituent of the FTSE 100 Index.
Learn more about Smith & Nephew
Size
17,500 employees
Market Cap
$11.5 billion
Industry
Net Income
$448 million
5 Year Trend
+2.2%
Revenue
$4.5 billion

Similar Jobs

More Jobs at Smith & Nephew

More Healthcare Jobs

Find similar Principal Product Security Engineer jobs: