Product Security Engineer
In-Office, Irvine, CA
- 求人ID
- R-546847
- Category
- Engineering
- Location
- アーバイン, カリフォルニア州
イノベーション、オーナーシップ、そしてヘルスケアの前進に貢献するエンジニアリングのキャリアを築く
BDのエンジニアリング・R&Dは、世界中の医療提供のあり方を形づくるテクノロジーを設計し、開発し、改良しています。あなたは科学的思考、技術的専門性、創造的な問題解決力を活かして、複雑な課題を意義あるソリューションに変えていくことになります。
機械、電気、プロセス、システム、ソフトウェア、リサーチエンジニアリングなど、どの分野を専門とされていても、BDにはイノベーションを推進するための規模、リソース、そして自由があります。明確な期待値、成果に対する責任、そして業界をリードするテクノロジーとともにキャリアを成長させる機会があります。
そして、世界最大級のメドテックカンパニーの一員として、グローバルなヘルスケアシステムに広く届けられるソリューションを形づくり、大規模に人々の生活を向上させていくことになります。
We are the people who give possibilities purpose
BD is one of the largest global medical technology companies in the world. Advancing the world of health™ is our Purpose, and it’s no small feat. It takes the imagination and passion of all of us—from design and engineering to the manufacturing and marketing of our billions of MedTech products per year—to look at the impossible and find transformative solutions that turn dreams into possibilities.
Job Description
Summary:
The Product Security Engineer is responsible for supporting the security of a BD product or subset of features within the product across the development lifecycle. This individual contributes to the delivery of secure products consistent with global regulatory requirements by executing product security program activities under the guidance of senior team members.
This role works in partnership with R&D and other stakeholders to support compliance with security technical requirements and reduce security risks within the product or feature set. This includes hands-on execution of product security activities such as threat modeling, vulnerability scanning and remediation, and security risk assessments. The successful candidate will apply developing technical expertise to evaluate security vulnerabilities and contribute to maintainable technical solutions. Collaboration with software engineers and R&D team members in a dynamic and agile development environment is essential. Having demonstrated positive work ethic and commitment to achieving project goals with strong collaboration and communication skills - both written and verbal - is key for success in this role.
The Product Security Office (PSO) ensures product security risks for BD’s software-based products and solutions are managed well over the lifecycle as they make a difference for our patients and customers. In the PSO, we offer flexibility so you can successfully balance your work and personal responsibilities. We care about our associates and ensure we have servant leaders to help you grow your career, provide feedback and recognition, and empower you to show up every day as your authentic self. We are passionate about improving patient outcomes and enabling our R&D teams to create and maintain innovative solutions in a secure manner. Armed with a growth mindset and a desire to want to do more, learn more, impact more, you are in a great position to join us and help BD advance the world of health in ways you may never have imagined in your career.
Responsibilities:
Security Requirements & Implementation: Support project teams in defining and implementing security requirements and technologies for a product or set of features in accordance with industry standards for medical devices, including encryption, authentication, audit logging, hardening measures, SBOM creation and composition, patch management, vulnerability monitoring, and antivirus/antimalware as applicable.
Cryptography & PKI: Support the selection and implementation of appropriate cryptographic algorithms, key management practices, and certificate lifecycle management (issuance, renewal, revocation) for devices and cloud-connected components.
Secure Communications: Evaluate and support secure communication implementations across device interfaces and network protocols relevant to the product, including validation of TLS/mTLS configurations and medical or proprietary protocols as applicable.
Cloud & API Security: Assist in identifying and addressing security risks in cloud-connected device backends and associated APIs, including authentication, authorization, and protection of data in transit and at rest.
Design Reviews: Participate in technical design reviews and code inspections, providing feedback to project team members and following proper coding practices.
Security Assessments: Support execution of product security risk assessments, hazard analysis, and vulnerability remediation activities in coordination with product development software engineers.
Process & Documentation: Assist product development teams in complying with product security framework activities and contributing to security documentation, including Incident and Vulnerability Management Plans and Product Security White Papers.
Incident Response: Participate in product security incident response activities as appropriate.
Training & Procedures: Where applicable, support the deployment of software engineering procedures and training related to vulnerability scanning and static code analysis tools.
Automated Testing: Where applicable, assist R&D teams in implementing systems for automated testing of software vulnerabilities and verification of OS security patches.
Quality Assurance: Where applicable, contribute to quality in R&D security test deliverables, including design, data summary, report preparation, and review for adherence to applicable regulations.
May perform other duties as required.
Minimum Required:
Undergraduate degree in cybersecurity, computer science, computer engineering, software engineering, or related technical field.
Minimum of 3+ years in product security, product development, software development, or quality assurance.
Foundational knowledge of information security standards for product development.
Experience with configuration and use of static code analysis and vulnerability scanning tools.
Foundational understanding of applied cryptography and PKI concepts (cipher selection, key management, certificate lifecycle).
Preferred Knowledge, Skills:
Master’s degree (cybersecurity, computer science, software engineering) with minimum of 2 years of industry experience
Familiarity with product cybersecurity requirements in the context of 510(k) and/or PMA-regulated products.
Developing experience assessing security risks using industry standard methods (penetration test results, threat modeling, security testing) and applying compensating security controls.
Foundational competence in threat modeling software systems or software-enabled products using industry standard methods (STRIDE, PASTA, NIST, OWASP).
Understanding of applied cryptography fundamentals: algorithm and mode selection, key length, hashing, and secure key storage practices.
Familiarity with PKI concepts including CA hierarchies, certificate lifecycle management, and revocation mechanisms (CRL/OCSP).
Familiarity with securing network communications, including TLS/mTLS configuration and validation, and medical or device-specific protocols (e.g., HL7, FHIR, Bluetooth LE) as applicable.
Foundational awareness of cloud and API security principles, including authentication/authorization patterns and protection of PHI/PII in cloud-connected product architectures.
Exposure to cybersecurity tooling such as Black Duck, Coverity, Veracode, Nessus, Snyk, or Metasploit.
Experience working within a structured software development lifecycle process; agile methodology.
Experience with connected products, software development, lifecycles, network technologies, or regulated environments.
Certifications such as CCNA, CISSP, CISM, GIAC, CCSP, CEH
At BD, we prioritize on-site collaboration because we believe it fosters creativity, innovation, and effective problem-solving, which are essential in the fast-paced healthcare industry. For most roles, we require a minimum of 4 days of in-office presence per week to maintain our culture of excellence and ensure smooth operations, while also recognizing the importance of flexibility and work-life balance. Remote or field-based positions will have different workplace arrangements which will be indicated in the job posting.
For certain roles at BD, employment is contingent upon the Company’s receipt of sufficient proof that you are fully vaccinated against COVID-19. In some locations, testing for COVID-19 may be available and/or required. Consistent with BD’s Workplace Accommodations Policy, requests for accommodation will be considered pursuant to applicable law.
Why Join Us?
To find purpose in the possibilities, we need people who can see the bigger picture, who understand the human story that underpins everything we do. We welcome people with the imagination and drive to help us reinvent the future of healthcare. At BD, you’ll discover a culture in which you can learn, grow and thrive.
We believe that when people connect in person, we learn faster, collaborate more deeply, and build a stronger culture. Join us and enjoy a culture where face-to-face collaboration supports your learning, your progress, and your success.
To learn more about BD visit https://bd.com/careers.
Becton, Dickinson, and Company is an Equal Opportunity Employer. We evaluate applicants without regard to race, color, religion, age, sex, creed, national origin, ancestry, citizenship status, marital or domestic or civil union status, familial status, affectional or sexual orientation, gender identity or expression, genetics, disability, military eligibility or veteran status, and other legally protected characteristics.
Required Skills
Optional Skills
.
Primary Work Location
USA CA - Irvine Laguna CanyonAdditional Locations
Work Shift
At BD, we reward, support and develop our associates through our comprehensive Total Rewards program. We are committed to attracting and retaining high quality talent by providing reward and recognition opportunities that promote a performance-based culture, as well as a competitive package of compensation and benefits programs. You can learn more on our career site under "Our Commitment to You."
Our salary or hourly rate ranges reward associates fairly and competitively. We regularly review these ranges and factors, such as location, contribute to the range displayed.
Our pay is based on the role and the necessary skills and education to perform it successfully. The salary or hourly rate offered is determined by the role's specific requirements, including any applicable step rate pay system at the work location. Salary or hourly pay ranges are influenced by labor laws and Collective Bargaining Agreement (CBA) requirements applicable to the work location which may also affect the workplace arrangement of the role.
Salary Range Information
$105,500.00 - $168,800.00 USD Annual求められる人物像
BDのエンジニアリング・R&D部門で活躍する人たちには、どのような特長があるでしょうか。以下のような方は、BDのエンジニアリング・R&D部門できっと活躍できるはずです:
- 分析力のある方
- 協働的な方
- 探究心・好奇心旺盛な方
- 細部にまで注意を払える方
- 創造力のある方
- 問題解決力のある方
次のチャレンジの準備はできていますか?
ここは、大胆な発想と精密な実行を両立させたいエンジニアのための環境です。あなたは設計の意思決定に影響を与え、製品ライフサイクル全体に関わり、あなたの仕事がコンセプトから実際の世界でのインパクトへとつながる過程を見届けることができます。そのすべては、グローバルメドテックリーダーとしての規模によって支えられています
BDイノベーターの一人から、BDがどのように最先端のAIや機械学習を活用して、患者アウトカムを改善し、医療アクセスを拡大する意思決定を推進しているかをお聞きください。ここでは、あなたの仕事が世界中でリアルタイムにインパクトを生み出します。
人を中心に築かれた職場環境
-

「BDは大きなグローバルカンパニーなので、周囲の人とつながり、積極的に連絡を取ることをためらわないで欲しいです。ここには学べることが本当にたくさんありますし、会社は人の育成と成長に手厚く支援をしてくれます。スポンジのようになって、できるだけ多くの知識を吸収し、自分のキャリアブループリントを最大限に活かしてほしいと思います。私は自分の仕事が本当に大好きで、BDで働けることにとても感謝しています。」
-

「アイルランドのリサーチセンターでは、30カ国以上の国籍の人たちが働いていると思います。これはとても素晴らしいことで、BDについて私が最も気に入っていることの一つです。私は電気エンジニア、機械エンジニア、科学者など、多くの人々と仕事をしています。一日を通して非常に多様な視点を見聞きできることは素晴らしいことです。」
-

「メドテック分野で私たちがどのようにイノベーションを続けているのか、今でも驚かされています。医療従事者にさらに多くのソリューションを届けるにはどうすべきか、技術の効率性をどのように高めるか、常に検討しています。そのすべてを、患者さんへの影響を念頭に置きながら行っています。BDで意義のある仕事を見つけられただけでなく、自分が活躍できる場所を見つけました。」
-

「面接のときに、私たちの輸液ソリューションが世界中でどれほど大きな影響を与えているかを知り、感銘を受けました。鎮痛剤、がん治療、麻酔、その他の治療など、いずれであっても、自分の家族の誰かがBDの製品を使っている可能性は高いのです。ヘルスケアにこれほど大きなインパクトを与えることのできる製品の開発に携われることは、誇らしいことです。私はBDでの自分の役割が大好きです。」
福利厚生
-
競争力のある報酬
-
退職金制度
-
医療保険
-
有給休暇
-
育児休暇
-
従業員支援プログラム(EAP)
-
報奨・表彰制度
求人アラートに登録する
スキルや希望勤務地に合ったポジションの募集開始時に通知を受け取れるよう、求人アラートを作成しましょう