Talent.com
Senior Principal Engineer, Product Security

Senior Principal Engineer, Product Security

VantivePlymouth, MN, US
9 hours ago
Job type
  • Full-time
Job description

Vantive is a vital organ therapy company on a mission to extend lives and expand possibilities for patients and care teams everywhere. For 70 years, our team has driven meaningful innovations in kidney care. As we build on our legacy, we are deepening our commitment to elevating the dialysis experience through digital solutions and advanced services, while looking beyond kidney care and investing in transforming vital organ therapies. Greater flexibility and efficiency in therapy administration for care teams, and longer, fuller lives for patients— that is what Vantive aspires to deliver.

We believe Vantive will not only build our leadership in the kidney care space, it will also offer meaningful work to those who join us. At Vantive, you will become part of a community of people who are focused, courageous and don’t settle for the mediocre. Each of us is driven to help improve patients’ lives worldwide. Join us in advancing our mission to extend lives and expand possibilities.

Your Role

As the Sr. Principal Product Security Engineer you will be responsible for designing, building, testing and implementing systems with the primary goal of product security across Vantive’s software within the medical device product portfolio in various operating environments. Prevention of breach of Intellectual Property (IP), Attack surface minimization, preventive security and privacy controls, incident / vulnerability management are some of the focal areas for this position.

This role requires deep knowledge of security by design, web-based secure code principles, and web application development including microservice security and system hardening in cloud environments. Candidates should have experience in web-application development or cloud software development with a desire to secure products protecting our customers and patients who use our products each day. Success in this role required a strong understanding and interest of the latest security standards, systems, protocols, and products.

What you'll be doing

Work directly with software developers in building a security by design mindset by defining implementations and coding inline with the Application Security Program mandates

Implement secure code solutions, design patterns, and code guidelines that meet security and privacy requirements defined in the security plans, risk assessments, policies, and procedures

Support security project governance through scheduling activities, planning and prioritization

Proactively drive security solutions implementation in-alignment with the development leads, security architects and product owner(s)

Drive feature implementations in line with the architecture via designs, coding, reviews and tests. Perform Proof of Concept (POC) activities as necessary

Review, Analyze and mitigate SAST, DAST, SCA, and penetration test results in collaboration with the developers for various non-medical and software as medical devices (SaMD) product lifecycles

Review current software security control measures and implement security enhancements for multiple cloud-based products

Participate in post-market product analysis to support vulnerability investigations as required as well as be engaged in continuous security monitoring

What you'll bring

Experienced security developer able to interpret and guide software development teams on secure coding practices and application security test report interpretation for various coding languages and multiple cloud services

Strong knowledge of secure software development lifecycle and practices including SAFe / Agile methodologies for software development

Understanding of security by design principles and architecture level security concepts

Sound understanding and experience in implementing security technologies / techniques like Cryptographic Algorithms / Cipher Suites, Public key Infrastructure (PKI)), network security protocols, OAuth, 2-factor authentication, and data at rest encryption standards

Experience implementing OWASP Top10 application security guidelines in cloud-based web applications

Experience with cloud-based design and security controls (e.g. network security, instance hardening, identify and access control, cloud environment configuration best practices)

Experienced in generating, defining, and reviewing penetration test results through knowledge of standard methodologies and tools including environmental configuration definition, security analysis, threat modeling, and system security audits

Knowledge of current and emerging security threats and techniques for exploiting security vulnerabilities

Exposure to international privacy requirements & cross-industry trends

Qualifications and Skills

Bachelor's degree in Computer Science, a related field or equivalent demonstrated experience and knowledge

Minimum 8+ years of experience in software development or related fields.

Minimum 5 years technical experience implementing product security requirements in cloud / hosted server environment

4 years working with each of the following :

Software development experience using web / application software technologies such as C / C++, Java, .Net, python, etc.

Experience analyzing, interpreting, and mitigating security findings from multiple sources including SAST, DAST, SCA and penetration tests.

AWS network security controls

Vantive is committed to supporting the needs for flexibility in the workplace. We do so through our flexible workplace policy which includes a minimum of 3 days a week onsite. This policy provides the benefits of connecting and collaborating in-person in support of our Mission.

We understand compensation is an important factor as you consider the next step in your career. At Vantive, we are committed to equitable pay for all employees, and we strive to be more transparent with our pay practices. The estimated base salary for this position is $128,000 - $192,000 annually. The estimated range is meant to reflect an anticipated salary range for the position. We may pay more or less than the anticipated range based upon market data and other factors, all of which are subject to change. Individual pay is based on upon location, skills and expertise, experience, and other relevant factors. For questions about this, our pay philosophy, and available benefits, please speak to the recruiter if you decide to apply and are selected for an interview.

US Benefits at Vantive

This is where your well-being matters. Vantive offers comprehensive compensation and benefits packages for eligible roles. Our health and well-being benefits include medical, dental and vision coverage that start on day one, as well as insurance coverage for basic life, accident, short-term and long-term disability, and business travel accident insurance. Financial and retirement benefits include the Aon Pooled Employer Plan (“Aon PEP”), Vantive’s 401(k) retirement savings plan, to help you prepare for your future. The Aon PEP is designed to help improve retirement outcomes by providing retirement resources more efficiently. The plan offers a robust set of investment options, financial education, and a suite of resources to support your retirement goals.

We also offer Flexible Spending Accounts, educational assistance programs, and time-off benefits such as paid holidays, paid time off ranging from 20 to 35 days based on length of service, family and medical leaves of absence, and paid parental leave. Additional benefits include commuting benefits, the Employee Discount Program, the Employee Assistance Program (EAP), and childcare benefits. Join us and enjoy the competitive compensation and benefits we offer to our employees. For additional information regarding Vantive’s US Benefits, please speak with your recruiter or visit our Benefits site : Benefits | Vantive

Equal Employment Opportunity

Vantive is an equal opportunity employer. Vantive evaluates qualified applicants without regard to race, color, religion, gender, national origin, age, sexual orientation, gender identity or expression, protected veteran status, disability / handicap status or any other legally protected characteristic.

Know Your Rights : Workplace Discrimination is Illegal

Reasonable Accommodation

Vantive is committed to working with and providing reasonable accommodations to individuals with disabilities globally. If, because of a medical condition or disability, you need a reasonable accommodation for any part of the application or interview process, please click on the link here and let us know the nature of your request along with your contact information. Form Link

Recruitment Fraud Notice

Vantive has discovered incidents of employment scams, where fraudulent parties pose as Vantive employees, recruiters, or other agents, and engage with online job seekers in an attempt to steal personal and / or financial information. To learn how you can protect yourself, review our Recruitment Fraud Notice .

Create a job alert for this search

Principal Security Engineer • Plymouth, MN, US

Related jobs
  • Promoted
Program Manager (Information Security)

Program Manager (Information Security)

Diverse LynxMinneapolis, MN, US
Full-time
Program Management experience 10+ years, Knowledge of Info Security Program Management, Excellent communications skills and Stakeholder Management. Proficiency in MS Office Diverse Lynx LLC is an Eq...Show moreLast updated: 30+ days ago
  • Promoted
Senior Fire Alarm Project Manager

Senior Fire Alarm Project Manager

Integrated Building SolutionsAnoka County, MN, US
Full-time
If you’re tired of being a small player in a big company, Integrated Building Solutions (“IBS”) might be the place for you to be seen, heard, and contribute.We are a small company...Show moreLast updated: 30+ days ago
  • Promoted
Security Systems Engineer l

Security Systems Engineer l

Paladin TechnologiesBurnsville, MN, US
Full-time
As a Systems Engineer, you will perform discovery and analysis of business and contractual requirements to define systems and sub-systems architecture and technical design packages.This position wo...Show moreLast updated: 30+ days ago
  • Promoted
Critical Operations Manager

Critical Operations Manager

Meta PlatformsRosemount, MN, US
Full-time
Meta is seeking a Critical Operations Manager to join our Data Center Operations team.Our data centers serve as the foundation upon which our software operates to meet the demands of our customers....Show moreLast updated: 30+ days ago
  • Promoted
Managing Director, Forensics

Managing Director, Forensics

BDO USAMinneapolis, MN, US
Full-time
Job Summary : The Managing Director is responsible for developing business through relationships, contacts, and other opportunities and leading, managing, and directing staff in performing analysis,...Show moreLast updated: 30+ days ago
  • Promoted
Sr Software Safety Engineer

Sr Software Safety Engineer

Lancesoft INCSaint Paul, MN, US
Full-time
In this exciting role as a Software Safety Engineer II, you will have responsibility for ensuring our products exceed the safety and reliability requirements and expectations of patients, clinician...Show moreLast updated: 20 days ago
  • Promoted
Senior Security Consultant (AI / ML Penetration Testing)

Senior Security Consultant (AI / ML Penetration Testing)

NetSPI LLCMinneapolis, MN, US
Full-time
NetSPI® is an award-winning pioneer of Penetration Testing as a Service (PTaaS) with its AI-powered platform supported by more than 350 in-house cybersecurity experts.Specializing in 50+ pentes...Show moreLast updated: 30+ days ago
  • Promoted
Enterprise Security Services Manager

Enterprise Security Services Manager

Xcel EnergyMinneapolis, MN, US
Full-time
Enterprise Security Services Position.Are you looking for an exciting job where you can put your skills and talents to work at a company you can feel proud to be a part of? Do you want a workplace ...Show moreLast updated: 11 days ago
  • Promoted
Internal Controls System Manager

Internal Controls System Manager

Paladin TechnologiesBurnsville, MN, US
Full-time
Internal Controls System Manager.This role works closely with cross-functional teams to identify control gaps, assess risks, and drive continuous improvement in internal controls, ultimately safegu...Show moreLast updated: 4 days ago
  • Promoted
Senior Security Consultant (Secure Code Review)

Senior Security Consultant (Secure Code Review)

NetSPI LLCMinneapolis, MN, US
Full-time
NetSPI® is an award-winning pioneer of Penetration Testing as a Service (PTaaS) with its AI-powered platform supported by more than 350 in-house cybersecurity experts.Specializing in 50+ pentes...Show moreLast updated: 19 days ago
  • Promoted
Executive Protection - Senior Security Manager

Executive Protection - Senior Security Manager

Medtronic PlcMinneapolis, MN, US
Full-time
Executive Protection And Security Planning.At Medtronic, you can begin a life-long career of exploration and innovation, while helping champion healthcare access and equity for all.You'll lead with...Show moreLast updated: 30+ days ago
  • Promoted
Director of Product Management - Video Surveillance

Director of Product Management - Video Surveillance

Resideo TechnologiesMinneapolis, MN, US
Full-time
Director of Product Management Video Surveillance.Resideo's Products & Solutions business is seeking a Director of Product Management Video Surveillance to drive the growth and expansion of our p...Show moreLast updated: 30+ days ago
  • Promoted
  • New!
Lead Security Engineer - SAP

Lead Security Engineer - SAP

GlobalSource ITSt Paul, MN, United States
Full-time
The Lead Security Engineer – SAP is responsible for driving the design, implementation, and optimization of enterprise SAP systems with a focus on security, scalability, and performance.This role c...Show moreLast updated: 7 hours ago
  • Promoted
Sr. Compliance Analyst, Customer Complaints

Sr. Compliance Analyst, Customer Complaints

OsaicSaint Paul, MN, US
Full-time
Senior Compliance Analyst, Customer Complaints.Osaic is seeking an organized, detail-oriented and energetic Senior Compliance Analyst to join our Customer Complaint team. This individual will play a...Show moreLast updated: 5 days ago
  • Promoted
Senior Corporate Security Manager - Eden Prairie or Minnetonka, MN - 2287235

Senior Corporate Security Manager - Eden Prairie or Minnetonka, MN - 2287235

UnitedHealth GroupCircle Pines, MN, US
Full-time
Senior Corporate Security Manager.UnitedHealth Group is a health care and well-being company thats dedicated to improving the health outcomes of millions around the world.We are comprised of two di...Show moreLast updated: 30+ days ago
  • Promoted
IT Internal Audit Associate Director - Eden Prairie, MN Hybrid - 2301755

IT Internal Audit Associate Director - Eden Prairie, MN Hybrid - 2301755

UnitedHealth GroupCircle Pines, MN, US
Full-time
UnitedHealth Group is a health care and well-being company thats dedicated to improving the health outcomes of millions around the world. We are comprised of two distinct and complementary businesse...Show moreLast updated: 30+ days ago
information security program manager

information security program manager

Purple DriveMINNEAPOLIS, Minnesota, USA
Full-time
Lead the planning, execution, and delivery of cross-functional information security programs and projects.Collaborate with security, IT, legal, compliance, and business stakeholders to define progr...Show moreLast updated: 30+ days ago
  • Promoted
Vice President, Chief Privacy Officer

Vice President, Chief Privacy Officer

Thomson ReutersSaint Paul, MN, US
Full-time
Vice President, Chief Privacy Officer.Thomson Reuters is seeking an experienced Vice President, Chief Privacy Officer to lead our organization's comprehensive privacy strategy and program.This role...Show moreLast updated: 30+ days ago