368,611open jobs
9,439companies
50,719added this week
Browse all
Salary
$106k – $169k per year
Location
In office (Irvine)
Seniority
Junior · 2+ years exp
Employment
Full-Time
Overview
Company
Impact
Profile match
BDX (Builders Digital Experience) is a digital marketing and media solutions provider tailored for the residential construction industry. The company offers virtual tour tools, interactive site plans, and listing services that connect homebuilders with prospective homebuyers. Through its technology platforms, it helps builders showcase new home communities and streamline the digital sales journey.

We are the people who give possibilities purpose

BD is one of the largest global medical technology companies in the world. Advancing the world of health™ is our Purpose, and it’s no small feat. It takes the imagination and passion of all of us-from design and engineering to the manufacturing and marketing of our billions of MedTech products per year-to look at the impossible and find transformative solutions that turn dreams into possibilities.

Job Description

Summary:

The Product Security Engineer (Embedded) is responsible forsupporting the security of BD's physical, IoT, and embedded medical devices- including embedded Linux and Windows-based platforms- or a subset of features within the product, across the engineering and product development lifecycle.This individual contributes to the delivery of secure products consistent with global regulatory requirements by executing product security program activities under the guidance of senior team members.

This role works in partnership with R&D and other stakeholders to support compliance with security technical requirements and reduce security risks within the product or feature set.This includes hands-on execution of product security activities such as threat modeling, vulnerability scanning and remediation, and security risk assessments. The successful candidate will apply developing technical expertiseto evaluate security vulnerabilities and contribute to maintainable technical solutions. Collaboration with software engineers and R&D team members in a dynamic and agile development environment is essential. Having demonstratedpositive work ethicand commitment to achieving project goals with strong collaboration and communication skills - both written and verbal - is key for success in this role.

The Product Security Office (PSO) ensures product security risks for BD’s software-based products and solutions are managed well over the lifecycle as they make a difference for our patients and customers. In the PSO, we offer flexibility so you can successfully balance your work and personal responsibilities.We care about our associates and ensure we have servant leaders to help you grow your career, provide feedback and recognition, and empower you to show up every day as your authentic self. We are passionate about improving patient outcomes and enabling our R&D teams to create and maintaininnovative solutions in a secure manner. Armed with a growth mindset and a desire to want to do more, learn more, impact more, you are in a great position to join us and help BD advance the world of health in ways you may never have imagined in your career.

Responsibilities:

  • Security Requirements & Implementation: Support project teams in defining and implementing security requirements and technologies for a product or set of features in accordance with industry standards for medical devices, including encryption, authentication, audit logging, hardening measures, SBOM creation and composition, patch management, vulnerability monitoring, and antivirus/antimalware as applicable.

  • Cryptography & PKI: Support the selection and implementation of appropriate cryptographicalgorithms, key management practices, and certificate lifecycle management (issuance, renewal, revocation) for devices and cloud-connected components.

  • Secure Communications: Evaluate and support secure communication implementations across device interfaces and network protocols relevant to the product, including validation of TLS/mTLSconfigurations and medical or proprietary protocols as applicable.

  • Embedded & Firmware Security: Support hardening of embedded Linux,Windows, and RTOS-based device platforms, including secure boot,firmware integrity, hardware attack surface reduction, and physical/IoTdevice engineering practices across the product development lifecycle.

  • Cloud & API Security: Assist in identifyingand addressing security risks in cloud-connected device backends and associated APIs, including authentication, authorization, and protection of data in transit and at rest.

  • Design Reviews: Participatein technical design reviews and code inspections, providing feedback to project team members and following proper coding practices.

  • Security Assessments: Support execution of product security risk assessments, hazard analysis, and vulnerability remediation activities in coordination with product development software engineers.

  • Process & Documentation: Assist product development teams in complying withproduct security framework activities and contributing to security documentation, including Incident and Vulnerability Management Plans and Product Security White Papers.

  • Incident Response: Participatein product security incident response activities as appropriate.

  • Training & Procedures: Where applicable, support the deployment of software engineering procedures and training related to vulnerability scanning and static code analysis tools.

  • Automated Testing: Where applicable, assistR&D teams in implementing systems for automated testing of software vulnerabilities and verification of OS security patches.

  • Quality Assurance: Where applicable, contribute to quality in R&D security test deliverables, including design, data summary, report preparation, and review for adherence to applicable regulations.

  • May perform other duties as required.

Minimum Required:

  • Undergraduate degree in computer engineering, cybersecurity, computer science,or related technical field.

  • Hands-on experience with embedded Linux, Windows Embedded/IoT, or RTOS-based systems, including familiarity with C/C++ in an embedded security engineering context.

  • Minimum of 2+ years in product security, product development, software development, or quality assurance.

  • Foundational knowledge of information security standards for product development.

  • Based in or in a commutable distance to the Irvine California area

Preferred Knowledge, Skills:

  • Master’s degree (cybersecurity, computer science, software engineering) with minimum of 2 years of industry experience

  • Exposure to embedded/firmware security tooling and techniques, such as firmware image analysis, JTAG/SWD hardware debugging, and staticanalysis for C/C++embedded codebases.

  • Familiarity with product cybersecurity requirements in the context of 510(k) and/or PMA-regulated products.

  • Developing experience assessing security risks using industry standard methods (penetration test results, threat modeling, security testing) and applyingcompensating security controls.

  • Foundational competence in threat modeling software systems or software-enabled products using industry standard methods (STRIDE, PASTA, NIST, OWASP).

  • Understanding ofapplied cryptography fundamentals: algorithm and mode selection, key length, hashing, and secure key storage practices.

  • Familiarity with PKI concepts including CA hierarchies, certificate lifecycle management, and revocation mechanisms (CRL/OCSP).

  • Familiarity with securing network communications, including TLS/mTLSconfiguration and validation, and medical or device-specific protocols (e.g., HL7, FHIR, Bluetooth LE) as applicable.

  • Foundational awareness of cloud and API security principles, including authentication/authorization patterns and protection of PHI/PII in cloud-connected product architectures.

  • Exposure to cybersecurity tooling such as Black Duck, Coverity, Veracode, Nessus, Snyk, or Metasploit.

  • Experience working within a structured software development lifecycle process; agile methodology.

  • Experience withconnected products, software development, lifecycles, network technologies, or regulated environments.

  • Experience with configuration and use of static code analysis and vulnerability scanning tools.

  • Foundational understanding of applied cryptography and PKI concepts (cipher selection, key management, certificate lifecycle).

  • Certifications such as CCNA, CISSP, CISM, GIAC, CCSP, CEH

Why Join Us?

To find purpose in the possibilities, we need people who can see the bigger picture, who understand the human story that underpins everything we do. We welcome people with the imagination and drive to help us reinvent the future of healthcare. At BD, you’ll discover a culture in which you can learn, grow and thrive.

We believe that when people connect in person, we learn faster, collaborate more deeply, and build a stronger culture. Join us and enjoy a culture where face-to-face collaboration supports your learning, your progress, and your success.

To learn more about BD visithttps://bd.com/careers.

Becton, Dickinson, and Company is an Equal Opportunity Employer. We evaluate applicants without regard to race, color, religion, age, sex, creed, national origin, ancestry, citizenship status, marital or domestic or civil union status, familial status, affectional or sexual orientation, gender identity or expression, genetics, disability, military eligibility or veteran status, and other legally protected characteristics.

Required Skills

Optional Skills

.

Primary Work Location

USA CA - Irvine Laguna Canyon

Additional Locations

Work Shift

At BD, we reward, support and develop our associates through our comprehensive Total Rewards program. We are committed to attracting and retaining high quality talent by providing reward and recognition opportunities that promote a performance-based culture, as well as a competitive package of compensation and benefits programs. You can learn more on our career site under " Our Commitment to You."

Our salary or hourly rate ranges reward associates fairly and competitively. We regularly review these ranges and factors, such as location, contribute to the range displayed.

Our pay is based on the role and the necessary skills and education to perform it successfully. The salary or hourly rate offered is determined by the role's specific requirements, including any applicable step rate pay system at the work location. Salary or hourly pay ranges are influenced by labor laws and Collective Bargaining Agreement (CBA) requirements applicable to the work location which may also affect the workplace arrangement of the role.

Salary Range Information

$105,500.00 - $168,800.00 USD Annual
Free account
Stop reading job ads. Get the ones that fit.
One free account turns this page into a shortlist built around your stack, your level and your pay.
Match on every job. Stack, seniority, pay and location, scored against your profile.
368,611 open roles. Read straight off company career pages, refreshed every day.
Unlimited applications. Every one you send is tracked in one place, on-site or on a company board.
3 tailored CVs a month. Rewritten for the exact job you are applying to. Included free.
Create a free account
Free forever. No card. Under a minute.

Your match

How well do you fit this role?
Two answers are enough for a real match. No account needed.
Check my fit
Answers stay in this browser until you create an account.

Recommended for you based on this role

Similar stack
Same company
Irvine
$48k – $112k per year (Estimated) • In office • Full-Time • Master's Degree • Toronto
C++
MATLAB
Python
Apply
$48k – $90k per year (Estimated) • Remote/Hybrid • Full-Time • Nice
C++
Apply
$175k – $250k per year • Remote/Hybrid • Full-Time • 4+ years exp • Master's Degree • New York
C++
Python
SQL
C++
PyTorch C++
TensorFlow C++
AI/ML
PyTorch
Scikit-learn
TensorFlow
Apply
$124k – $208k per year • In office • Full-Time • 2+ years exp • Bachelor's Degree • Austin • San Jose
C++
Python
SystemVerilog
Chips/EDA
Formal Verification
Apply
$71k – $112k per year • In office • Full-Time • 5+ years exp • Bachelor's Degree • Austria
C#
C++
Python
Visual Basic
Apply
$162k – $307k per year (Estimated) • In office • Full-Time • 12+ years exp • Bachelor's Degree • Warwick
Apply
$118k – $189k per year • In office • Full-Time • 7+ years exp • Bachelor's Degree • Sparks
Apply
$60k – $119k per year (Estimated) • In office • Full-Time • 1+ year exp • High School Diploma • El Paso
Cybersecurity
CAPA
Apply
$154k – $247k per year • In office • Full-Time • 8+ years exp • Bachelor's Degree • Franklin Lakes
Python
SQL
Databases
Databricks
Analytics
Power BI
Apply
$148k – $253k per year (Estimated) • In office • Full-Time • 3+ years exp • Bachelor's Degree • El Paso
Apply
$84k – $126k per year • Equity • In office • Full-Time • 2+ years exp • High School Diploma • Lafayette • Tempe • Irvine • Santa Ana
Apply
$183k – $275k per year • Equity • In office • Full-Time • 10+ years exp • High School Diploma • Fort Worth • Minneapolis • Irvine • Jacksonville • Boston
DevOps
IAM
Cybersecurity
Least Privilege
Zero Trust
Apply
$70k – $196k per year • Remote/Hybrid • Full-Time • 12+ years exp • Associate's Degree • Chicago • Milwaukee • Dallas • Columbus • Kirkland
Databases
Databricks
Google BigQuery
SAP HANA
Snowflake
AI/ML
Knowledge Graph
DevOps
Azure
Apply
$70k – $196k per year • Remote/Hybrid • Full-Time • 5+ years exp • Associate's Degree • Chicago • Milwaukee • Dallas • Columbus • Kirkland
DevOps
SLI/SLO/SLA
Apply
$136k – $226k per year • In office • Full-Time • 8+ years exp • Bachelor's Degree • Irvine
Apply
See all jobs
This is one of many
368,611 more open roles from verified company boards, updated every day.