Job Information
Baxter Healthcare Corporation Senior Principal Product Security Engineer in SKANEATELES FALLS, New York
This is whereyour work makes a difference. At Baxter, we believe every person-regardless of who they are or where they are from-deserves a chance to live a healthy life. It was our founding belief in 1931 and continues to be our guiding principle. We are redefining healthcare delivery to make a greater impact today, tomorrow, and beyond. Our Baxter colleagues are united by our Mission to Save and Sustain Lives. Together, our community is driven by a culture of courage, trust, and collaboration. Every individual is empowered to take ownership and make a meaningful impact. We strive for efficient and effective operations, and we hold each other accountable for delivering exceptional results. Here, you will find more than just a job-you will find purpose and pride. Your Role at Baxter Secure technology that saves lives.In support of our mission to save and sustain lives, we take product security seriously. We're seeking a Sr Principal Cybersecurity Engineer to strengthen the cybersecurity of our diagnostic cardiology products and help shape the future of connected, lifecritical medical technology.In this role, you'll lead by example-driving secure design, influencing architecture, and mentoring engineers across teams. You'll work closely with product development to proactively identify risks, respond to emerging threats, and embed security into every stage of the software lifecycle. We offer a culture of trust, flexibility, and growth, where you manage your time and shape your career path. What you'll be doing * Define and document the security architecture and cybersecurity posture of lifecritical medical products * Lead threat modeling, interface analysis, and secure design reviews across product lines * Author product security whitepapers, technical documentation, and regulatoryfacing materials * Develop Manufacturer Disclosure Statements for Medical Devices (MDS) and related artifacts * Produce and interpret static code analysis and vulnerability assessment reports * Partner with development teams on security requirements and policies * Establish and drive governance around vulnerability management, from discovery through remediation * Support incident response, investigation, and recovery efforts in collaboration with crossfunctional teams * Use industryleading tools (e.g., Tenable Nessus, Fortify, Coverity) to identify, analyze, and mitigate risks * Monitor and assess zeroday threats and emerging vulnerabilities * Participate in security planning, project scoping, and delivery of security initiatives * Evaluate thirdparty and offtheshelf components to ensure secure use What you'll bring * Bachelor's degree in Computer Science or a related technical field * 8+ years of experience working within a secure software development life cycle (SSDLC) * Strong understanding of application security across the full software life cycle * Handson experience developing, reviewing, or enforcing secure coding practices * Familiarity with handling PHI and PII in regulated environments * Experience with threat modeling methodologies such as STRIDE, DREAD, LINDDUN, or PASTA * Proven ability to perform security risk assessments and clearly communicate risk and business impact * Experience analyzing, documenting, and remediating software and system vulnerabilities * Familiarity with industry standards and guidance including IEC TR 80001, NIST 80053, ISO/IEC 27001 & 27002 (preferred) * Expertise in designing secure networks, systems, and application architectures * 8+ years of experience working within a secure software development life cycle (SSDLC) * Strong understanding of application security across the full software life cycle * Handson experience developing, reviewing, or enforcing secure coding practices * Familiarity with handling PHI and PII in regulated environments * Experience with threat modeling methodologies such as STRIDE,