Let’s get started
By clicking ‘Next’, I agree to the Terms of Service
and Privacy Policy, and consent to receive emails from Rise
Jobs / Job page
Senior Product Security Engineer - Vulnerability Management image - Rise Careers
Job details

Senior Product Security Engineer - Vulnerability Management

Company Description

It started with a simple idea: what if surgery could be less invasive and recovery less painful? Nearly 30 years later, that question still fuels everything we do at Intuitive. As a global leader in robotic-assisted surgery and minimally invasive care, our technologies—like the da Vinci surgical system and Ion—have transformed how care is delivered for millions of patients worldwide.

We’re a team of engineers, clinicians, and innovators united by one purpose: to make surgery smarter, safer, and more human. Every day, our work helps care teams perform with greater precision and patients recover faster, improving outcomes around the world.

The problems we solve demand creativity, rigor, and collaboration. The work is challenging, but deeply meaningful—because every improvement we make has the potential to change a life.

If you’re ready to contribute to something bigger than yourself and help transform the future of healthcare, you’ll find your purpose here.

Job Description

Primary Function:
The Product Cybersecurity Team is responsible for the security lifecycle of medical devices, software
products, infrastructure, cloud services, and IoMT solutions that generate, collect and analyze medical
device machine data from thousands of systems deployed world-wide.


The ideal candidate for the position of Senior Product Security Engineer is an accomplished security engineer,
with demonstrated experience in the secure design, development, and management of complex medical
device applications and systems. The candidate has solid cybersecurity knowledge, comprising detailed
understanding of cybersecurity threats, secure software design principles, secure coding practices and
knowledge of cryptographic tools and libraries. The candidate can review product cybersecurity
vulnerabilities; can recommend improvements in security design, and can support remediation. The
candidate routinely conducts threat modeling, vulnerability management, and product line security
management activities.


This position requires a candidate with strong technical and interpersonal skills, the ability to work
effectively and collaboratively with the business and peer Engineering teams to deliver high quality
solutions that ensure patient safety

What you’ll do

  • Own and operate the post-market vulnerability management lifecycle across Intuitive products and services, from intake through remediation and closure
  • Perform and operationalize ongoing vulnerability scanning for internal and external assets, including medical devices, digital applications, infrastructure, cloud services, and IoMT solutions
  • Manage monthly, quarterly, and annual vulnerability scans and penetration tests, including coordination with third-party providers to meet regulatory and compliance requirements
  • Define scan scope, rules of engagement, and schedules with external vendors to ensure coverage, quality, and on-time delivery
  • Analyze vulnerability findings to assess real-world risk, prioritizing issues based on exploitability, exposure, patient safety, and business impact
  • Review and synthesize results from scans and penetration tests, delivering clear, prioritized remediation guidance to engineering and product stakeholders
  • Track remediation activities to completion, ensuring alignment with compliance obligations and internal risk acceptance criteria
  • Maintain vulnerability inventories, repositories, and metrics to support ongoing reporting and audits
  • Prepare and deliver vulnerability reports, dashboards, and technical risk evaluations for monthly, quarterly, and annual reviews
  • Support risk-based vulnerability assessments across the post-market product portfolio
  • Conduct ad-hoc vulnerability scans and analyses in support of incident response, customer inquiries, and emerging threat activity
  • Identify vulnerability trends and patterns to inform preventative controls and long-term risk reduction
  • Advise remediation teams on effective mitigation strategies and secure engineering practices
  • Support the development, maintenance, and monitoring of Software Bills of Materials (SBOMs) as part of vulnerability tracking and reporting
  • Contribute to the design, improvement, and operation of vulnerability management processes, standards, and security policies
  • Maintain vulnerability management procedures and playbooks, supporting leadership, service teams, and audit stakeholders
  • Partner closely with Product Security, Engineering, Quality, Incident Response, and service teams through regular check-ins and coordinated execution
  • Support incident response activities and investigations related to product vulnerabilities
  • Help elevate organizational awareness of emerging threats and in-market vulnerabilities, and how Intuitive proactively manages risk

What you’ll bring

  • Hands-on experience owning post-market vulnerability management or product security workflows in a regulated or safety-critical environment
  • Strong understanding of vulnerability lifecycles, including intake, triage, validation, prioritization, remediation tracking, verification, and reporting
  • Practical experience assessing real-world risk using frameworks such as CVE, CVSS, CWE, OWASP Top 10, and SANS guidance
  • Experience coordinating third-party security assessments, including vulnerability scanning and penetration testing engagements
  • Ability to translate technical findings into clear, actionable remediation guidance for engineering and product teams
  • Strong judgment in balancing security risk, compliance requirements, and product realities
  • Familiarity with secure software design principles, secure coding practices, and threat modeling
  • Working knowledge of cryptographic tools, libraries, and common security controls
  • Experience supporting audit, compliance, and regulatory reporting related to product security
  • Exposure to SBOMs, third-party component risk, and software supply chain security
  • Comfort operating across hardware, software, firmware, and cloud environments, with the ability to learn new domains quickly
  • Strong analytical skills with a track record of solving complex technical and operational problems
  • Excellent collaboration and communication skills, with the ability to influence cross-functional teams without direct authority
  • Ability to manage multiple workstreams, vendors, and stakeholders while maintaining responsiveness and operational rigor
  • A mindset oriented toward continuous improvement, adaptability, and building scalable security processes

Qualifications

Qualifications 

Demonstrated technical knowledge and experience in the following areas: 

  • Experience in vulnerability management, information assurance, security operations, and penetration testing
  • Ability to plan, manage, and execute multiple tasks and projects within defined timelines
  • Operating the vulnerability scanning tool set – may include Qualys, Nessus, Gitlab, Black Duck, etc
  • Excellent verbal, written, and presentation communication skills. Ability to clearly articulate risk and provide actionable remediation guidance

Desired Qualifications:  

  • Bachelor’s degree or higher, preferred in Cybersecurity or a closely related field, or an equivalent combination of education, training, and experience
  • Current, relevant professional certifications, such as GPEN, GWAPT, GEVA, CEPT, OSCP, OSCE a plus
  • Prior experience in healthcare, medical device, or bioscience sectors a plus
  • Knowledge of the OWASP Top 10 
  • Demonstrated knowledge and skill in exploitation tactics including, but not limited to, buffer overflows, heap overflows, format string attacks, cross-site scripting, SQL injection, LFI and RFI, cross-site request forgery, server-side request forgery, XXE, pass-the-hash, ARP poisoning, wi-fi injection, phishing, credential harvesting, MiTM, AP spoofing, brute forcing, etc
  • Able to demonstrate risk with post-exploitation tactics such as pivoting, data scavenging, privilege escalation, etc
  • Familiarity of security concepts, e.g. best practices to protect CIA, types of security controls, CIS Top 20 Security Controls, risk management, risk analysis models, threat modeling, common vulnerability scoring system (CVSS)
  • Familiarity of the Cyber Kill Chain and MITRE ATT&CK frameworks 

• Travel: <10%
• Job location: Sunnyvale, CA or remote

Additional Information

Due to the nature of our business and the role, please note that Intuitive and/or your customer(s) may require that you show current proof of vaccination against certain diseases including COVID-19.  Details can vary by role.

Intuitive is an Equal Opportunity Employer. We provide equal employment opportunities to all qualified applicants and employees, and prohibit discrimination and harassment of any type, without regard to race, sex, pregnancy, sexual orientation, gender identity, national origin, color, age, religion, protected veteran or disability status, genetic information or any other status protected under federal, state, or local applicable laws.

Mandatory Notices

U.S. Export Controls Disclaimer:  In accordance with the U.S. Export Administration Regulations (15 CFR §743.13(b)), some roles at Intuitive Surgical may be subject to U.S. export controls for prospective employees
who are nationals from countries currently on embargo or sanctions status.

Certain information you provide as part of the application will be used for purposes of determining whether Intuitive Surgical will need to (i) obtain an export license from the U.S. Government on your behalf (note: the government’s licensing process can take 3 to 6+ months) or (ii) implement a Technology Control Plan (“TCP”) (note: typically adds 2 weeks to the hiring process).  

For any Intuitive role subject to export controls, final offers are contingent upon obtaining an approved export license and/or an executed TCP prior to the prospective employee’s
start date, which may or may not be flexible, and within a timeframe that does not unreasonably impede the hiring need. If applicable, candidates will be notified and instructed on any requirements for these purposes. 

We will consider for employment qualified applicants with arrest and conviction records in accordance with fair chance laws.

Preference will be given to qualified candidates who do not reside, or plan to reside, in Alabama, Arkansas, Delaware, Florida, Indiana, Iowa, Louisiana, Maryland, Mississippi, Missouri, Oklahoma, Pennsylvania, South Carolina, or Tennessee.

We provide market-competitive compensation packages, inclusive of base pay, incentives, benefits, and equity. It would not be typical for someone to be hired at the top end of range for the role, as actual pay will be determined based on several factors, including experience, skills, and qualifications. The target compensation ranges are listed.

Average salary estimate

$180000 / YEARLY (est.)
min
max
$150000K
$210000K

If an employer mentions a salary or salary range on their job, we display it as an "Employer Estimate". If a job has no salary data, Rise displays an estimate if available.

Similar Jobs
Photo of the Rise User
Posted 16 hours ago

Lead development of predictive analytics, ML models, and data pipelines that improve product performance and proactive service across Intuitive’s robotic surgery portfolio.

Photo of the Rise User
Posted 3 hours ago

Experienced systems engineer needed to design, automate, and support Windows server and virtual/cloud infrastructure for a leading medical robotics company.

Photo of the Rise User
Salesforce Hybrid California - San Francisco
Posted 22 hours ago
Inclusive & Diverse
Rise from Within
Mission Driven
Diversity of Opinions
Work/Life Harmony
Feedback Forward
Take Risks
Collaboration over Competition
Medical Insurance
Dental Insurance
Vision Insurance
Paid Time-Off
Maternity Leave
Paternity Leave
Mental Health Resources
Life insurance
Disability Insurance
Health Savings Account (HSA)
Flexible Spending Account (FSA)
Employee Resource Groups

Lead performance engineering at Salesforce to design high-scale automation, optimize systems and databases, and own the resolution of complex production performance issues.

Photo of the Rise User
Posted 13 hours ago

Lead the back-end engineering efforts at DataLab USA, driving complex API and cloud solutions while mentoring the development team and managing live deployments.

Photo of the Rise User

Visa's CMS Visa Direct SRE team is hiring a Senior System Reliability Engineer to lead L3 production support, incident response, and reliability improvements for global payment platforms.

Photo of the Rise User

Senior platform-focused DevOps leader needed to design scalable self-service tooling, drive automation, and improve delivery pipelines across cloud-native environments.

Photo of the Rise User

Quizlet is hiring a Site Reliability Engineer to strengthen cloud infrastructure reliability, automate operations, and scale services for millions of learners.

Posted 3 hours ago

Echo Neurotechnologies seeks a seasoned Software Test Engineer to drive automated integration testing and verification across cloud, desktop, and mobile components of its connected medical device platform.

Photo of the Rise User

Help design and scale a global crypto payments backend by building blockchain integrations and smart contract-driven services as a Remote Blockchain Software Engineer.

Posted 10 hours ago

Contract JavaScript Developer needed at Alignerr to evaluate and improve AI-generated frontend code and help train models through high-quality feedback and documentation.

Photo of the Rise User
Posted 13 hours ago
Inclusive & Diverse
Transparent & Candid
Growth & Learning
Collaboration over Competition

Senior Server Engineer II to join Strava’s B2B team in San Francisco, building scalable backend systems for sponsored experiences and mentoring engineers across the organization.

Alignerr is hiring a Senior C++ Full-Stack Engineer to build and optimize production C++ systems that power AI data pipelines and evaluation tooling on a remote, contract basis.

Photo of the Rise User
Posted 13 hours ago

Work on scalable backend systems and Kubernetes observability pipelines to help customers get unmatched insights into cloud cost.

Photo of the Rise User

Senior Software Engineer wanted to lead full‑stack, cloud‑native development and technical coaching for Hudl’s scalable sports analytics platform in a remote US role.

Senior Rust engineer needed to build and optimize distributed, high-performance systems and full-stack tooling for AI data and evaluation pipelines at a fast-moving research-focused company.

Founded in 1995, Intuitive Surgical, Inc develops, manufactures and markets robotic technologies designed to improve clinical outcomes and help patients return more quickly to active and productive lives. The company is headquartered in Sunnyvale,...

46 jobs
MATCH
Calculating your matching score...
FUNDING
SENIORITY LEVEL REQUIREMENT
TEAM SIZE
EMPLOYMENT TYPE
Full-time, hybrid
DATE POSTED
January 12, 2026
Risa star 🔮 Hi, I'm Risa! Your AI
Career Copilot
Want to see a list of jobs tailored to
you, just ask me below!