Staff DevSecOps Engineer– Medical Devices

Analog Devices
  • Wilmington, Massachusetts
    6 days ago

    Job Description

    About Analog Devices

    Analog Devices, Inc. (NASDAQ: ADI) is a global semiconductor leader that bridges the physical and digital worlds to enable breakthroughs at the Intelligent Edge. ADI combines analog, digital, AI, and software technologies into solutions that combat climate change, reliably connect humans and the world, and help drive advancements in automation and robotics, mobility, healthcare, energy and data centers. With revenue of more than $11 billion in FY25, ADI ensures today's innovators stay Ahead of What's Possible. Learn more at www.analog.com and on LinkedIn and X.

              

    Staff DevSecOps Engineer– Medical Devices

    The Health Solutions Business Unit at Analog Devices is seeking a DevSecOps Engineer to support the development and operation of secure cloud-native platforms for connected medical devices and digital health solutions.

    The successful candidate will contribute to the implementation of secure software development practices, cloud security controls, software supply chain security, and regulatory compliance activities throughout the product lifecycle. This role requires strong experience with AWS cloud environments, CI/CD pipelines, application security, and healthcare software platforms, along with deep expertise in HIPAA compliance, healthcare data protection, cloud security, and cybersecurity requirements for FDA-regulated medical devices. The ideal candidate is a hands-on engineer with experience securing modern cloud applications, automating security processes, and supporting regulated software products from development through deployment and post-market operations.

    Key Responsibilities

    • Implement and maintain security controls across AWS cloud environments supporting connected medical devices, Software as a Medical Device (SaMD), and digital health solutions.
    • Integrate and manage security capabilities within CI/CD pipelines and Secure Software Development Lifecycle (SSDLC) processes, including secure coding practices, SAST, DAST, SCA, secrets scanning, container security scanning, and Infrastructure-as-Code security validation.
    • Manage software supply chain security activities, including SBOM generation, dependency management, artifact integrity validation, and vulnerability remediation.
    • Configure and maintain identity and access management, authentication, authorization, encryption, key management, and secrets management solutions across cloud and application environments.
    • Design and maintain audit logging, monitoring, and security controls supporting HIPAA compliance and healthcare data protection requirements.
    • Partner with software engineering teams to identify, prioritize, and remediate security vulnerabilities throughout the product lifecycle.
    • Support security risk assessments, penetration testing activities, vulnerability management, incident response, and operational security efforts.
    • Build and maintain security automation capabilities to improve platform security, compliance, and operational efficiency.
    • Support the reliability, availability, monitoring, and operational readiness of cloud-based production systems.

    Requirements

    • Bachelor's, Master's, or Ph.D. degree in Cybersecurity, Computer Science, Software Engineering, Computer Engineering, Information Security, or a related technical discipline.
    • 7+ years of experience in DevSecOps, Cloud Security, Security Engineering, Application Security, or related technical roles.
    • Experience supporting software development for healthcare products, medical devices, or digital health solutions within established quality and compliance frameworks.
    • Strong experience securing cloud-native applications and platforms running on AWS.
    • Hands-on experience with AWS services such as ECS, EKS, Lambda, RDS, S3, SQS, Cognito, IAM, KMS, CloudFormation, and related cloud technologies.
    • Experience implementing and managing CI/CD pipelines using GitHub Actions or similar platforms.
    • Experience with security tooling including SAST, DAST, SCA, container security scanning, secrets detection, Infrastructure-as-Code security scanning, and vulnerability management solutions.
    • Strong understanding of application security principles, secure coding practices, authentication, authorization, encryption, secrets management, and key management.
    • Experience with software supply chain security concepts, including SBOM generation, dependency management, artifact signing, and vulnerability remediation.
    • Experience with Infrastructure as Code technologies such as Terraform, CloudFormation, or AWS CDK.
    • Strong understanding of OWASP guidance, cloud security best practices, and secure software development methodologies.
    • Experience with containerized applications and orchestration platforms such as ECS, EKS, Kubernetes, or similar technologies.
    • Experience implementing and supporting HIPAA-compliant cloud environments and healthcare data protection controls.
    • Experience supporting security and compliance programs aligned with frameworks such as ISO 27001, SOC 2, or similar industry standards.
    • Strong analytical, problem-solving, communication, and collaboration skills.

    Additional Desired Skills and Qualifications

    • Experience supporting FDA-regulated products and familiarity with IEC 62304, ISO 14971, FDA Cybersecurity Guidance, and related healthcare software development standards.
    • Experience supporting cloud platforms that enable AI-powered or AI-assisted healthcare solutions.
    • Proven track record of successfully delivering secure cloud-based software products and improving security posture through automation and DevSecOps practices.
    • Professional certifications such as CISSP, CSSLP, AWS Security Specialty, Security+, Certified Kubernetes Security Specialist (CKS), or equivalent.

    For positions requiring access to technical data, Analog Devices, Inc. may have to obtain export  licensing approval from the U.S. Department of Commerce - Bureau of Industry and Security and/or the U.S. Department of State - Directorate of Defense Trade Controls.  As such, applicants for this position – except US Citizens, US Permanent Residents, and protected individuals as defined by 8 U.S.C. 1324b(a)(3) – may have to go through an export licensing review process.

    Analog Devices is an equal opportunity employer. We foster a culture where everyone has an opportunity to succeed regardless of their race, color, religion, age, ancestry, national origin, social or ethnic origin, sex, sexual orientation, gender, gender identity, gender expression, marital status, pregnancy, parental status, disability, medical condition, genetic information, military or veteran status, union membership, and political affiliation, or any other legally protected group.

    EEO is the Law: Notice of Applicant Rights Under the Law.

    Job Req Type: Experienced

              

    Required Travel: Yes, 10% of the time

              

    Shift Type: 1st Shift/Days

    The expected wage range for a new hire into this position is $134,644 to $201,966.

    • Actual wage offered may vary depending on work location, experience, education, training, external market data, internal pay equity, or other bona fide factors.

    • This position qualifies for a discretionary performance-based bonus which is based on personal and company factors.

    • This position includes medical, vision and dental coverage, 401k, paid vacation, holidays, and sick time, and other benefits.

    Numbers & Facts

    LocationWilmington, Massachusetts
    Websiteanalog.com/en.html

    Skills

    • AWS Lambdaunmatched
    • Amazon Simple Storage Service (S3)unmatched
    • Amazon Web Services (AWS)unmatched
    • Analysis Skillsunmatched
    • Applications Securityunmatched
    • Artificial Intelligence (AI)unmatched
    • Authenticationunmatched
    • Automationunmatched
    • Best Practicesunmatched
    • CISSP - Certified Information Systems Security Professionalunmatched
    • Climate Changeunmatched
    • Cloud Applicationsunmatched
    • Cloud Computingunmatched
    • CompTIA Security+unmatched
    • Computer Engineeringunmatched
    • Computer Scienceunmatched
    • Computer Securityunmatched
    • Continuous Deployment/Deliveryunmatched
    • Continuous Integrationunmatched
    • Cryptographyunmatched
    • Environmental Healthunmatched
    • Establish Prioritiesunmatched
    • FDA (Food and Drug Administration)unmatched
    • FDA Requirementsunmatched
    • GitHubunmatched
    • HIPAA (Health Insurance Portability and Accountability Act)unmatched
    • Healthcareunmatched
    • Healthcare Softwareunmatched
    • ISO (International Organization for Standardization)unmatched
    • Identity Data Managementunmatched
    • Incident Responseunmatched
    • Industry Standardsunmatched
    • Information/Data Security (InfoSec)unmatched
    • International Electro-Technical Commission (IEC)unmatched
    • Internet Securityunmatched
    • Licensingunmatched
    • LinkedInunmatched
    • Machine Toolunmatched
    • Medical Conditionsunmatched
    • Medical Equipmentunmatched
    • Medical Geneticsunmatched
    • Medical Productsunmatched
    • Militaryunmatched
    • Network Operations Centerunmatched
    • Operational Strategyunmatched
    • Operations Security (OPSEC)unmatched
    • Penetration Testingunmatched
    • Problem Solving Skillsunmatched
    • Product Lifecycleunmatched
    • Product Supportunmatched
    • Production Systemsunmatched
    • Regulatory Complianceunmatched
    • Risk Analysisunmatched
    • Roboticsunmatched
    • Secure Codingunmatched
    • Security Analysisunmatched
    • Security Infrastructureunmatched
    • Security Monitoringunmatched
    • Security Softwareunmatched
    • Semiconductorsunmatched
    • Simple Queue Service (SQS)unmatched
    • Software Administrationunmatched
    • Software Developmentunmatched
    • Software Development Lifecycle (SDLC)unmatched
    • Software Engineeringunmatched
    • Supply Chainunmatched
    • Supply Chain Managementunmatched
    • Team Playerunmatched
    • Vulnerability Scannersunmatched
    • Willing to Travelunmatched

    Be found by employers

    5,500+ employers search our resume database daily. Add yours to get found by recruiters looking for candidates like you.

    Level up your application

    Professional resume templates

    Browse dozens of recruiter approved resume templates, layouts and formats. Choose your favorite and make it your own in minutes.

    Free resume templates

    Free resume builder

    Improve your existing resume or start from scratch and create a standout, ATS-friendly resume. Add job-specific content, download and apply.

    Free resume builder