Firmware and Product Security Technical Lead
Description
Technical Lead - Firmware and Product Security (Level 5)
Position Summary
The Technical Lead - Firmware and Product Security (Level 5) is a senior role responsible for the architecture, development, verification, and lifecycle security of embedded firmware used in connected medical devices. This role establishes technical direction, leads complex and high-impact initiatives, and ensures that firmware and product-security controls are designed into products from concept through post-market support. The position partners across Systems, Hardware, Software, Quality, Regulatory, Information Security, Manufacturing, and Program Management to translate product and security needs into robust, maintainable, and compliant solutions. The lead remains hands-on in design, implementation, review, debugging, and risk resolution while mentoring engineers and raising organizational capability in secure product development.
Key Responsibilities
- Own the technical vision and roadmap for embedded firmware and product security across assigned connected medical-device platforms.
- Lead firmware architecture, requirements decomposition, interface definition, design reviews, implementation, integration, verification, and release readiness for safety- and business-critical features.
- Establish firmware architecture secure-by-design practices, including threat modeling, security risk assessment, attack-surface analysis, secure boot, authentication, cryptography, key management, access control, secure communications, logging, and secure update mechanisms.
- Translate system, clinical, user, safety, privacy, and cybersecurity needs into clear firmware requirements and testable acceptance criteria with bidirectional traceability.
- Provide hands-on technical leadership in C/C++, RTOS-based systems, device drivers, board bring-up, bootloaders, communication protocols, connectivity, diagnostics, and performance optimization.
- Drive disciplined engineering practices, including coding standards, peer reviews, static and dynamic analysis, unit and integration testing, automated builds, CI/CD, configuration management, and defect prevention.
- Lead technical investigations and root-cause analysis for complex firmware, hardware-interface, connectivity, performance, reliability, and security issues; ensure effective corrective and preventive actions.
- Partner with Quality and Regulatory teams to produce and maintain design history, software lifecycle, cybersecurity, risk-management, verification, and submission documentation consistent with applicable medical-device requirements.
- Support product-security activities throughout the lifecycle, including vulnerability monitoring, coordinated vulnerability response, third-party component assessment, software bill of materials governance, security testing, and post-market remediation.
- Evaluate technical tradeoffs involving safety, security, performance, power, memory, cost, schedule, manufacturability, serviceability, and long-term maintainability; communicate recommendations and business impact to stakeholders.
- Coordinate with internal teams, suppliers, and development partners to define deliverables, review designs, manage technical risks, and ensure adherence to architecture, quality, and security expectations.
- Mentor engineers, lead technical forums, improve reusable platforms and processes, and foster a culture of engineering rigor, accountability, collaboration, and continuous learning.
Qualifications
- Bachelor’s degree in Computer Science, Computer Engineering, Electrical Engineering, Software Engineering, or a related discipline, or an equivalent combination of education and relevant experience.
- Typically 15+ years of embedded software or firmware experience, including substantial responsibility for architecture and delivery of complex products in a regulated or high-reliability environment.
- Advanced proficiency in C and C++, with strong knowledge of embedded systems, microcontrollers, RTOS concepts, memory and power constraints, hardware/software interfaces, debugging, and communication protocols.
- Demonstrated experience leading firmware architecture and development from requirements through verification, release, maintenance, and end-of-life.
- Practical knowledge of product-security engineering, including threat modeling, security risk management, vulnerability assessment, secure coding, cryptographic concepts, secure communications, and software-update security.
- Experience operating within a quality management system and applying disciplined design controls, risk management, configuration management, traceability, verification, and technical documentation.
- Working knowledge of medical-device software and cybersecurity expectations, including FDA guidance and relevant standards such as IEC 62304, ISO 14971, IEC 81001-5-1, and applicable quality-system requirements.
- Proven ability to influence across functions, lead technical decision-making, manage ambiguity and risk, and communicate complex topics clearly to engineering and business stakeholders.
- Strong problem-solving, mentoring, organizational, and written communication skills, with a proactive and hands-on leadership style.
Preferred Qualifications
- Master’s degree in Computer Science, Computer Engineering, Electrical Engineering, Software Engineering, Cybersecurity, or a related discipline.
- Experience developing connected medical devices, digital-health products, portable or battery-powered systems, or cloud-connected embedded solutions.
- Experience with embedded, wireless or cellular connectivity, Bluetooth Low Energy, secure cloud/device integration, or over-the-air firmware updates.
- Experience with penetration testing, fuzz testing, vulnerability management, SBOM tools, open-source software governance, or incident-response processes.
- Familiarity with standards and frameworks such as UL 2900, NIST Cybersecurity Framework, NIST Secure Software Development Framework, or equivalent secure-development practices.
- Experience leading suppliers or geographically distributed engineering teams and delivering multiple products or platform releases.
- Relevant technical or cybersecurity certification is beneficial but not required.
- US citizens and Greencard holder
Inogen assesses market data to ensure a competitive compensation package for our employees. The base salary for this position is expected to be between $145,000.00 and $181,652.24 annually. However, actual base salary if hired will be determined on an individualized basis and will be based on non-discriminatory factors, including as to individual skills, education, experience and market location.
Our Benefits and Rewards:
In addition to the expected base salary, this role is eligible to participate in Inogen’s annual performance bonus incentive plan, highly competitive and company-sponsored benefits, and wellbeing programs rooted in our strong culture of excellence. As a valued member of our team, Inogen provides health, dental, and vision insurance, 401(k) plan plus employer contribution and match, and generous paid leaves such as vacation and sick leave, including paid volunteer time, that can support you and your family through moments that matter.
Inogen is an Equal Employment Opportunity/Affirmative Action Employer - Underrepresented racial and ethnic groups/Females/Individuals with Disabilities/Protected Veterans.