Careers that change lives start here. Medtronic is a global leader in healthcare technology with a Mission to alleviate pain, restore health, and extend life. Our 95,000 employees work across more than 150 countries to put patients first - developing innovative medical technologies that improve the lives of 72+ million patients each year. Your unique talents will help shape the future of healthcare while building a career grounded in purpose, growth, and impact.
A Day in the Life
CathWorks, now part of Medtronic, develops FFRangio - a Windows-based system used in the cardiac catheterization lab (Cath lab) to support interventional cardiology decision-making. As part of our platform and infrastructure team, you'll help ensure our Windows-based medical device environment is secure, compliant, and reliably deployable across clinical sites.
We are looking for a Windows platform expert with deep, hands-on scripting skills (PowerShell preferred) to own the security hardening, imaging, and deployment automation of the Windows environment underlying our FFRangio system.
You'll work at the intersection of low-level Windows internals (boot security, disk encryption, image management) and modern Windows virtualization and DevOps practices (CI/CD pipelines), helping us build a secure, locked down, and reliably reproducible Windows environment for a regulated medical device product.
You should be comfortable going deep - from BIOS settings and TPM chains up through image-building and pipeline automation - and who treats scripting as the primary tool for making security and deployment repeatable, auditable, and reliable, in service of a real clinical product used in the Cath lab.
Responsibilities may include the following and other duties may be assigned:
- Design, implement, and maintain PowerShell-based automation for system configuration, hardening, and deployment of FFRangio Windows workstations
- Define and enforce BIOS/UEFI security settings and TPM-based trust chains (Secure Boot, measured boot, TPM attestation)
- Implement and manage BitLocker and other Windows encryption mechanisms, including key management and recovery strategies
- Build and maintain Windows hardening baselines using Group Policy, AppLocker, custom Shell/UI restrictions, and Kiosk (Assigned Access) mode suited to a clinical, cath-lab environment
- Manage user/account permission models and least-privilege access schemes across managed devices
- Create, manipulate, and maintain VHD/VHDX-based images for deployment, recovery, and testing workflows
- Build and maintain CI/CD pipelines in Azure DevOps for automated build, test, and deployment of Windows images and configurations
- Collaborate with software, QA, and regulatory/quality teams to ensure hardening and deployment practices
- Document configurations, scripts, and processes for reproducibility and audit purposes, consistent with medical device quality system requirements
Requirements: Required Knowledge and Experience:
- B.Sc. in Computer Science, Software Engineering, Computer Engineering, Mathematics, or a related field
- 4+ years of relevant experience in Windows systems engineering, software engineering, security, or automation
- Strong, demonstrable PowerShell scripting skills
- Solid understanding of BIOS/UEFI security concepts and TPM (Trusted Platform Module) architecture
- Experience with BitLocker and Windows encryption/hardening tools: Group Policy design and management AppLocker rule creation and enforcement Kiosk mode / Assigned Access / custom shell configuration Windows account, group, and permission management
- Experience creating and manipulating VHD/VHDX virtual disks (mounting, provisioning, offline servicing, diskpart/DISM)
- Strong troubleshooting skills across the Windows boot chain, OS internals, and security stack.
*
This position is open to all candidates.