Dentsply Sirona is the world’s largest manufacturer of professional dental products and technologies, with a 130-year history of innovation and service to the dental industry and patients worldwide. Dentsply Sirona develops, manufactures, and markets a comprehensive solutions offering including dental and oral health products as well as other consumable medical devices under a strong portfolio of world class brands. Dentsply Sirona’s products provide innovative, high-quality and effective solutions to advance patient care and deliver better and safer dentistry. Dentsply Sirona’s global headquarters is located in Charlotte, North Carolina, USA. The company’s shares are listed in the United States on NASDAQ under the symbol XRAY
We are looking for an experienced Senior Product Security Engineer (m/f/d) to join our team. This individual will help build and enhance our Product & Solution Security (PSS) program. As a Senior Product Security Engineer for our medical devices, cloud-based software, and connected solutions, you will be responsible for integrating security throughout the product lifecycle, ensuring regulatory compliance, and driving a security-first culture
This senior technical role reports to the Head of Product & Solution Security and spans the full engineering lifecycle. You'll implement agile security best practices, DevSecOps, tools, and controls. Responsibilities include leading secure code reviews, automating security testing, and collaborating closely with Quality Assurance, Regulatory Affairs (QARA), and product teams within the CTO organization
This is a hybrid position requiring working from either our Bensheim or Zurich office
Key responsibilities
Perform security assessments of code, configurations, and components in complex solutions involving multiple products
Implement shift-left practices throughout the product development lifecycle and manage security tools within CI/CD pipelines
Act as a trusted advisor to product teams within the CTO organization and establish standards for vulnerability remediation and secure coding
Drive the automation of security testing and compliance validation practices
Lead the development and continuous refinement of security engineering standards
Support threat modeling and risk mitigation efforts for various products and solutions involving multiple components
Monitor security metrics (KPIs and KRIs) and assist with incident response as needed
Collaborate with product development teams and QARA to embed security into system and software design
Promote a culture of security awareness across R&D and product management teams
Education
Bachelor's or Master's degree in Computer Science, Cybersecurity, or related field
Years and Type of Experience
8+ years of experience in cybersecurity, product security, software and hardware security, and cloud security. Experience in the medical device or healthcare industry is a strong plus
Industry-recognized certifications such as CISSP, OSCE, OSCP, CSSLP, CCSP, etc., are a strong plus
Key Skills, Knowledge & Capabilities:
Proven experience in implementing secure SDLC practices, DevSecOps, and collaborating with engineering teams
Proficiency in tools such as SAST, DAST, SCA, and CI/CD pipelines
In-depth knowledge of Secure SDLC (SSDLC) and Secure Product Development Frameworks (SPDF)
Strong understanding of secure coding and testing practices
Extensive scripting and automation experience
Experience with cloud security platforms, including AWS, Azure, GCP, and Alibaba Cloud
Excellent English communication skills; German language skills are a plus
Dentsply Sirona is an Equal Opportunity/ Affirmative Action employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, age, sexual orientation, disability, or protected Veteran status. We appreciate your interest in Dentsply Sirona
If you need assistance with completing the online application due to a disability, please send an accommodation request to . Please be sure to include “Accommodation Request” in the subject