Careers that change lives start here. Medtronic is a global leader in healthcare technology with a Mission to alleviate pain, restore health, and extend life. Our 95,000 employees work across more than 150 countries to put patients first — developing cutting-edge medical technologies that improve the lives of 72+ million patients each year. Your unique talents will help shape the future of healthcare while building a career grounded in purpose, growth, and impact.
A Day in the Life
The Principal Application Security Specialist is a technical leader responsible for securing the software development lifecycle (SDLC) with a strong emphasis on GitLab-based development environments and CI/CD pipelines. This role partners engineering, DevOps, cloud, and security teams to design, implement, and mature secure-by-design practices across build, test, and deployment workflows.
This role will leverage GitLab’s native security capabilities within the development pipeline to identify security requirements.
The GitLab Application Security Engineer will enable efficient and secure software delivery across business and Global IT, directly supporting ongoing initiatives in AI and automation
Responsibilities may include the following and other duties may be assigned.
- Embed and refine security controls in GitLab CI/CD pipelines.
- Automate testing (SAST/DAST/SCA, container scans, secrets detection) in pipelines.
- Set and enforce secure pipeline standards, guardrails, and policies.
- Architect and secure GitLab (runners, projects, configs, permissions).
- Ensure secure use of GitLab runners, including isolation, ephemeral runners, and hardened execution environments.
- Build and maintain security automation integrated into pipelines.
- Develop reusable pipeline templates and security modules.
- Implement policy-as-code and automated compliance validation.
- Analyze pipeline and application security findings and drive remediation with engineering teams.
- Prioritize vulnerabilities bas