Director, Product Security

Johnson & Johnson Johnson & Johnson · Pharma · Pune, Maharashtra, India

Director, Product Security role at Johnson & Johnson (DePuy Synthes) responsible for defining and executing the global product security strategy for medical device and digital product portfolios. Ensures cybersecurity is embedded across the product lifecycle, enabling innovation, regulatory compliance, and patient safety. Partners with R&D, Quality, Regulatory, and IT to integrate cybersecurity risk management, oversees vulnerability management, threat modeling, penetration testing, and incident response. Ensures compliance with global cybersecurity and medical device regulations.

What you'd actually do

  1. Define and lead the global product security strategy aligned with DePuy Synthes business objectives and regulatory requirements.
  2. Establish and oversee product security governance, standards, and secure development lifecycle practices across hardware, software, and connected medical devices.
  3. Partner with R&D, Quality, Regulatory Affairs, and IT to integrate cybersecurity risk management into product design, development, and post‑market activities.
  4. Lead global teams and external partners delivering product security services, tools, and capabilities that enable scalable and consistent execution.
  5. Oversee vulnerability management, threat modeling, penetration testing, and incident response activities related to product security.

Skills

Required

  • Bachelor’s degree in Computer Science, Engineering, Information Security, or a related technical field
  • 10-12 years of experience in cybersecurity or product security leadership roles
  • Demonstrated experience securing complex software‑enabled or connected products
  • Strong knowledge of secure product development, vulnerability management, and cybersecurity risk management frameworks
  • Proven ability to lead and develop high‑performing global teams and service‑based operating models
  • Executive‑level communication and stakeholder management skills

Nice to have

  • Master’s degree in Cybersecurity, Engineering, or Business Administration
  • Experience in medical devices, healthcare technology, or life sciences
  • Familiarity with FDA cybersecurity guidance, IEC 62304, ISO 14971, and related standards
  • Experience enabling cybersecurity capabilities within shared services or global enablement models
  • Background in cloud, embedded systems, or IoT security
  • CISSP
  • CISM
  • CSSLP

What the JD emphasized

  • global scope
  • matrixed environments
  • regulated industries
  • FDA cybersecurity guidance
  • IEC 62304
  • ISO 14971