Director, Product Security

Johnson & Johnson Johnson & Johnson · Pharma · Raynham, MA +7

Director, Product Security responsible for defining and executing the global product security strategy for DePuy Synthes' medical device and digital product portfolio. This role ensures that cybersecurity is embedded across the product lifecycle—from design and development through deployment and post‑market support—while enabling innovation, regulatory compliance, and patient safety.

What you'd actually do

  1. Define and lead the global product security strategy aligned with DePuy Synthes business objectives and regulatory requirements.
  2. Establish and oversee product security governance, standards, and secure development lifecycle practices across hardware, software, and connected medical devices.
  3. Partner with R&D, Quality, Regulatory Affairs, and IT to integrate cybersecurity risk management into product design, development, and post‑market activities.
  4. Lead global teams and external partners delivering product security services, tools, and capabilities that enable scalable and consistent execution.
  5. Oversee vulnerability management, threat modeling, penetration testing, and incident response activities related to product security.

Skills

Required

  • cybersecurity leadership
  • product security leadership
  • global scope
  • matrixed environments
  • securing complex software-enabled or connected products
  • regulated industries
  • secure product development
  • vulnerability management
  • cybersecurity risk management frameworks
  • lead and develop high-performing global teams
  • service-based operating models
  • Executive-level communication
  • stakeholder management

Nice to have

  • medical devices
  • healthcare technology
  • life sciences
  • FDA cybersecurity guidance
  • IEC 62304
  • ISO 14971
  • enabling cybersecurity capabilities within shared services
  • global enablement models

What the JD emphasized

  • global product security strategy
  • product security governance
  • secure development lifecycle practices
  • cybersecurity risk management
  • global teams
  • product security services
  • vulnerability management
  • threat modeling
  • penetration testing
  • incident response
  • global cybersecurity and medical device regulations
  • FDA
  • ISO
  • IEC