Director, Product Security

Johnson & Johnson Johnson & Johnson · Pharma · Irvine, CA +50

Director, Product Security for Johnson & Johnson MedTech, responsible for defining and executing product security strategy, leading a global team, overseeing security integration across medical devices and software, and championing secure development practices. The role also involves leading efforts in emerging technologies like AI and Quantum Cryptography, managing post-market security, and representing product security in regulatory inspections.

What you'd actually do

  1. Define and execute the Business Units product security strategy aligned with FDA/MDR/524B expectations, and QMS requirements.
  2. Lead and grow a global product security team, fostering collaboration that balances technical rigor with business needs.
  3. Oversee security integration across medical devices, software, mobile applications, embedded devices, and cloud environments
  4. Partner with Regulatory, Quality, Legal, Privacy, and Commercial teams to ensure cybersecurity requirements are built into Class I, II, and III devices, supporting PMA and 510(k) submissions.
  5. Champion secure SDLC, DevSecOps, SBOM generation/validation, and vulnerability management across device and software platforms.

Skills

Required

  • Bachelor’s degree in STEM, Engineering, Computer Science, Cybersecurity or related field, or equivalent work experience.
  • 15+ years of MedTech experience in Quality, R&D, engineering, product development, medical devices, or product security, with 5+ years in leadership.
  • Experience with Class I, Class II, and Class III medical devices, including 510(k) and PMA submissions.
  • Knowledge of hardware and software security, including secure screws, tamper seals, physical port blocking, enclosure access detection, secure boot and system integrity, trusted hardware, secure coding, identity and access management, PKI, integrating security into the development lifecycle (DevSecOps) and manufacturing lifecycle
  • Experience with medical device cybersecurity regulatory expectations and risk management framework, including FDA cybersecurity guidance, section 524B of the FD&C Act for cyber devices, ISO/IEC 81001-5-1, NIST CSF, NIST 800-175, FIPS 140-3, and IEC 62443 and global frameworks.
  • Demonstrated success bridging Engineering, Quality, Regulatory, Legal, Privacy, and Commercial functions

Nice to have

  • Strong R&D, Regulatory or Quality experience in medical devices is highly preferred
  • Experience with medical devices, and/or connected product solutions.

What the JD emphasized

  • FDA/MDR/524B expectations
  • Class I, II, and III devices
  • 510(k) and PMA submissions
  • FDA cybersecurity guidance
  • section 524B of the FD&C Act
  • ISO/IEC 81001-5-1
  • NIST CSF
  • NIST 800-175
  • FIPS 140-3
  • IEC 62443