Lead Product Security Architect

Johnson & Johnson Johnson & Johnson · Pharma · Santa Clara, CA +1

Lead Product Security Architect for a surgical robot (OTTAVA), focusing on end-to-end cybersecurity architecture, system-level security, and security-by-design from firmware to external interfaces. The role involves technical leadership, risk assessment, and collaboration with quality, regulatory, and FDA stakeholders. This is a highly regulated medical device environment.

What you'd actually do

  1. Own the end-to-end cybersecurity architecture for the OTTAVA product, a FDA-regulated device, maintaining a system-level view of security and ensuring security-by-design from firmware and embedded software to external interfaces
  2. Be the singular R&D voice on security, clearly communicating and alinging approaches with internal (quality, information security, regulatory) and external (FDA) stakeholders
  3. Act as the technical authority for cybersecurity decisions and trade offs
  4. Design and oversee implementation of technical cybersecurity controls, primarily based in software and network infrastructure
  5. Lead R&D cyber reviews and documentation (threat modeling, risk assessment) in partnership with internal collaborators

Skills

Required

  • software development
  • systems engineering
  • device security
  • technical leadership in cybersecurity
  • regulatory guidance (FDA)
  • cybersecurity implementation
  • documentation
  • pre- and post-market surveillance
  • risk-assessment
  • software development for complex safety critical products
  • medical device
  • partnering and influencing across a matrix environment
  • designing system-level security architecture for embedded devices
  • communication skills
  • interpersonal skills
  • collaboration skills
  • travel

Nice to have

  • FDA Class II or III medical devices
  • IEC 62304
  • post-market vulnerability monitoring
  • FDA audits
  • SOC2
  • robotic technology
  • robotic surgery paradigms
  • global development team
  • supporting or launching medical device products

What the JD emphasized

  • regulatory guidance (preferably FDA) on cybersecurity implementation and documentation, pre- and post-market surveillance, and risk-assessment is required
  • Demonstrated success in partnering and influencing across a matrix environment is required
  • Proven leadership designing system-level security architecture for embedded devices is required
  • Strong communication and interpersonal skills, with the ability to collaborate effectively with diverse teams and partners is required
  • Ability to travel up to 10%, international and domestic, is required