Lead Product Security Engineer

Johnson & Johnson Johnson & Johnson · Pharma · Danvers, MA +2

Lead Product Security Engineer at Johnson & Johnson focusing on cybersecurity for medical devices throughout the product lifecycle, including pre-market and post-market activities, compliance, and risk management.

What you'd actually do

  1. Partner with engineering and other cross-functional teams (cloud, console, pump, etc.) to drive successful adherence to J&J Heart Recovery's product security program.
  2. Deliver documentation for pre-market development activities including security plans, architecture and data flow diagrams, threat models, requirements, SBOM, and risk documentation.
  3. Define and implement key management infrastructure (PKI, HSMs, TPMs, and secure enclave integration) for device identity, authentication, and software signing.
  4. Monitor and drive post-market vulnerability management activities, with adherence to strict timelines.
  5. Support compliance certification activities, such as SOC2, FedRAMP, ISO 27001, etc.

Skills

Required

  • Bachelor’s degree in Computer Science, Information Systems, or related field.
  • 4+ years industry experience in Information Security.
  • Working knowledge of regulatory standards and compliance frameworks (e.g., NIST Cybersecurity Framework, ISO27001, SOC2, HIPAA, GDPR).
  • Experience with security risk management techniques and tactics.
  • Experience working in a regulated environment, FDA-regulated preferred.

What the JD emphasized

  • security is implemented by design
  • Product Security
  • product security program
  • product security team
  • product security process
  • product development lifecycle
  • security risk
  • security objectives
  • security risk management techniques and tactics
  • regulated environment
  • FDA-regulated