Principal Med Device Security Engineer

Johnson & Johnson Johnson & Johnson · Pharma · Danvers, MA +51

Johnson & Johnson MedTech is seeking a Principal Product Security Engineer to ensure security is implemented by design for medical devices. The role involves owning the Product Security process throughout the product development lifecycle, providing technical expertise in securing cardiac support systems and connected medical devices, and delivering security architecture, cryptographic controls, and threat mitigation techniques. Responsibilities include supporting new product development, reviewing requirements, completing quality documentation, threat modeling, coordinating penetration testing, software architecture review, code analysis, and post-market responsibilities like vulnerability monitoring and remediation.

What you'd actually do

  1. Drive alignment to J&J Product Security’s overarching framework.
  2. Support the Product Security strategy and objectives within Heart Recovery
  3. Define and implement secure boot, firmware integrity validation, and anti-tamper mechanisms to protect Heart Recovery Device firmware against unauthorized modification.
  4. Enforce cryptographic protocols for data-at-rest and data-in-transit, ensuring compliance with FDA cybersecurity requirements, NIST 800-175, FIPS 140-3, and IEC 62443.
  5. Define and implement key management infrastructure (PKI, HSMs, TPMs, and secure enclave integration) for device identity, authentication, and software signing.

Skills

Required

  • Product Security Engineering
  • Cybersecurity Risk Management
  • Threat Modeling
  • Secure Development Lifecycle (SDL)
  • Embedded Systems Security
  • Cryptographic Protocols
  • Key Management Infrastructure (PKI, HSMs, TPMs)
  • Secure Boot and Firmware Integrity
  • Over-the-Air (OTA) Update Security
  • Vulnerability Assessment
  • Zero Trust Security Principles
  • Medical Device Security Regulations (FDA, NIST, IEC)
  • Software Architecture Review
  • Code Analysis
  • Penetration Testing Coordination

Nice to have

  • Experience with wireless communication security (Bluetooth LE, NFC, Wi-Fi, 5G)
  • Familiarity with real-time operating systems (RTOS)
  • Knowledge of memory safety strategies
  • Experience responding to customer security questionnaires

What the JD emphasized

  • security is implemented by design
  • regulatory-compliant security
  • FDA cybersecurity requirements
  • FIPS 140-3
  • IEC 62443