Principal Product Security Engineer

Johnson & Johnson Johnson & Johnson · Pharma · Danvers, MA +50

Johnson & Johnson MedTech is seeking a Principal Product Security Engineer to ensure security is implemented by design for medical devices. This role involves owning the Product Security process throughout the product development lifecycle, providing technical expertise in securing cardiac support systems and connected medical devices, and ensuring regulatory compliance. Responsibilities include defining security architecture, cryptographic controls, embedded system protections, threat mitigation, and post-market vulnerability monitoring.

What you'd actually do

  1. Drive alignment to J&J Product Security’s overarching framework.
  2. Support the Product Security strategy and objectives within Heart Recovery
  3. Define and implement secure boot, firmware integrity validation, and anti-tamper mechanisms to protect Heart Recovery Device firmware against unauthorized modification.
  4. Enforce cryptographic protocols for data-at-rest and data-in-transit, ensuring compliance with FDA cybersecurity requirements, NIST 800-175, FIPS 140-3, and IEC 62443.
  5. Define and implement key management infrastructure (PKI, HSMs, TPMs, and secure enclave integration) for device identity, authentication, and software signing.

Skills

Required

  • Product Security Engineering
  • Cybersecurity
  • Medical Device Security
  • Embedded Systems Security
  • Cryptographic Protocols
  • Key Management Infrastructure (PKI, HSMs, TPMs)
  • Secure Boot
  • Firmware Integrity Validation
  • Threat Modeling
  • Secure Development Lifecycle (SDL)
  • NIST 800-175
  • FIPS 140-3
  • IEC 62443

Nice to have

  • Wireless Communications Security (Bluetooth LE, NFC, Wi-Fi, 5G)
  • Zero Trust Security
  • Over-the-Air (OTA) Updates Security
  • Static/Dynamic Analysis
  • Fuzz Testing
  • Code Analysis

What the JD emphasized

  • security is implemented by design
  • security risk and compliance skills
  • regulatory-compliant security
  • FDA cybersecurity requirements