Senior Product Security Cloud Engineer

Johnson & Johnson Johnson & Johnson · Pharma · Danvers, MA +51

Johnson & Johnson MedTech is seeking a Senior Product Security Cloud Engineer to ensure security is implemented by design for connected medical devices. The role involves implementing the enterprise Product Security strategy and framework for cloud platforms, providing expertise in MS Azure cloud security architecture, cryptographic controls, PKI, and threat mitigation. Responsibilities include defining security requirements, conducting threat modeling and risk assessments (STRIDE, CVSS), managing SBOM and SCA, performing SAST/DAST, coordinating penetration testing, and developing cybersecurity risk management reports. Post-market responsibilities include vulnerability monitoring, patching, and remediation.

What you'd actually do

  1. responsible for implementation of J&J’s enterprise Product Security strategy and framework for the Heart Recovery cloud and supporting platforms.
  2. provide MS Azure Cloud technical expertise and strategic leadership in securing Impella heart pump cloud technologies, next-generation cardiac support systems, and connected medical devices to the MS Azure cloud.
  3. responsible for delivering MS Azure cloud security architecture, cryptographic controls and Public Key Infrastructure (PKI) , cloud security protections/controls, and threat mitigation techniques to ensure robust, regulatory-compliant security across the product lifecycle.
  4. define product security requirements and recommend security design solutions, complete Quality documentation that includes development of the following: product security plan, security requirements definition, threat modeling, cybersecurity architecture views per FDA pre-Market Guidance for Medical Devices, cybersecurity risk assessment leveraging STRIDE and CVSS, Software Bill of Materials (SBOM), Software Composition Analysis (SCA) against the SBOM, SAST (Static Application Security Testing), DAST (Dynamic Application Security Testing), additional security testing including coordinating internal and external Pen Testing, and development of the cybersecurity risk management report, code analysis and other security testing work as needed.
  5. monitoring for new vulnerabilities (CVEs), developing the monthly cybersecurity documentation with approvals, assisting with patching and remediation plans.

Skills

Required

  • MS Azure cloud security architecture and design
  • connected medical devices or IOTs connected to the cloud supporting secure data transmission and connectivity
  • Cloud security controls
  • Cybersecurity Threat Model and Risk Assessment using STRIDE per element and CVSS 3.1 frameworks for the Cloud environment
  • PKI and cryptographic controls

What the JD emphasized

  • MS Azure experience
  • connected medical devices
  • security risk and compliance skills
  • threat modeling
  • cybersecurity risk assessment