Johnson & Johnson

Principal Product Security Engineer

Johnson & Johnson$118K — $203K *
Healthcare
8 - 10 years of experience
Job Overview by Ladders

Qualifications

  • Bachelor's degree in Computer Science, Cybersecurity, or related field.
  • 8+ years of experience in cybersecurity or related technical disciplines.
  • Expertise in threat modeling and secure software development practices.
  • Experience in securing embedded systems and connected medical devices.
  • Strong understanding of security controls like authentication, cryptography, and secure update mechanisms.
  • Ability to translate cybersecurity risks into practical engineering solutions.
  • Experience leading complex security initiatives across cross-functional teams.

Responsibilities

  • Lead cybersecurity efforts on complex medical device and digital health product programs.
  • Drive security practices throughout the product lifecycle and influence development trade-offs.
  • Mentor cross-functional engineering teams on secure development frameworks.
  • Develop and maintain cybersecurity requirements for various systems and devices.
  • Conduct detailed security assessments, including design reviews and vulnerability analyses.
  • Manage and respond to cybersecurity threats and vulnerabilities post-market.
  • Provide technical direction for regulatory compliance and customer cybersecurity inquiries.

Benefits

  • 401(k) and pension plan participation.
  • Extensive vacation and sick time allowances.
  • Parental leave for new parents.
  • Structured volunteer and caregiver time-off policies.
  • Flexible work arrangements to enhance personal and family time.
Full Job Description

Job Function:

Technology Enterprise Strategy & Security

Job Sub Function:

Security & Controls

Job Category:

People Leader

All Job Posting Locations:

Santa Clara, California, United States of America

Job Description:

Johnson & Johnson’s MedTech cybersecurity team is recruiting for an experienced Principal Product Security Engineer to be based in Santa Clara, CA. This may require up to 10% travel.

Relocation to the San Francisco Bay area will be considered on a case-by-case basis. 

About MedTech

Fueled by innovation at the intersection of biology and technology, we’re developing the next generation of smarter, less invasive, more personalized treatments.

Your unique talents will help patients on their journey to wellness. Learn more at https://www.jnj.com/medtech.

Position Summary


The Principal Product Security Engineer is a senior technical cybersecurity expert responsible for securing connected medical devices, robotic systems, embedded platforms, cloud services, and supporting digital health ecosystems throughout the product lifecycle.

This role provides hands-on technical leadership across multiple product teams by identifying cybersecurity risks, developing security requirements, performing security assessments, guiding remediation, and verifying that security controls are appropriately implemented within regulated medical device products.

Primary Responsibilities

Technical Product Security Leadership

  • Serve as the cybersecurity technical lead for complex medical device and digital health product development programs.
  • Provide technical direction on security design, implementation, verification, vulnerability remediation, and risk treatment activities.
  • Drive security-by-design practices throughout the product development lifecycle.
  • Influence engineering tradeoffs by balancing cybersecurity risk, patient safety, clinical workflow, usability, and product constraints.
  • Mentor software, systems, cloud, and embedded engineering teams on secure development practices.

Security Engineering

  • Develop, review, and maintain cybersecurity requirements for embedded systems, software applications, cloud services, and connected medical devices.
  • Perform detailed security design reviews, implementation assessments, configuration reviews, and attack surface analysis.
  • Evaluate authentication, authorization, cryptography, secure boot, key management, access control, logging, monitoring, update mechanisms, and operating system hardening implementations.
  • Provide practical secure coding and design recommendations to engineering teams.
  • Identify design weaknesses early and partner with teams to implement technically feasible mitigations.

Threat Modeling and Cybersecurity Risk Assessment

  • Lead threat modeling activities for products, platforms, system features, and supporting services.
  • Analyze threats, vulnerabilities, abuse cases, misuse cases, and chained attack paths.
  • Perform cybersecurity risk assessments and evaluate risk control effectiveness.
  • Assess potential impact to patient safety, clinical operations, confidentiality, integrity, availability, and product performance.
  • Develop risk-based mitigation strategies and support the objective evidence needed to demonstrate control effectiveness.

Security Testing and Validation

  • Perform or coordinate security testing activities including static analysis, software composition analysis, vulnerability scanning, fuzz testing, penetration testing, secure configuration reviews, and architecture assessments.
  • Analyze test results and translate findings into clear, actionable remediation plans.
  • Support independent security assessments and third-party penetration testing activities.
  • Verify the effectiveness of implemented security controls and compensating controls.
  • Ensure security testing outputs are traceable to product risks, requirements, and release decisions.

Vulnerability Management and Post-Market Security

  • Analyze vulnerabilities affecting commercial, open-source, cloud, infrastructure, and internally developed software components.
  • Evaluate exploitability and product impact using CVSS and product-specific cybersecurity risk assessment methods.
  • Lead technical investigations, root cause analysis, remediation planning, and compensating control evaluation.
  • Support patching strategies, remediation roadmaps, coordinated vulnerability disclosure, and post-market surveillance activities.
  • Partner with product support and customer-facing teams to provide technically accurate cybersecurity responses.

Regulatory, Quality, and Customer Support

  • Provide cybersecurity technical input for product releases, design reviews, quality documentation, and regulatory submissions.
  • Support cybersecurity deliverables such as product security plans, threat models, SBOM-related assessments, vulnerability assessments, penetration test summaries, security architecture documentation, and customer-facing security materials.
  • Participate in audits, assessments, and regulatory inspections as a product cybersecurity technical expert.
  • Review customer security questionnaires and cybersecurity contractual language for technical accuracy.
  • Communicate complex security topics clearly to technical and non-technical stakeholders.

Qualifications

Required:

  • Bachelor's degree in Computer Science, Cybersecurity, Software Engineering, Computer Engineering, or equivalent practical experience.
  • 8+ years of experience in cybersecurity, product security, cloud security, or related technical disciplines.
  • Demonstrated expertise in threat modeling, secure software development, vulnerability management, penetration testing, security design review, and cybersecurity risk assessment.
  • Experience securing embedded systems, connected medical devices, IoT products, robotics platforms, cloud-connected systems, or other cyber-physical products.
  • Strong technical understanding of authentication, authorization, cryptography, secure boot, key management, operating system hardening, network security, logging, monitoring, and secure update mechanisms.
  • Experience writing, reviewing, and validating technical cybersecurity requirements.
  • Ability to translate complex cybersecurity risks into practical engineering recommendations and risk-based product decisions.
  • Experience using vulnerability scoring and assessment methodologies such as CVSS.
  • Ability to independently lead technically complex security initiatives across multiple cross-functional teams.
  • Excellent written and verbal communication skills, including the ability to influence engineering and program stakeholders without direct authority.

Preferred:

  • Experience with medical devices, healthcare technology, surgical robotics, regulated software, or connected health platforms.
  • Familiarity with FDA medical device cybersecurity expectations and global medical device cybersecurity regulatory requirements.
  • Working knowledge of standards and frameworks such as ISO 14971, AAMI TIR57, IEC 62304, IEC 81001-5-1, HIPAA, GDPR, HITRUST, ISO 27001, OWASP Top 10, SOC 2, or FedRAMP.
  • Experience with AWS, Azure, cloud security, web application security, and secure infrastructure design.
  • Software development experience in C, C++, C#, Java, Python, or similar languages.
  • CISSP, CSSLP, GIAC, GICSP, or similar security certification.
  • Master's degree in Cybersecurity, Computer Science, Engineering, or related discipline.
  • Experience supporting formal security audits, regulatory submissions, or product security customer engagements.

Characteristics of Success

  • Solves complex product security problems across multiple product lines without relying on direct people management authority.
  • Identifies cybersecurity concerns early enough to influence design and implementation decisions.
  • Improves security posture through hands-on technical analysis, practical remediation guidance, and verification of control effectiveness.
  • Builds credibility with engineering teams by providing technically sound, feasible, and risk-informed recommendations.
  • Maintains strong traceability between cybersecurity risks, requirements, controls, verification activities, and release decisions.
  • Communicates cybersecurity risk in a way that supports patient safety, regulatory defensibility, and business decision-making.

Required Skills:

 

Preferred Skills:

 

 

The anticipated base pay range for this position is :

$118,000.00 - $203,550.00

Additional Description for Pay Transparency:

Subject to the terms of their respective plans, employees are eligible to participate in the Company’s consolidated retirement plan (pension) and savings plan (401(k)).

Subject to the terms of their respective policies and date of hire, employees are eligible for the following time off benefits:
• Vacation –120 hours per calendar year
• Sick time - 40 hours per calendar year; for employees who reside in the State of Colorado –48 hours per calendar year; for employees who reside in the State of Washington –56 hours per calendar year
• Holiday pay, including Floating Holidays –13 days per calendar year
• Work, Personal and Family Time - up to 40 hours per calendar year
• Parental Leave – 480 hours within one year of the birth/adoption/foster care of a child
• Bereavement Leave – 240 hours for an immediate family member: 40 hours for an extended family member per calendar year
• Caregiver Leave – 80 hours in a 52-week rolling period10 days
• Volunteer Leave – 32 hours per calendar year
• Military Spouse Time-Off – 80 hours per calendar year

For additional general information on Company benefits, please go to: - https://www.careers.jnj.com/employee-benefits

About Johnson & Johnson

Scio Diamond creates single-crystal Type IIa diamonds for the jewelry market and for industrial applications. It employs a patent-protected chemical vapor deposition (CVD) process in a precisely controlled laboratory setting to produce diamonds. It was founded in 2009 and is headquartered in Greenville, South Carolina.

Johnson & Johnson Careers

Joining Johnson & Johnson provides an unparalleled opportunity to be a part of a global team of professionals dedicated to blending care, science, and innovation to profoundly change the trajectory of health for humanity.

Work You’ll Do

At Johnson & Johnson, you will engage in work that matters. Join our community of professionals in health care to drive significant and impactful changes across the globe. Our team at Johnson & Johnson leads with science and heart in sectors from pharmaceuticals to medical devices and consumer health products.

Transform Health Care

Leverage Johnson & Johnson’s culture of innovation to transform health care and improve the lives of people around the world. Our collaborative environment encourages leadership and growth, allowing you to pioneer new strategies for health care solutions with a diverse team of experts.

Innovative Work

Engage in groundbreaking work that enhances how care is delivered on a global scale. Johnson & Johnson’s commitment to innovative health solutions results in dynamic career paths filled with opportunities for professional growth and development.

Be Part of a Great Team

Our team at Johnson & Johnson thrives on collaboration and diversity. You will work alongside over 130,000 employees globally who are committed to making a lasting impact. With a culture that values diversity training and leadership, you are supported in both personal and professional growth.

Future-Proof Your Career

Johnson & Johnson offers a myriad of job opportunities and employment benefits designed to help you meet your career and personal goals. Our employees enjoy comprehensive benefits, including health insurance, retirement plans, and family-friendly policies that pave the way for a fulfilling career and life balance.

Explore Job Opportunities and Internships

Whether you’re looking to start your career or take it to the next level, Johnson & Johnson offers positions ranging from internships to leadership roles across various sectors. Enhance your skills through hands-on experience and our extensive networking and mentorship programs.

Johnson & Johnson Leadership and Development

Our commitment to leadership and continuous learning is at the core of our employment philosophy. Every position offers chances to lead, learn, and innovate. We provide extensive training programs and development courses that prepare you for the future of health care.

Stay Connected

Join Our Team

Search open positions that match your skills and interests. We are constantly hiring and looking for curious, driven, and compassionate team players.

SEARCH JOHNSON & JOHNSON JOBS

Keep Up to Date

Stay informed with career tips, insider perspectives, and industry-leading insights you can put to use today—all from the people who work here.

READ CAREERS BLOG

Job Alert Emails

Customize your subscription to receive job alerts, latest news, and insider tips tailored to your preferences. Discover the exciting and rewarding career opportunities that await at Johnson & Johnson. Join Johnson & Johnson today to be a part of a team that values innovation, leadership, and diversity, and see how far your ambition can take you.
Learn more about Johnson & Johnson
Size
141,700 employees
Market Cap
$462.7 billion
Industry
Net Income
$14.7 billion
Founded
1886
5 Year Trend
+5.5%
Revenue
$82.5 billion
NASDAQ

Similar Jobs

More Jobs at Johnson & Johnson

More Healthcare Jobs

Find similar Principal Product Security Engineer jobs: