Johnson & Johnson

Professional, Prog Lead, PenTesting Svcs

Johnson & Johnson$94K — $170K *
Healthcare
5 - 7 years of experience
Job Overview by Ladders

Qualifications

  • Bachelor's degree in Computer Science or related technical field; advanced degree preferred
  • 6+ years in penetration testing or application security
  • Proven experience managing a penetration testing program
  • Hands-on expertise in web, API, mobile, and network testing
  • Familiarity with tools like Burp Suite and Metasploit, plus scripting skills
  • Strong understanding of vulnerability classes and risk scoring
  • Excellent communication skills for non-technical audiences

Responsibilities

  • Lead the penetration testing services program across product platforms
  • Define methodology and scoping standards for security testing
  • Integrate security testing into the product development lifecycle
  • Oversee hands-on security assessments for various product types
  • Manage relationships with third-party penetration testing vendors
  • Assess vulnerabilities to evaluate risk for patient safety and business
  • Advise on remediation processes with engineering teams

Benefits

  • Opportunity for domestic and international travel
  • Participation in retirement and savings plans
  • Generous vacation and sick leave policies
  • Parental and bereavement leaves
  • Volunteer and military spouse leave programs
  • Access to secure development training resources
  • Comprehensive benefits including personal and family time off
Full Job Description
Job Function:
Technology Enterprise Strategy & Security

Job Sub Function:
Solution Architecture

Job Category:
Scientific/Technology

All Job Posting Locations:
New Brunswick, New Jersey, United States of America, Palm Beach Gardens, Florida, United States of America, Raynham, Massachusetts, United States of America, Warsaw, Indiana, United States of America, West Chester, Pennsylvania, United States of America

Job Description:

DePuy Synthes is recruiting for a(n) Professional, Prog Lead, PenTesting Svcs located in New Brunswick, NJ or West Chester, PA or Palm Beach Gardens, FL or Warsaw, IN or Raynham, MA.

Job Overview

The Professional, Program Lead, Penetration Testing Services is a seasoned individual contributor within the Cybersecurity function, Product Security sub-function, accountable for building and running the penetration testing and offensive security services program for the DePuy Synthes product portfolio. This role establishes the testing methodology, scoping standards, and engagement model that embed Secure by Design verification into the product development lifecycle - spanning medical devices, embedded firmware, mobile applications, APIs, and supporting cloud services. The Program Lead manages internal testers and third-party assessment partners, translates technical findings into patient safety and business risk, and drives remediation to closure with R&D and engineering teams. Applying advanced technical skills and industry-leading practices, this role serves as the authoritative voice on product security testing across the enterprise.

Key Responsibilities

  • Own the end-to-end penetration testing services program for products and connected platforms, including the annual testing roadmap, prioritization model, and capacity planning across internal and external resources.


  • Define and maintain the penetration testing methodology, scoping standards, rules of engagement, and reporting templates aligned to industry frameworks (OWASP, PTES, NIST SP 800-115, MITRE ATT&CK).


  • Embed security testing gates into the product development lifecycle, ensuring Secure by Design verification occurs at defined design, integration, and pre-release milestones.


  • Execute and oversee hands-on assessments across medical devices, embedded firmware, wireless protocols, mobile applications, web applications, APIs, and cloud infrastructure.


  • Manage third-party penetration testing vendors - including scoping, statement of work development, quality review of deliverables, and performance management against SLAs.


  • Triage and validate findings, assess exploitability, and evaluate patient safety and clinical impact in partnership with Product Security, Quality, and Regulatory stakeholders.


  • Drive remediation with R&D and engineering teams, tracking findings through retest and verified closure, and escalating overdue or elevated risks through governance channels.


  • Conduct threat modeling and attack surface analysis to inform test scoping and identify high-value targets prior to engagement.


  • Support regulatory and customer requirements by producing testing evidence for FDA premarket submissions, EU MDR technical files, and hospital security assessments.


  • Contribute penetration testing results and residual risk analysis into product security risk files aligned to AAMI TIR57 and ISO 14971.


  • Build and report program metrics - test coverage across the portfolio, finding severity distribution, remediation aging, and retest pass rates - to leadership and product stakeholders.


  • Research emerging attack techniques, medical device vulnerabilities, and tooling; continuously evolve the testing capability and develop custom tooling and exploits where needed.


  • Assess the testing implications of platform migrations, supplier changes, and separation/carve-out activity affecting the product portfolio and supporting infrastructure.


  • Deliver technical enablement and secure development training to engineering teams, using real findings to strengthen security ownership and cyber culture.


Qualifications

Education

  • Bachelor's degree in Computer Science, Cybersecurity, Software/Electrical/ Biomedical Engineering, Information Systems, or a related technical discipline.


  • Advanced degree or specialized cybersecurity education (preferred).


Experience and Skills

Required:

  • Minimum 6 years of progressive experience in penetration testing, offensive security, red teaming, or application security assessment.


  • Demonstrated experience leading or managing a penetration testing program, including methodology definition, scoping standards, and vendor oversight.


  • Hands-on proficiency across multiple domains: web application, API, mobile, network, wireless, and cloud penetration testing.


  • Working knowledge of common testing tools and frameworks (Burp Suite, Metasploit, Nmap, Wireshark, Ghidra/IDA, Kali) and scripting proficiency (Python, Bash, PowerShell).


  • Strong understanding of vulnerability classes and taxonomies (OWASP Top 10, CWE) and risk scoring methodologies (CVSS).


  • Experience embedding security testing into an SDLC and driving remediation with engineering teams through verified closure.


  • Excellent written and verbal communication skills, with proven ability to translate technical exploitation detail into business and patient safety risk for non-technical audiences.


Preferred:

  • MedTech or medical device experience; familiarity with FDA premarket/postmarket cybersecurity guidance, EU MDR, IEC 62304, ISO 14971, and AAMI TIR57.


  • Embedded systems and firmware security experience, including hardware interfaces (JTAG/UART), secure boot, and reverse engineering.


  • Experience testing wireless and IoMT protocols (Bluetooth/BLE, Zigbee, RF, proprietary protocols).


  • Experience supporting product security testing within a divestiture, carve-out, or standalone entity stand-up.


  • Cloud penetration testing experience in AWS and/or Azure environments.


  • Exposure to coordinated vulnerability disclosure programs and researcher engagement.


  • Experience applying Generative AI / LLM-enabled tooling to accelerate reconnaissance, code review, and reporting workflows.


  • Experience integrating automated security testing into DevSecOps and CI/CD pipelines.


Other:

  • Travel: Up to 10% domestic and international travel expected for lab-based device testing and site engagements.


  • Language: English proficiency required.


  • Certifications: OSCP, OSCE, GPEN, GWAPT, or GXPN required or in progress. OSWE, GRTP, CRTO, or CISSP preferred.


Required Skills:

Preferred Skills:
Business Alignment, Business Architecture, Business Requirements Analysis, Coaching, Consulting, Critical Thinking, Emerging Technologies, Information Security Management System (ISMS), Information Technology Strategies, Information Technology Trends, IT Architecture, Management Systems Implementation, Problem Solving, Requirements Analysis, Solution Architecture, Technical Credibility, Technical Writing, Technologically Savvy

The anticipated base pay range for this position is :
94,000.00 - 170,000.00 USD Annual

Additional Description for Pay Transparency:
Subject to the terms of their respective plans, employees are eligible to participate in the Company's consolidated retirement plan (pension) and savings plan (401(k)). Subject to the terms of their respective policies and date of hire, employees are eligible for the following time off benefits: • Vacation -120 hours per calendar year • Sick time - 40 hours per calendar year; for employees who reside in the State of Colorado -48 hours per calendar year; for employees who reside in the State of Washington -56 hours per calendar year • Holiday pay, including Floating Holidays -13 days per calendar year • Work, Personal and Family Time - up to 40 hours per calendar year • Parental Leave - 480 hours within one year of the birth/adoption/foster care of a child • Bereavement Leave - 240 hours for an immediate family member: 40 hours for an extended family member per calendar year • Caregiver Leave - 80 hours in a 52-week rolling period10 days • Volunteer Leave - 32 hours per calendar year • Military Spouse Time-Off - 80 hours per calendar year For additional general information on Company benefits, please go to: - https://www.careers.jnj.com/employee-benefits

About Johnson & Johnson

Scio Diamond creates single-crystal Type IIa diamonds for the jewelry market and for industrial applications. It employs a patent-protected chemical vapor deposition (CVD) process in a precisely controlled laboratory setting to produce diamonds. It was founded in 2009 and is headquartered in Greenville, South Carolina.

Johnson & Johnson Careers

Joining Johnson & Johnson provides an unparalleled opportunity to be a part of a global team of professionals dedicated to blending care, science, and innovation to profoundly change the trajectory of health for humanity.

Work You’ll Do

At Johnson & Johnson, you will engage in work that matters. Join our community of professionals in health care to drive significant and impactful changes across the globe. Our team at Johnson & Johnson leads with science and heart in sectors from pharmaceuticals to medical devices and consumer health products.

Transform Health Care

Leverage Johnson & Johnson’s culture of innovation to transform health care and improve the lives of people around the world. Our collaborative environment encourages leadership and growth, allowing you to pioneer new strategies for health care solutions with a diverse team of experts.

Innovative Work

Engage in groundbreaking work that enhances how care is delivered on a global scale. Johnson & Johnson’s commitment to innovative health solutions results in dynamic career paths filled with opportunities for professional growth and development.

Be Part of a Great Team

Our team at Johnson & Johnson thrives on collaboration and diversity. You will work alongside over 130,000 employees globally who are committed to making a lasting impact. With a culture that values diversity training and leadership, you are supported in both personal and professional growth.

Future-Proof Your Career

Johnson & Johnson offers a myriad of job opportunities and employment benefits designed to help you meet your career and personal goals. Our employees enjoy comprehensive benefits, including health insurance, retirement plans, and family-friendly policies that pave the way for a fulfilling career and life balance.

Explore Job Opportunities and Internships

Whether you’re looking to start your career or take it to the next level, Johnson & Johnson offers positions ranging from internships to leadership roles across various sectors. Enhance your skills through hands-on experience and our extensive networking and mentorship programs.

Johnson & Johnson Leadership and Development

Our commitment to leadership and continuous learning is at the core of our employment philosophy. Every position offers chances to lead, learn, and innovate. We provide extensive training programs and development courses that prepare you for the future of health care.

Stay Connected

Join Our Team

Search open positions that match your skills and interests. We are constantly hiring and looking for curious, driven, and compassionate team players.

SEARCH JOHNSON & JOHNSON JOBS

Keep Up to Date

Stay informed with career tips, insider perspectives, and industry-leading insights you can put to use today—all from the people who work here.

READ CAREERS BLOG

Job Alert Emails

Customize your subscription to receive job alerts, latest news, and insider tips tailored to your preferences. Discover the exciting and rewarding career opportunities that await at Johnson & Johnson. Join Johnson & Johnson today to be a part of a team that values innovation, leadership, and diversity, and see how far your ambition can take you.
Learn more about Johnson & Johnson
Size
141,700 employees
Market Cap
$462.7 billion
Industry
Net Income
$14.7 billion
Founded
1886
5 Year Trend
+5.5%
Revenue
$82.5 billion
NASDAQ

Similar Jobs

More Jobs at Johnson & Johnson

More Healthcare Jobs

Find similar Professional, Prog Lead, PenTesting Svcs jobs: