Job Function:
Technology Product & Platform Management
Job Sub Function:
Technical Product Management
Job Category:
Scientific/Technology
All Job Posting Locations:
New Brunswick, New Jersey, United States of America, Palm Beach Gardens, Florida, United States of America, Raynham, Massachusetts, United States of America, Warsaw, Indiana, United States of America, West Chester, Pennsylvania, United States of America
Job Description:
DePuy Synthes is recruiting for a Professional, Quality Steward located in New Brunswick, NJ or West Chester, PA or Palm Beach Gardens, FL or Warsaw, IN or Raynham, MA.
The Professional, Quality Steward is an established and productive individual contributor within the Cybersecurity function, accountable for embedding Secure by Design principles into the DePuy Synthes medical device and connected product portfolio. This role serves as the quality and security steward across the total product lifecycle — partnering with R&D, Product Management, Engineering, Regulatory Affairs, and Quality to ensure security requirements are defined early, designed in, verified through testing, and sustained through postmarket monitoring. Working under moderate supervision, the analyst applies practical knowledge of product security, secure development practices, and medical device regulatory expectations to ensure products are safe, secure, compliant, and defensible to regulators and customers.
Define and document security requirements, design inputs, and acceptance criteria in collaboration with product owners, systems engineers, and R&D teams during early design phases.
Facilitate threat modeling and security architecture reviews for connected devices, embedded software, mobile applications, and supporting cloud services; ensure identified threats are mitigated and traceable to controls.
Support secure software development practices, including secure coding standards, static and dynamic analysis, dependency scanning, and integration of security gates into CI/CD pipelines.
Coordinate penetration testing and security verification activities with internal teams and third-party assessors; triage findings, assess exploitability and patient safety impact, and track remediation to closure.
Prepare and review cybersecurity documentation for regulatory submissions, aligned to FDA premarket cybersecurity guidance, EU MDR, and applicable international requirements.
Operate postmarket vulnerability management for released products 6 monitoring threat intelligence, performing impact analysis, and supporting coordinated vulnerability disclosure and customer advisories.
Develop and maintain customer-facing security artifacts, including MDS2 forms, security white papers, and responses to hospital and health system security assessments.
Establish and report product security metrics 6 design review coverage, vulnerability aging, SBOM currency, and remediation SLA performance 6 to leadership and program stakeholders.
Assess security implications of product changes, platform migrations, supplier changes, and separation/carve-out activity affecting the product portfolio.
Bachelor's degree in Computer Science, Cybersecurity, Software/Biomedical/ Electrical Engineering, Information Systems, or a related technical discipline.
4+ years of experience in product security, application security, secure software development, or a related cybersecurity engineering discipline.
Hands-on experience with threat modeling methodologies (e.g., STRIDE, attack trees) for embedded, mobile, or connected systems.
Working knowledge of secure coding practices, common vulnerability classes (OWASP Top 10, CWE), and application security testing tools (SAST, DAST, SCA).
Experience with vulnerability management, including CVE analysis, CVSS scoring, and risk-based remediation prioritization.
Familiarity with SBOM generation, formats (SPDX, CycloneDX), and third-party/open-source component risk management.
Strong written and verbal communication skills, with the ability to explain security risk to engineering, quality, regulatory, and commercial stakeholders.
MedTech or medical device experience; working knowledge of FDA premarket and postmarket cybersecurity guidance, EU MDR, IEC 62304, ISO 14971, ISO 13485, and AAMI TIR57/TIR97.
Familiarity with embedded systems security, firmware analysis, secure boot, cryptographic key management, and hardware root of trust.
Experience with cloud and connected-platform security (AWS, Azure), API security, and IoT/IoMT architectures.
Certifications: CSSLP, GWAPT, OSCP, CEH, CISSP, or equivalent product/application security certification preferred.
For more information on how we support the whole health of our employees throughout their wellness, career, and life journey, please visit www.careers.jnj.com.
Johnson & Johnson announced plans to separate ourOrthopaedicsbusiness toestablisha standaloneorthopaedicscompany, operating as DePuy Synthes. The process of the planned separation isanticipatedto be completed within 18 to24 months, subject to legal requirements, including consultation with works councils and other employee representative bodies, as may berequired, regulatory approvals and other customary conditions and approvals. Should you accept this position, it isanticipatedthat, following conclusion of the transaction, you would be an employee of DePuySynthesand your employment would be governed by DePuy Synthes employment processes, programs, policies, and benefit plans. In that case, details of any planned changes would be provided to you by DePuy Synthes atan appropriate timeand subject to any necessary consultation processes.