Job Function: Technology Enterprise Strategy & Security
Job Sub Function: Security & Controls
Job Category:People Leader
All Job Posting Locations:Santa Clara, California, United States of America
Job Description:Johnson & Johnson is hiring for a Sr. Manager, Product Security - Shockwave Medical to join our team located in Santa Clara, CA.
Fueled by innovation at the intersection of biology and technology, we're developing the next generation of smarter, less invasive, more personalized treatments. Ready to join a team that's pioneering the development and commercialization of Intravascular Lithotripsy (IVL) to treat complex calcified cardiovascular disease. Our Shockwave Medical portfolio aims to establish a new standard of care for medical device treatment of atherosclerotic cardiovascular disease through its differentiated and proprietary local delivery of sonic pressure waves for the treatment of calcified plaque.
Position OverviewThe Sr. Manager, Product Security provides technical leadership supporting product cybersecurity strategy and execution. This position is responsible for defining secure architecture patterns and controls for medical devices and guiding advanced security real-world testing approaches. The position partners closely with engineering, quality, PMO, and regulatory to translate global cybersecurity expectations into practical and scalable engineering solutions.
Essential Job Functions- serve as the functional owner of product security within the Business Unit, accountable for defining, governing, and ensuring execution of product security processes and tools in alignment with J&J Quality Standards.
- Define and architect defense in depth security controls including hardware root of trust, secure boot, cryptographic services (PKI/TLS), identity and access management, secure update mechanisms, and trusted device to cloud communications.
- Conduct medical devices threat modeling, secure design reviews, and cyber risk assessments for new and existing product platforms.
- Support cybersecurity submission readiness by contributing technical direction, regulatory evidence, architecture rationale, and risk mitigation strategies.
- Lead emerging cyber technologies (AI and Quantum Cryptography) for medical devices and that will be impacted by cybersecurity. Make internal and external policy recommendations to mitigate threats and vulnerabilities.
- Provide technical leadership supporting cyber architecture, penetration testing approaches, advanced real-world security testing methodologies, and risk-based validation strategies.
- Drive integration of security tooling and controls into Business Units CI/CD pipelines, including static analysis, software composition analysis, component/sub-systems security, and SBOM generation.
- Define secure build, release, and patching architecture patterns aligned with regulatory expectations. Promote scalable shift-left security practices across each product release.
- Act as a trusted cybersecurity architect advisor to R&D, engineering leaders, quality, regulatory, PMOS, and commercial teams
- Partner with engineering and quality teams to prioritize and track mitigation of identified cybersecurity risks.
- Support cybersecurity regulatory expectations (e.g., FDA guidance, global cybersecurity standards) into implementable engineering requirements and QMS procedures.
- Drive Post Market cybersecurity monitoring, risk management, including threat monitoring, and formal risk dispositioning decisions.
- Define and execute patching and mitigation strategies, supporting coordinated disclosure, regulatory reporting, and field actions in alignment with FDA expectations.
- Other duties as needed.
Requirements- Bachelor's degree in Engineering, Cybersecurity, STEM or related field, or equivalent work experience.
- 12+ years of MedTech experience in R&D, engineering, product development, medical devices, or product security.
- Strong technical understanding of software development languages, preferred with C, C++, Python, and Groovy to support secure architecture reviews, threat modeling, vulnerability analysis, and DevSecOps enablement across product teams.
- Experience integrating DevSecOps capabilities into CI/CD pipelines using Jenkins and Bitbucket Cloud, including SAST/SCA tooling (Black Duck, Checkmarx, Snyk), SBOM generation, secure code review, artifact signing, and automated security validation.
- Expertise in Class I, Class II, and Class III medical devices, including 510(k) and PMA submissions. Experience with medical devices, and/or connected product solutions.
- Experience implementing hardware and software security, including secure screws, tamper seals, physical port blocking, enclosure access detection, secure boot and system integrity, trusted hardware, secure coding, identity and access management, PKI, integrating security into the development lifecycle (DevSecOps) and manufacturing lifecycle
- Demonstrated expertise in secure architecture design and security testing of connected or embedded systems
- Experience integrating security controls into DevSecOps environments and software delivery pipelines as well in manufacturing environments.
- Experience with medical device cybersecurity regulatory expectations and risk management framework, including FDA cybersecurity guidance, section 524B of the FD&C Act for cyber devices, ISO/IEC 81001-5-1, NIST CSF, NIST 800-175, FIPS 140-3, and IEC 62443 and global frameworks.
- Demonstrated success bridging Engineering, Quality, Regulatory, Legal, Privacy, and Commercial functions. Strong ability to influence engineering teams and communicate complex technical concepts
- Preferred certifications: CISSP, CSSLP, CISM, CISA, or equivalent.
Required Skills:Preferred Skills:Business Process Design, Collaboration, Crisis Management, Critical Thinking, Cyber Threat Intelligence, Developing Others, Inclusive Leadership, Information Security Auditing, Information Security Management System (ISMS), Information Technology (IT) Security Assessments, Information Technology Strategies, Leadership, Managing Managers, People Performance Management, Presentation Design, Process Optimization, Security Architecture Design, Security Policies
The anticipated base pay range for this position is :$142,000.00 - $244,950.00
Additional Description for Pay Transparency:
Subject to the terms of their respective plans, employees are eligible to participate in the Company's consolidated retirement plan (pension) and savings plan (401(k)).
This position is eligible to participate in the Company's long-term incentive program.
Subject to the terms of their respective policies and date of hire, employees are eligible for the following time off benefits:
Vacation -120 hours per calendar year
Sick time - 40 hours per calendar year; for employees who reside in the State of Colorado -48 hours per calendar year; for employees who reside in the State of Washington -56 hours per calendar year
Holiday pay, including Floating Holidays -13 days per calendar year
Work, Personal and Family Time - up to 40 hours per calendar year
Parental Leave - 480 hours within one year of the birth/adoption/foster care of a child
Bereavement Leave - 240 hours for an immediate family member: 40 hours for an extended family member per calendar year
Caregiver Leave - 80 hours in a 52-week rolling period10 days
Volunteer Leave - 32 hours per calendar year
Military Spouse Time-Off - 80 hours per calendar year
For additional general information on Company benefits, please go to: - https://www.careers.jnj.com/employee-benefits