Exp, Analyst, Security Engineer Product

Johnson & Johnson MedTech

Raynham (MA)

On-site

USD 90,000 - 130,000

Full time

17 hours ago
Be an early applicant
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Job summary

Johnson & Johnson’s DePuy Synthes Technology organization seeks an Exp, Analyst, Security Engineer Product in New Brunswick, NJ or West Chester, PA or Raynham, MA. This role embeds security across the product lifecycle for digital and connected medical devices, partnering with engineering, quality, and regulatory teams to design secure solutions and ensure regulatory compliance.

Responsibilities include threat modeling, risk assessments, remediation coordination, and ongoing security testing to

Qualifications

  • Bachelor’s degree in a technical field; Master’s preferred in cybersecurity or related discipline.
  • Experience with security risk assessments, threat modeling, or vulnerability analysis.
  • Familiarity with ISO, NIST, OWASP standards; ability to work with cross-functional teams.

Responsibilities

  • Integrate security requirements into design and development of digital/connected products.
  • Perform security risk assessments, threat modeling, and vulnerability analysis across the lifecycle.
  • Support secure design reviews, remediation activities, and governance processes.
  • Coordinate security testing (SAST/DAST), tracking findings to closure.
  • Monitor regulatory guidance relevant to medical devices and digital health.

Skills

Security risk assessments
Threat modeling
Vulnerability analysis
Secure SDLC
Regulatory standards (ISO/NIST/OWASP)
Cross-functional collaboration
Documentation & communication

Education

Bachelor’s degree in Computer Science/Engineering/Info Security
Master’s preferred: Cybersecurity/Computer Engineering

Job description

At Johnson & Johnson,we believe health is everything. Our strength in healthcare innovation empowers us to build aworld where complex diseases are prevented, treated, and cured,where treatments are smarter and less invasive, andsolutions are personal.Through our expertise in Innovative Medicine and MedTech, we are uniquely positioned to innovate across the full spectrum of healthcare solutions today to deliver the breakthroughs of tomorrow, and profoundly impact health for humanity.Learn more at jnj.com

As guided by Our Credo, Johnson & Johnson is responsible to our employees who work with us throughout the world. We provide an inclusive work environment where each person is considered as an individual. At Johnson & Johnson, we respect the diversity and dignity of our employees and recognize their merit.

Job Function

Technology Product & Platform Management

Job Sub Function

Technical Product Management

Job Category

Scientific/Technology

All Job Posting Locations

New Brunswick, New Jersey, United States of America, Palm Beach Gardens, Florida, United States of America, Raynham, Massachusetts, United States of America, Warsaw, Indiana, United States of America, West Chester, Pennsylvania, United States of America

Job Description

DePuy Synthes is recruiting for a(n) Exp, Analyst, Security Engineer Product located in New Brunswick, NJ or West Chester, PA or Palm Beach Gardens, FL or Warsaw, IN or Raynham, MA.

Job Overview

This role supports the protection of DePuy Synthes digital products and connected medical technologies by embedding security practices throughout the product lifecycle. The Exp, Analyst, Security Engineer Product partners closely with engineering, quality, regulatory, and IT teams to identify risks early, design secure solutions, and ensure products meet cybersecurity and regulatory expectations. This is an exciting opportunity to directly impact patient safety and product trust while working in a highly regulated, innovation‑driven environment and reports into the DePuy Synthes Technology organization.

Key Responsibilities
  • Integrate security requirements and controls into the design and development of digital and connected products.
  • Perform product security risk assessments, threat modeling, and vulnerability analysis across the product lifecycle.
  • Partner with product development, quality, and regulatory teams to support secure design reviews and remediation activities.
  • Support security testing activities, including static and dynamic analysis, penetration testing coordination, and vulnerability validation.
  • Track, document, and manage product security findings to closure in alignment with internal governance processes.
  • Contribute to the development and maintenance of product security standards, procedures, and best practices.
  • Monitor emerging cybersecurity threats, vulnerabilities, and regulatory guidance relevant to medical devices and digital health.
  • Support audits, assessments, and regulatory inquiries related to product cybersecurity.
Education
  • Required: Bachelor’s degree in Computer Science, Engineering, Information Security, or a related technical field.
  • Preferred: Master’s degree in Cybersecurity, Computer Engineering, or a related discipline.
Required
  • 2–4 years of relevant professional experience in cybersecurity, product security, or secure software development.
  • Working knowledge of secure development lifecycle (SDLC) practices and security‑by‑design principles.
  • Experience conducting security risk assessments, threat modeling, or vulnerability analysis.
  • Familiarity with common security standards and frameworks (e.g., ISO, NIST, OWASP).
  • Ability to collaborate effectively with cross‑functional technical and non‑technical teams.
  • Strong analytical, documentation, and communication skills.
Preferred
  • Experience supporting cybersecurity activities in a regulated industry (medical devices, healthcare, or life sciences).
  • Hands‑on exposure to security testing tools and techniques (e.g., SAST, DAST, dependency scanning).
  • Knowledge of cloud, embedded, or connected device security concepts.
  • Understanding of regulatory cybersecurity expectations (e.g., FDA premarket/postmarket guidance).
  • Experience contributing to internal security policies, standards, or governance processes.
Other
  • Language: English proficiency required.
  • Travel: Up to 10% domestic travel.
  • Certifications (Preferred): CISSP, CSSLP, GSEC, or equivalent security certification.

For more information on how we support the whole health of our employees throughout their wellness, career and life journey, please visit www.careers.jnj.com.

Johnson & Johnson announced plans to separate our Orthopaedics business to establish a standalone orthopaedics company, operating as DePuy Synthes. The process of the planned separation is anticipated to be completed within 18 to 24 months, subject to legal requirements, including consultation with works councils and other employee representative bodies, as may be required, regulatory approvals and other customary conditions and approvals. Should you accept this position, it is anticipated that, following conclusion of the transaction, you would be an employee of DePuy Synthes and your employment would be governed by DePuy Synthes employment processes, programs, policies, and benefit plans. In that case, details of any planned changes would be provided to you by DePuy Synthes at an appropriate time and subject to any necessary consultation processes.

Johnson & Johnson is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex,

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Exp, Analyst, Security Engineer Product
Exp, Analyst, Security Engineer Product

6090-Johnson & Johnson Services Inc. Legal Entity • New Brunswick (NJ)

On-site
USD 79,000 - 142,000
Professional, Quality Steward
Professional, Quality Steward

6090-Johnson & Johnson Services Inc. Legal Entity • New Brunswick (NJ)

On-site
USD 79,000 - 142,000
Vacation time
Parental Leave
Volunteer Leave
Professional, Service & Repair
Professional, Service & Repair

Antler • Warsaw (IN)

On-site
USD 94,000 - 152,000
Director, Incident Response & Threat
Director, Incident Response & Threat

Johnson & Johnson MedTech • West Chester

Hybrid
USD 150,000 - 259,000
Vacation – 120 hours/year
Sick time – 40 hours/year
Holiday pay – 13 days/year
+2
Director, Incident Response & Threat
Director, Incident Response & Threat

Johnson & Johnson MedTech • Town of Florida (NY)

Hybrid
USD 150,000 - 259,000
Vacation –120 hours per year
Parental Leave
Sick time – 40 hours/year (Colorado/Wa
+2
Director, Incident Response & Threat
Director, Incident Response & Threat

Johnson & Johnson MedTech • Raynham (MA)

Hybrid
USD 150,000 - 259,000
Vacation –120 hours per calendar year
Sick time –40 hours per calendar year
Holiday pay –13 days per calendar year
+1
Technology Manager, Quality Systems, BA
Technology Manager, Quality Systems, BA

Antler • Raynham (MA)

On-site
USD 102,000 - 204,000
Domestic travel
Professional, Compliance Lead
Professional, Compliance Lead

6090-Johnson & Johnson Services Inc. Legal Entity • New Brunswick (NJ)

On-site
USD 140,000 - 200,000
Professional, Tech Prod IT Sales
Professional, Tech Prod IT Sales

Antler • Raritan (NJ)

On-site
USD 112,000 - 152,000
Professional, Tech Prod IT Sales
Professional, Tech Prod IT Sales

Antler • Raynham (MA)

On-site
USD 112,000 - 152,000