Principal Med Device Security Engineer

Johnson & Johnson

Garden City (SC)

Hybrid

USD 102,000 - 177,100

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

120 hours of vacation
40 hours of sick time
Holiday pay – 13 days per year
Parental leave – 480 hours

Job summary

Johnson & Johnson’s MedTech cybersecurity team is looking for an experienced Principal Product Security Engineer. This role involves implementing the company’s Product Security strategy across various medical devices while leading security practices.

Key qualifications include 8+ years in Information Security and experience with embedded systems. This position offers remote work options and competitive pay.

Qualifications

  • 8+ years of industry experience in Information Security.
  • 5+ years with embedded systems, IoT, or medical device cybersecurity.
  • Strong project leadership and ability to track timelines.

Responsibilities

  • Implement J&J’s enterprise Product Security strategy across the Heart Recovery portfolio.
  • Drive alignment to J&J Product Security’s overarching framework.
  • Lead Secure Development Lifecycle practices, integrating threat modeling and testing.

Skills

Information Security
Embedded systems
Risk assessments
Technical security requirements
Cloud security principles
Secure coding
Data privacy

Education

Bachelor’s degree or equivalent

Tools

CVSS
STRIDE methodology
QNX
Linux Ubuntu
AWS
Azure

Job description

Johnson & Johnson’s MedTech cybersecurity team is recruiting for an experienced Principal Product Security Engineer. The role can be remote-based or located onsite in Danvers, MA or Raritan, NJ, and will require up to 10% travel.

Responsibilities

The Principal Product Security Engineer will implement J&J’s enterprise Product Security strategy and framework across the Heart Recovery portfolio, providing technical expertise and strategic leadership in securing Impella heart pump technologies and related medical devices.

  • Drive alignment to J&J Product Security’s overarching framework.
  • Support the Product Security strategy and objectives within Heart Recovery.
  • Define and implement secure boot, firmware integrity validation, and anti-tamper mechanisms for device firmware.
  • Enforce cryptographic protocols for data-at-rest and data-in-transit, ensuring compliance with FDA cybersecurity requirements, NIST 800-175, FIPS 140-3, and IEC 62443.
  • Define and implement key management infrastructure (PKI, HSMs, TPMs, and secure enclave integration) for device identity, authentication, and software signing.
  • Develop real-time vulnerability assessment techniques for detecting security flaws in wireless communications (Bluetooth LE, NFC, Wi‑Fi, 5G, proprietary RF).
  • Implement Zero Trust security for device-to-cloud connectivity, integrating mTLS and continuous authentication models.
  • Oversee secure OTA update mechanisms, ensuring firmware rollbacks, code signing, and supply chain integrity validation.
  • Lead Secure Development Lifecycle practices, integrating threat modeling, static/dynamic analysis, fuzz testing, and formal verification.
  • Work with R&D Engineering to define hardware security architecture, including trust zones and hardware root of trust.
  • Implement memory safety strategies to mitigate buffer overflows, side‑channel attacks, and execution vulnerabilities in real‑time operating systems and bare‑metal firmware.
  • Respond to customer cybersecurity questionnaires and contractual language for post‑market medical devices.
Qualifications

Key requirements for this role include:

  • 8+ years of industry experience in Information Security.
  • 5+ years with embedded systems, IoT, or medical device cybersecurity.
  • Bachelor’s degree or equivalent.
  • Experience generating threat models without tools.
  • Experience performing risk assessments using CVSS 3.1 or higher and STRIDE methodology.
  • Ability to write technical security requirements for embedded systems and web platforms.
  • Understanding of third‑party penetration testing, vulnerability scanning, and security testing principles.
  • Experience supporting regulatory security submissions (FDA Guidance 2025, EU MDR, NIST 800‑53, IMDRF, AAMI TIR57).
  • Knowledge of real‑time operating system hardening techniques and cloud security principles.
  • Ability to generate SBOMs from software, firmware, and operating systems.
  • Ability to conduct pre‑market and post‑market risk assessments using STRIDE and SCA SBOM scans.
  • Ability to create security architecture views for medical devices.
  • Strong secure coding and review skills.
  • Data privacy experience (HIPAA, GDPR).
  • Understanding of industry standards and certifications such as HITRUST and ISO 27001.
  • Strong project leadership and ability to track timelines.
  • Excellent communication, collaboration, and leadership skills.
  • Creative problem‑solving and customer focus.
Preferred Qualifications
  • Experience leading or participating in formal security audits.
  • Experience with QNX, QOS, Yocto, Linux Ubuntu, and Alpine.
  • Familiarity with FDA and other global cybersecurity guidance and submission processes.
  • Experience with web application and server hardening (AWS, Azure) and OWASP Top 10.
  • Experience in cybersecurity pre‑sales.
  • Software development experience.
  • Certifications such as CISSP or CISM.
  • MS or advanced degree.
Benefits
  • Vacation – 120 hours per calendar year.
  • Sick time – 40 hours per calendar year (48 in Colorado, 56 in Washington).
  • Holiday pay, including floating holidays – 13 days per calendar year.
  • Work, personal, and family time – up to 40 hours per calendar year.
  • Parental leave – 480 hours within one year of birth/adoption/foster care.
  • Bereavement leave – 240 hours for immediate family; 40 hours for extended family.
  • Caregiver leave – 80 hours in a 52‑week rolling period.
  • Volunteer leave – 32 hours per calendar year.
  • Military spouse time‑off – 80 hours per calendar year.
Pay

$102,000.00 – $177,100.00

EEO Statement

Johnson & Johnson is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, age, national origin, disability, protected veteran status, or other characteristics protected by federal, state or local law. We actively seek qualified candidates who are protected veterans and individuals with disabilities as defined under VEVRAA and Section 503 of the Rehabilitation Act. If you are an individual with a disability and would like to request an accommodation, please contact us at https://www.jnj.com/contact-us/careers or ask GS to be directed to your accommodation resource.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Principal Product Security Engineer
Principal Product Security Engineer

Johnson & Johnson • Santa Clara (CA)

On-site
USD 118,000 - 204,000
Vacation hours
Parental Leave
Holiday pay
Principal Product Security Engineer
Principal Product Security Engineer

6267-Auris Health Inc. Legal Entity • Santa Clara (CA)

On-site
USD 118,000 - 204,000
Lead Product Security Engineer
Lead Product Security Engineer

6942-ABIOMED Inc. Legal Entity • Danvers (MA)

On-site
USD 94,000 - 152,000
Medical, dental, vision, and life insurance
401(k) savings plan
Paid time off including parental leave
Manager, External Innovation - MedTech Surgery
Manager, External Innovation - MedTech Surgery

Johnson & Johnson MedTech • Raritan (NJ)

Hybrid
USD 117,000 - 202,000
Vacation – 120 hours per calendar year
Parental Leave – 480 hours within one year of a child's birth/adoption/foster care
Sick time – 40 hours per calendar year
Senior Director, Head of Technology, Heart Recovery
Senior Director, Head of Technology, Heart Recovery

Johnson & Johnson • Danvers (MA)

On-site
USD 196,000 - 343,000
Senior Principal, Cyber Experience & AI Engagement
Senior Principal, Cyber Experience & AI Engagement

Johnson & Johnson • Raritan (NJ)

On-site
USD 137,000 - 236,000
Senior Principal, Cyber Experience & AI Engagement
Senior Principal, Cyber Experience & AI Engagement

6090-Johnson & Johnson Services Inc. Legal Entity • Raritan (NJ)

On-site
USD 137,000 - 236,000
Medical
Dental
Vision
+4
Principal Med Device Security Engineer
Principal Med Device Security Engineer

Jobtailor • Maine

On-site
USD 180,000 - 240,000
Principal MedTech Security Engineer - Remote/Hybrid Leader
Principal MedTech Security Engineer - Remote/Hybrid Leader

Johnson & Johnson • Garden City (SC)

Hybrid
USD 102,000 - 178,000
120 hours of vacation
40 hours of sick time
Holiday pay – 13 days per year
+1
Staff Electrical Engineer
Staff Electrical Engineer

6240-AMO Manufacturing USA LLC Legal Entity • Milpitas (CA)

On-site
USD 109,000 - 175,000
401(k) plan
Pension plan