Principal Security Architect

Johnson Johnson

New Brunswick (NJ)

On-site

USD 150,000 - 230,000

Full time

38 hours ago
Be an early applicant
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Job summary

DePuy Synthes is seeking a Principal Security Architect to lead secure-by-design architecture across cloud, network, endpoint, data, identity, and OT environments. You will perform threat modeling, risk assessments, and design resilient, compliant security controls for enterprise platforms.

The role emphasizes Zero Trust, risk mitigation, and continuous improvement with collaboration across Enterprise and Solution Architects to embed security in transformation initiatives.

Qualifications

  • Bachelor’s degree in Computer Science, Information Security, Engineering, or related field.
  • Master’s degree in Cybersecurity, Information Security, or related discipline preferred.

Responsibilities

  • Lead Secure by Design, Resilient by Design, and Zero Trust architectures across cloud, network, endpoint, identity, application, data, and OT environments.
  • Conduct security architecture reviews, threat modeling, and risk assessments for new and existing solutions.
  • Drive enterprise Zero Trust strategy including identity, segmentation, least privilege, and continuous verification capabilities.
  • Design network segmentation and micro-segmentation architectures to protect critical assets.

Skills

Security architecture
Vulnerability management
Zero trust
Cloud security
Endpoint protection
Network segmentation
Regulatory standards
Threat modeling
Security tooling

Education

Bachelor's degree in Computer Science/Info Security/Engineering
Master's degree in Cybersecurity/Info Security

Tools

AWS
Azure
GCP

Job description

DePuy Synthes is recruiting for a Principal, Security Architect, located in the United States.

The Security Architect designs, evaluates, and strengthens the security architecture that protects DePuy Synthes technology assets, data, and operational environments. Sitting within the Technology Enterprise Strategy & Security organization, this role serves as a technical authority on security controls—assessing system and network configurations, identifying vulnerabilities and exposures, performing root-cause analysis, and contributing to the design, development, and implementation of countermeasures and security tooling across the enterprise.

This role is responsible for advancing the organization’s Zero Trust, Secure by Design, and Resilient by Design strategy, ensuring security and resilience are embedded into every technology platform, architecture decision, and transformation initiative.

Key Responsibilities
  • Lead the development of Secure by Design, Resilient by Design, and Zero Trust architectures across cloud, network, endpoint, identity, application, data, and OT environments.
  • Conduct security architecture reviews, threat modeling, and risk assessments for new and existing solutions.
  • Drive the enterprise Zero Trust strategy, including identity, segmentation, least privilege, and continuous verification capabilities.
  • Design network segmentation and micro-segmentation architectures to protect critical assets and reduce lateral movement.
  • Define vulnerability and exposure management strategies, including risk-based prioritization and remediation.
  • Develop resilient security architectures that strengthen containment, recovery, and business continuity capabilities.
  • Design endpoint security controls, hardening standards, device compliance frameworks, and EDR/XDR integrations.
  • Establish secure architectures for cloud, AI, data, and application environments, including secure development, DevSecOps, and AI governance practices.
  • Develop OT security architectures that protect manufacturing, laboratory, and connected device environments.
  • Partner with Enterprise and Solution Architects to embed security, resilience, and compliance requirements across transformation initiatives.
  • Evaluate architectures and configurations against frameworks including NIST, NIST Zero Trust, CIS, ISO 27001, and applicable regulatory requirements.
  • Drive security automation, tooling integrations, and engineering improvements that enhance enterprise defenses.
  • Perform root-cause analysis of security findings and incidents, recommending strategic and sustainable improvements.
  • Produce architecture standards, reference designs, technical documentation, and executive-level roadmaps.
  • Mentor and coach security architects and engineers while fostering a culture of engineering excellence and continuous improvement.
Qualifications
Education:
  • Required: Bachelor's degree in Computer Science, Information Security, Engineering, or a related technical field.
  • Preferred: Master's degree in Cybersecurity, Information Security, or a related discipline.
Experience and Skills:
Required:
  • 8+ years of experience in information security, with demonstrated depth in security architecture and controls.
  • Hands‑on experience with vulnerability and exposure management, including assessment and remediation.
  • Strong knowledge of network security and segmentation, firewalls, and zero‑trust architecture.
  • Experience designing endpoint protection and device security controls (e.g., EDR/XDR, device hardening).
  • Experience with cloud security across one or more major platforms (AWS, Azure, or GCP), including secure configuration and workload protection.
  • Working knowledge of application and data security principles, including secure SDLC and data protection.
  • Familiarity with industry frameworks and standards (e.g., NIST CSF, ISO 27001, CIS Controls).
Preferred:
  • Experience securing Operational Technology (OT) and connected/IoT device environments.
  • Experience defining security controls for AI, data, and Generative AI solutions.
  • Experience in a regulated industry (MedTech, Pharmaceutical, or Healthcare) with familiarity in associated compliance requirements.
  • Experience with security automation, SOAR, and security tooling integration.
  • Experience supporting large‑scale transformation or separation programs.
Other:
  • Travel: Up to 25%
  • Certifications: Relevant security certifications (e.g., CISSP, CISSP-ISSAP, CCSP, SABSA, or cloud security certifications) preferred.

For more information on how we support the whole health of our employees throughout their wellness, career and life journey, please visit www.careers.jnj.com.

Johnson & Johnson announced plans to separate our Orthopedics business to establish a standalone Orthopedics company, operating as DePuy Synthes. The process of the planned separation is anticipated to be completed within 18 to 24 months, subject to legal requirements, including consultation with works councils and other employee representative bodies, as may be required, regulatory approvals and other customary conditions and approvals. Should you accept this position, it is anticipated that, following conclusion of the transaction, you would be an employee of DePuy Synthes and your employment would be governed by DePuy Synthes employment processes, programs, policies, and benefit plans. In that case, details of any planned changes would be provided to you by DePuy Synthes at an appropriate time and subject to any necessary consultation processes.

Johnson & Johnson is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, age, national origin, disability, protected veteran status or other characteristics protected by federal, state or local law. We actively seek qualified candidates who are protected veterans and individuals with disabilities as defined under VEVRAA and Section 503 of the Rehabilitation Act.

Johnson & Johnson is committed to providing an interview process that is inclusive of our applicants’ needs. If you are an individual with a disability and would like to request an accommodation, external applicants please contact us via https://www.jnj.com/contact-us/careers, internal employees contact AskGS to be directed to your accommodation resource.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Principal, Security Architect
Principal, Security Architect

Johnson Johnson • New Brunswick (NJ)

Hybrid
USD 102,000 - 177,000
Principal, Security Architect
Principal, Security Architect

Johnson & Johnson MedTech • Raritan (NJ)

On-site
USD 102,000 - 204,000
Principal, Security Architect
Principal, Security Architect

Brighter Signals • New Brunswick (NJ)

On-site
USD 102,000 - 204,000
Director Cyber Defense
Director Cyber Defense

Johnson Johnson • Raynham (MA)

On-site
USD 180,000 - 240,000
Manager, Laboratory Systems & Data
Manager, Laboratory Systems & Data

6149-DePuy Synthes Products Inc. Legal Entity • Raynham (MA)

Hybrid
USD 117,000 - 201,000
Regional Sales Manager, Trauma and Extremities
Regional Sales Manager, Trauma and Extremities

Johnson & Johnson MedTech • City of White Plains (NY)

On-site
USD 131,000 - 212,000
Vacation 120 hours per calendar year
Sick time 40 hours per calendar year
Parental Leave 480 hours
+2
VP, Head of Internal Audit, Orthopedics
VP, Head of Internal Audit, Orthopedics

6090-Johnson & Johnson Services Inc. Legal Entity • Raynham (MA)

On-site
USD 199,000 - 367,000
VP, Global Education Capabilities
VP, Global Education Capabilities

Johnson & Johnson MedTech • West Chester

On-site
USD 199,000 - 367,000
Vacation –120 hours
401(k) plan
Paid time off
Clinical Sales Specialist, Trauma – Savannah, GA – Johnson & Johnson MedTech - Orthopaedics
Clinical Sales Specialist, Trauma – Savannah, GA – Johnson & Johnson MedTech - Orthopaedics

6032-DePuy Synthes Sales, Inc. Legal Entity • West Chester

On-site
USD 85,000 - 125,000
Senior Sales Consultant, Sports Medicine (Detroit, MI) – Johnson & Johnson MedTech, Orthopaedics
Senior Sales Consultant, Sports Medicine (Detroit, MI) – Johnson & Johnson MedTech, Orthopaedics

6032-DePuy Synthes Sales, Inc. Legal Entity • Raynham (MA)

On-site
USD 85,000 - 125,000