Professional, Prog Lead, PenTesting Svcs

6090-Johnson & Johnson Services Inc. Legal Entity

New Brunswick (NJ)

On-site

USD 94,000 - 170,000

Full time

2 days ago
Be an early applicant
Application generator

Stand out for this role — generate a tailored resume and cover letter in about a minute.

Get past ATS filters

Job summary

Johnson & Johnson in New Brunswick, NJ, is recruiting for a Professional, Program Lead, Penetration Testing Services to build and run a comprehensive testing program across medical devices, embedded systems, mobile apps, APIs, and cloud services.

The role manages internal testers and external partners, defines methodology, and drives remediation with R&D and engineering teams to ensure patient safety and business risk are mitigated throughout the lifecycle.

Qualifications

  • Bachelor's degree in Computer Science, Cybersecurity, Software/Electrical/Biomedical Engineering, Information Systems, or a related technical discipline.
  • Advanced degree or specialized cybersecurity education (preferred).

Responsibilities

  • Own the end‑to‑end penetration testing services program for products and connected platforms, including roadmap and capacity planning.
  • Define and maintain the testing methodology, scoping standards, rules of engagement, and reporting templates.
  • Embed security testing gates into the product development lifecycle to ensure secure by design verification.
  • Execute and oversee hands‑on assessments across medical devices, firmware, mobile apps, APIs, and cloud infrastructure.
  • Manage third‑party penetration testing vendors and quality review of deliverables.

Skills

Penetration testing
Offensive security
Red teaming
Vendor management
Threat modeling
Cloud security
CI/CD security
Python scripting

Education

Bachelor's degree in CS/Engineering
Advanced cybersecurity degree preferred

Tools

Burp Suite
Metasploit
Nmap
Wireshark
Ghidra/IDA
Kali

Job description

At Johnson & Johnson,we believe health is everything. Our strength in healthcare innovation empowers us to build aworld where complex diseases are prevented, treated, and cured,where treatments are smarter and less invasive, andsolutions are personal.Through our expertise in Innovative Medicine and MedTech, we are uniquely positioned to innovate across the full spectrum of healthcare solutions today to deliver the breakthroughs of tomorrow, and profoundly impact health for humanity.Learn more at jnj.com As guided by Our Credo, Johnson & Johnson is responsible to our employees who work with us throughout the world. We provide an inclusive work environment where each person is considered as an individual. At Johnson & Johnson, we respect the diversity and dignity of our employees and recognize their merit.

Job Function: Technology Enterprise Strategy & Security
Job Sub Function: Solution Architecture
Job Category: Scientific/Technology
All Job Posting Locations:
  • New Brunswick, New Jersey, United States of America
  • Palm Beach Gardens, Florida, United States of America
  • Raynham, Massachusetts, United States of America
  • Warsaw, Indiana, United States of America
  • West Chester, Pennsylvania, United States of America
Job Description:

DePuy Synthes is recruiting for a(n) Professional, Prog Lead, PenTesting Svcs located in New Brunswick, NJ or West Chester, PA or Palm Beach Gardens, FL or Warsaw, IN or Raynham, MA.

Job Overview

The Professional, Program Lead, Penetration Testing Services is a seasoned individual contributor within the Cybersecurity function, Product Security sub‑function, accountable for building and running the penetration testing and offensive security services program for the DePuy Synthes product portfolio. This role establishes the testing methodology, scoping standards, and engagement model that embed Secure by Design verification into the product development lifecycle — spanning medical devices, embedded firmware, mobile applications, APIs, and supporting cloud services. The Program Lead manages internal testers and third‑party assessment partners, translates technical findings into patient safety and business risk, and drives remediation to closure with R&D and engineering teams. Applying advanced technical skills and industry‑leading practices, this role serves as the authoritative voice on product security testing across the enterprise.

Key Responsibilities

Own the end‑to‑end penetration testing services program for products and connected platforms, including the annual testing roadmap, prioritization model, and capacity planning across internal and external resources.

Define and maintain the penetration testing methodology, scoping standards, rules of engagement, and reporting templates aligned to industry frameworks (OWASP, PTES, NIST SP 800-115, MITRE ATT&CK).

Embed security testing gates into the product development lifecycle, ensuring Secure by Design verification occurs at defined design, integration, and pre‑release milestones.

Execute and oversee hands‑on assessments across medical devices, embedded firmware, wireless protocols, mobile applications, web applications, APIs, and cloud infrastructure.

Manage third‑party penetration testing vendors — including scoping, statement of work development, quality review of deliverables, and performance management against SLAs.

Triage and validate findings, assess exploitability, and evaluate patient safety and clinical impact in partnership with Product Security, Quality, and Regulatory stakeholders.

Drive remediation with R&D and engineering teams, tracking findings through retest and verified closure, and escalating overdue or elevated risks through governance channels.

Conduct threat modeling and attack surface analysis to inform test scoping and identify high‑value targets prior to engagement.

Support regulatory and customer requirements by producing testing evidence for FDA pre‑market submissions, EU MDR technical files, and hospital security assessments.

Contribute penetration testing results and residual risk analysis into product security risk files aligned to AAMI TIR57 and ISO 14971.

Build and report program metrics — test coverage across the portfolio, finding severity distribution, remediation aging, and retest pass rates — to leadership and product stakeholders.

Research emerging attack techniques, medical device vulnerabilities, and tooling; continuously evolve the testing capability and develop custom tooling and exploits where needed.

Assess the testing implications of platform migrations, supplier changes, and separation/carve‑out activity affecting the product portfolio and supporting infrastructure.

Deliver technical enablement and secure development training to engineering teams, using real findings to strengthen security ownership and cyber culture.

Qualifications

Education: Bachelor's degree in Computer Science, Cybersecurity, Software/Electrical/Biomedical Engineering, Information Systems, or a related technical discipline.

Advanced degree or specialized cybersecurity education (preferred).

Experience and Skills Required

Minimum 6 years of progressive experience in penetration testing, offensive security, red teaming, or application security assessment.

Demonstrated experience leading or managing a penetration testing program, including methodology definition, scoping standards, and vendor oversight.

Hands‑on proficiency across multiple domains: web application, API, mobile, network, wireless, and cloud penetration testing.

Working knowledge of common testing tools and frameworks (Burp Suite, Metasploit, Nmap, Wireshark, Ghidra/IDA, Kali) and scripting proficiency (Python, Bash, PowerShell).

Strong understanding of vulnerability classes and taxonomies (OWASP Top 10, CWE) and risk scoring methodologies (CVSS).

Experience embedding security testing into an SDLC and driving remediation with engineering teams through verified closure.

Excellent written and verbal communication skills, with proven ability to translate technical exploitation detail into business and patient safety risk for non‑technical audiences.

Preferred: MedTech or medical device experience; familiarity with FDA pre‑market/post‑market cybersecurity guidance, EU MDR, IEC 62304, ISO 14971, and AAMI TIR57.

Embedded systems and firmware security experience, including hardware interfaces (JTAG/UART), secure boot, and reverse engineering.

Experience testing wireless and IoMT protocols (Bluetooth/BLE, Zigbee, RF, proprietary protocols).

Experience supporting product security testing within a divestiture, carve‑out, or standalone entity stand‑up.

Cloud penetration testing experience in AWS and/or Azure environments.

Exposure to coordinated vulnerability disclosure programs and researcher engagement.

Experience applying Generative AI / LLM‑enabled tooling to accelerate reconnaissance, code review, and reporting workflows.

Experience integrating automated security testing into DevSecOps and CI/CD pipelines.

Other
Travel

Up to 10% domestic and international travel expected for lab‑based device testing and site engagements.

Language

English proficiency required.

Certifications

OSCP, OSCE, GPEN, GWAPT, or GXPN required or in progress.

OSWE, GRTP, CRTO, or CISSP preferred.

Required Skills
  • Business Alignment
  • Business Architecture
  • Business Requirements Analysis
  • Coaching
  • Consulting
  • Critical Thinking
  • Emerging Technologies
  • Information Security Management System (ISMS)
  • Information Technology Strategies
  • Information Technology Trends
  • IT Architecture
  • Management Systems Implementation
  • Problem Solving
  • Requirements Analysis
  • Solution Architecture
  • Technical Credibility
  • Technical Writing
  • Technologically Savvy
Preferred Skills
  • Business Alignment
  • Business Architecture
  • Business Requirements Analysis
  • Coaching
  • Consulting
  • Critical Thinking
  • Emerging Technologies
  • Information Security Management System (ISMS)
  • Information Technology Strategies
  • Information Technology Trends
  • IT Architecture
  • Management Systems Implementation
  • Problem Solving
  • Requirements Analysis
  • Solution Architecture
  • Technical Credibility
  • Technical Writing
  • Technologically Savvy

The anticipated base pay range for this position is : 94,000.00 - 170,000.00 USD

Annual Additional Description for Pay Transparency

Subject to the terms of their respective plans, employees are eligible to participate in the Company’s consolidated retirement plan (pension) and savings plan (401(k)). Subject to the terms of their respective policies and date of hire, employees are eligible for the following time off benefits:

  • Vacation –120 hours per calendar year
  • Sick time - 40 hours per calendar year; for employees who reside in the State of Colorado –48 hours per calendar year; for employees who reside in the State of Washington –56 hours per calendar year
  • Holiday pay, including Floating Holidays –13 days per calendar year
  • Work, Personal and Family Time - up to 40 hours per calendar year
  • Parental Leave – 480 hours within one year of the birth/adoption/foster care of a child
  • Bereavement Leave – 240 hours for an immediate family member: 40 hours for an extended family member per calendar year
  • Caregiver Leave – 80 hours in a 52-week rolling period10 days
  • Volunteer Leave – 32 hours per calendar year
  • Military Spouse Time-Off – 80 hours per calendar year

For additional general information on Company benefits, please go to: - https://www.careers.jnj.com/employee-benefits

At Johnson & Johnson,we believe health is everything. Our strength in healthcare innovation empowers us to build aworld where complex diseases are prevented, treated, and cured,where treatments are smarter and less invasive, andsolutions are personal.Through our expertise in Innovative Medicine and MedTech, we are uniquely positioned to innovate across the full spectrum of healthcare solutions today to deliver the breakthroughs of tomorrow, and profoundly impact health for humanity.Learn more at https://www.jnj.com/.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Professional, Prog Lead, PenTesting Svcs
Professional, Prog Lead, PenTesting Svcs

Johnson & Johnson MedTech • Warsaw (IN)

On-site
USD 94,000 - 170,000
Professional, Quality Steward
Professional, Quality Steward

6090-Johnson & Johnson Services Inc. Legal Entity • New Brunswick (NJ)

On-site
USD 79,000 - 142,000
Vacation time
Parental Leave
Volunteer Leave
Exp, Analyst, Security Engineer Product
Exp, Analyst, Security Engineer Product

6090-Johnson & Johnson Services Inc. Legal Entity • New Brunswick (NJ)

On-site
USD 79,000 - 142,000
Professional, Quality Steward
Professional, Quality Steward

Johnson & Johnson MedTech • New Brunswick (NJ)

On-site
USD 79,000 - 142,000
Vacation – 120 hours
Sick time – 40 hours
Holiday pay – 13 days per year
+2
Professional, Quality Steward
Professional, Quality Steward

Johnson & Johnson MedTech • Raynham (MA)

On-site
USD 79,000 - 142,000
System Implementation Lead & Project Manager, R&D - MedTech
System Implementation Lead & Project Manager, R&D - MedTech

6045-Ethicon Inc. Legal Entity • Raritan (NJ)

Hybrid
USD 109,000 - 175,000
Director, Incident Response & Threat
Director, Incident Response & Threat

Johnson & Johnson MedTech • Raynham (MA)

Hybrid
USD 150,000 - 259,000
Vacation –120 hours per calendar year
Sick time –40 hours per calendar year
Holiday pay –13 days per calendar year
+1
Director, Incident Response & Threat
Director, Incident Response & Threat

Johnson & Johnson MedTech • Town of Florida (NY)

Hybrid
USD 150,000 - 259,000
Vacation –120 hours per year
Parental Leave
Sick time – 40 hours/year (Colorado/Wa
+2
Director, Incident Response & Threat
Director, Incident Response & Threat

Johnson & Johnson MedTech • West Chester

Hybrid
USD 150,000 - 259,000
Vacation – 120 hours/year
Sick time – 40 hours/year
Holiday pay – 13 days/year
+2
Professional, Compliance Lead
Professional, Compliance Lead

6090-Johnson & Johnson Services Inc. Legal Entity • New Brunswick (NJ)

On-site
USD 140,000 - 200,000