Professional, Quality Steward

6090-Johnson & Johnson Services Inc. Legal Entity

New Brunswick (NJ)

On-site

USD 79,000 - 142,000

Full time

2 days ago
Be an early applicant
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Benefits offered by this job

Vacation time
Parental Leave
Volunteer Leave

Job summary

Johnson & Johnson is seeking a Professional, Quality Steward in the Cybersecurity function across DePuy Synthes product lines. The role embeds Secure by Design into the development lifecycle from concept through end-of-support, working with R&D, Product Management, Engineering, Regulatory Affairs and Quality.

The ideal candidate has 4+ years in product security, strong threat modeling skills, and experience with SBOMs and regulatory cybersecurity submissions. Travel up to 10% may be required.

Qualifications

  • 4+ years in product security, application security, or related cybersecurity engineering discipline.
  • Experience applying Secure by Design across a product development lifecycle.
  • Familiarity with SBOM generation formats and vulnerability management.

Responsibilities

  • Embed Secure by Design into the development lifecycle from concept through end-of-support.
  • Define security requirements, design inputs, and acceptance criteria with product owners and R&D.
  • Facilitate threat modeling and security architecture reviews for connected devices and cloud services.
  • Coordinate vulnerability management, SBOMs, third-party components, and remediation planning.
  • Prepare cybersecurity documentation for regulatory submissions and regulatory inquiries.

Skills

Threat modeling
Secure by Design
SBOM
Vulnerability management
Regulatory submissions
CI/CD security
SAST/DAST/SCA
Cloud security
Embedded security
Communication

Education

Bachelor's degree in Computer Science, Cybersecurity, Software/Biomedical/ Electrical Engineering, Information Systems
Master's degree in Cybersecurity, Computer Science, or Biomedical Engineering

Tools

Threat modeling methodologies (STRIDE)
Secure coding practices
SBOM formats (SPDX, CycloneDX)
Vulnerability management tooling
CI/CD security tooling

Job description

At Johnson & Johnson,we believe health is everything. Our strength in healthcare innovation empowers us to build aworld where complex diseases are prevented, treated, and cured,where treatments are smarter and less invasive, andsolutions are personal.Through our expertise in Innovative Medicine and MedTech, we are uniquely positioned to innovate across the full spectrum of healthcare solutions today to deliver the breakthroughs of tomorrow, and profoundly impact health for humanity.Learn more at jnj.com As guided by Our Credo, Johnson & Johnson is responsible to our employees who work with us throughout the world. We provide an inclusive work environment where each person is considered as an individual. At Johnson & Johnson, we respect the diversity and dignity of our employees and recognize their merit.

Job Function: Technology Product & Platform Management Job Sub Function: Technical Product Management Job Category: Scientific/Technology All Job Posting Locations: New Brunswick, New Jersey, United States of America, Palm Beach Gardens, Florida, United States of America, Raynham, Massachusetts, United States of America, Warsaw, Indiana, United States of America, West Chester, Pennsylvania, United States of America

Job Description: DePuy Synthes is recruiting for a Professional, Quality Steward located in New Brunswick, NJ or West Chester, PA or Palm Beach Gardens, FL or Warsaw, IN or Raynham, MA. Job Overview The Professional, Quality Steward is an established and productive individual contributor within the Cybersecurity function, accountable for embedding Secure by Design principles into the DePuy Synthes medical device and connected product portfolio. This role serves as the quality and security steward across the total product lifecycle — partnering with R&D, Product Management, Engineering, Regulatory Affairs, and Quality to ensure security requirements are defined early, designed in, verified through testing, and sustained through postmarket monitoring. Working under moderate supervision, the analyst applies practical knowledge of product security, secure development practices, and medical device regulatory expectations to ensure products are safe, secure, compliant, and defensible to regulators and customers.

Key Responsibilities Serve as the product security steward for assigned product lines, embedding Secure by Design requirements into the product development lifecycle from concept through end-of-support. Define and document security requirements, design inputs, and acceptance criteria in collaboration with product owners, systems engineers, and R&D teams during early design phases. Facilitate threat modeling and security architecture reviews for connected devices, embedded software, mobile applications, and supporting cloud services; ensure identified threats are mitigated and traceable to controls. Conduct and coordinate product security risk assessments aligned to AAMI TIR57 and ISO 14971, ensuring cybersecurity risk is integrated with overall product risk management files. Generate, validate, and maintain Software Bills of Materials (SBOMs) for products; monitor third‑party and open‑source components for known vulnerabilities and drive remediation planning. Support secure software development practices, including secure coding standards, static and dynamic analysis, dependency scanning, and integration of security gates into CI/CD pipelines. Coordinate penetration testing and security verification activities with internal teams and third‑party assessors; triage findings, assess exploitability and patient safety impact, and track remediation to closure. Prepare and review cybersecurity documentation for regulatory submissions, aligned to FDA premarket cybersecurity guidance, EU MDR, and applicable international requirements. Operate postmarket vulnerability management for released products — monitoring threat intelligence, performing impact analysis, and supporting coordinated vulnerability disclosure and customer advisories. Develop and maintain customer‑facing security artifacts, including MDS2 forms, security white papers, and responses to hospital and health system security assessments. Partner with Quality and Regulatory to ensure product security activities are captured in design history files, design controls, and the Quality Management System. Establish and report product security metrics — design review coverage, vulnerability aging, SBOM currency, and remediation SLA performance — to leadership and program stakeholders. Assess security implications of product changes, platform migrations, supplier changes, and separation/carve‑out activity affecting the product portfolio. Deliver Secure by Design training and enablement to engineering and product teams to strengthen security ownership and cyber culture.

Qualifications Education Bachelor's degree in Computer Science, Cybersecurity, Software/Biomedical/ Electrical Engineering, Information Systems, or a related technical discipline. Master's degree in Cybersecurity, Computer Science, or Biomedical Engineering. Experience and Skills Required: 4+ years of experience in product security, application security, secure software development, or a related cybersecurity engineering discipline. Demonstrated experience applying Secure by Design principles across a product development lifecycle, including security requirements definition and design review. Hands‑on experience with threat modeling methodologies (e.g., STRIDE, attack trees) for embedded, mobile, or connected systems. Working knowledge of secure coding practices, common vulnerability classes (OWASP Top 10, CWE), and application security testing tools (SAST, DAST, SCA). Experience with vulnerability management, including CVE analysis, CVSS scoring, and risk‑based remediation prioritization. Familiarity with SBOM generation, formats (SPDX, CycloneDX), and third‑party/open‑source component risk management. Strong written and verbal communication skills, with the ability to explain security risk to engineering, quality, regulatory, and commercial stakeholders. Preferred: MedTech or medical device experience; working knowledge of FDA premarket and postmarket cybersecurity guidance, EU MDR, IEC 62304, ISO 14971, ISO 13485, and AAMI TIR57/TIR97. Experience preparing cybersecurity content for regulatory submissions and responding to agency questions. Experience supporting product security within a divestiture, carve‑out, or standalone entity stand‑up. Familiarity with embedded systems security, firmware analysis, secure boot, cryptographic key management, and hardware root of trust. Experience with cloud and connected‑platform security (AWS, Azure), API security, and IoT/IoMT architectures. Exposure to coordinated vulnerability disclosure programs and customer security assessment response (MDS2, HSCC guidance). Experience applying Generative AI / LLM‑enabled tooling to accelerate code review, threat modeling, and security documentation. Familiarity with DevSecOps toolchains and integrating security gates into CI/CD pipelines.

Other: Travel: Up to 10% domestic and international travel expected across DePuy Synthes sites. Language: English proficiency required. Certifications: CSSLP, GWAPT, OSCP, CEH, CISSP, or equivalent product/application security certification preferred. For more information on how we support the whole health of our employees throughout their wellness, career, and life journey, please visit www.careers.jnj.com.

Johnson & Johnson announced plans to separate our Orthopaedics business to establish a standalone orthopaedics company, operating as DePuy Synthes. The process of the planned separation is anticipated to be completed within 18 to 24 months, subject to legal requirements, including consultation with works councils and other employee representative bodies, as may be required, regulatory approvals and other customary conditions and approvals. Should you accept this position, it is anticipated that, following conclusion of the transaction, you would be an employee of DePuy Synthes and your employment would be governed by DePuy Synthes employment processes, programs, policies, and benefit plans. In that case, details of any planned changes would be provided to you by DePuy Synthes at an appropriate time and subject to any necessary consultation processes.

Johnson & Johnson is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, age, national origin, disability, protected veteran status or other characteristics protected by federal, state or local law. We actively seek qualified candidates who are protected veterans and individuals with disabilities as defined under VEVRAA and Section 503 of the Rehabilitation Act. Johnson & Johnson is committed to providing an interview process that is inclusive of our applicants’ needs. If you are an individual with a disability and would like to request an accommodation, external applicants please contact us via https://www.jnj.com/contact-us/careers, internal employees contact AskGS to be directed to your accommodation resource.

Required Skills

Preferred Skills: Analytical Reasoning, Coaching, Communication, Cross‑Functional Collaboration, Demand Forecasting, Human‑Computer Interaction (HCI), Persistence and Tenacity, Product Costing, Product Development, Product Strategies, Quality Assurance (QA), Research and Development, Researching, Software Development Management, Technical Credibility, Technologically Savvy

The anticipated base pay range for this position is : 79,000.00 - 142,000.00 USD Annual Additional Description for Pay Transparency: Subject to the terms of their respective plans, employees are eligible to participate in the Company’s consolidated retirement plan (pension) and savings plan (401(k)). Subject to the terms of their respective policies and date of hire, employees are eligible for the following time off benefits:

  • Vacation –120 hours per calendar year
  • Sick time - 40 hours per calendar year; for employees who reside in the State of Colorado –48 hours per calendar year; for employees who reside in the State of Washington –56 hours per calendar year
  • Holiday pay, including Floating Holidays –13 days per calendar year
  • Work, Personal and Family Time - up to 40 hours per calendar year
  • Parental Leave – 480 hours within one year of the birth/adoption/foster care of a child
  • Bereavement Leave – 240 hours for an immediate family member: 40 hours for an extended family member per calendar year
  • Caregiver Leave – 80 hours in a 52-week rolling period10 days
  • Volunteer Leave – 32 hours per calendar year
  • Military Spouse Time-Off – 80 hours per calendar year

For additional general information on Company benefits, please go to: - https://www.careers.jnj.com/employee-benefits At Johnson & Johnson,we believe health is everything. Our strength in healthcare innovation empowers us to build aworld where complex diseases are prevented, treated, and cured,where treatments are smarter and less invasive, andsolutions are personal.Through our expertise in Innovative Medicine and MedTech, we are uniquely positioned to innovate across the full spectrum of healthcare solutions today to deliver the breakthroughs of tomorrow, and profoundly impact health for humanity.Learn more at https://www.jnj.com/.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Exp, Analyst, Security Engineer Product
Exp, Analyst, Security Engineer Product

6090-Johnson & Johnson Services Inc. Legal Entity • New Brunswick (NJ)

On-site
USD 79,000 - 142,000
Professional, Quality Steward
Professional, Quality Steward

Johnson & Johnson MedTech • New Brunswick (NJ)

On-site
USD 79,000 - 142,000
Vacation – 120 hours
Sick time – 40 hours
Holiday pay – 13 days per year
+2
Professional, Quality Steward
Professional, Quality Steward

Johnson & Johnson MedTech • Raynham (MA)

On-site
USD 79,000 - 142,000
Technology Manager, Quality Systems, BA
Technology Manager, Quality Systems, BA

Antler • Raynham (MA)

On-site
USD 102,000 - 204,000
Domestic travel
Technology Mgr, Quality Systems, Analyst
Technology Mgr, Quality Systems, Analyst

Antler • Raynham (MA)

On-site
USD 102,000 - 204,000
Manager, LMS & Learning Platforms
Manager, LMS & Learning Platforms

6029-MEDICAL DEVICE BUSINESS SERVICES, INC. Legal Entity • West Chester

On-site
USD 122,000 - 213,000
Long-term incentive program
401(k) plan
Professional, Prog Lead, PenTesting Svcs
Professional, Prog Lead, PenTesting Svcs

6090-Johnson & Johnson Services Inc. Legal Entity • New Brunswick (NJ)

On-site
USD 94,000 - 170,000
Tech Professional, Quality Systems, AI
Tech Professional, Quality Systems, AI

Antler • Raynham (MA)

On-site
USD 94,000 - 170,000
Tech Professional, Quality Systems, AI
Tech Professional, Quality Systems, AI

Johnson & Johnson MedTech • Raynham (MA)

On-site
USD 94,000 - 170,000
Travel up to 20% domestic
Professional, Compliance Lead
Professional, Compliance Lead

6090-Johnson & Johnson Services Inc. Legal Entity • New Brunswick (NJ)

On-site
USD 140,000 - 200,000