Program Lead, Penetration Testing — MedTech Security

Johnson & Johnson MedTech

West Chester (Chester County)

On-site

USD 94,000 - 170,000

Full time

2 days ago
Be an early applicant
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Job summary

Johnson & Johnson is recruiting for a Professional, Program Lead, Penetration Testing Services located in New Brunswick, NJ or West Chester, PA or Palm Beach Gardens, FL or Warsaw, IN or Raynham, MA. The role leads the penetration testing program across medical devices, firmware, apps, APIs, and cloud services.

The position requires strong technical expertise, governance, and collaboration with R&D and engineering to remediate findings and ensure patient safety. Travel up to 10% may be required.

Qualifications

  • Minimum 6 years of progressive experience in penetration testing, offensive security, red teaming, or application security assessment.
  • Experience leading or managing a penetration testing program, including methodology definition, scoping standards, and vendor oversight.
  • Hands-on proficiency across web application, API, mobile, network, wireless, and cloud penetration testing.
  • Strong familiarity with testing tools and frameworks (Burp Suite, Metasploit, Nmap, Wireshark, Ghidra/IDA, Kali) and scripting (Python, Bash, PowerShell).
  • Understanding of vulnerability classes and risk scoring (OWASP Top 10, CWE, CVSS).
  • Experience embedding security testing into the SDLC and driving remediation with engineering teams.
  • Excellent written and verbal communication skills to translate technical findings into business risk.

Responsibilities

  • Own the end-to-end penetration testing services program, including roadmap, prioritization, and capacity planning.
  • Define and maintain testing methodology, scoping standards, rules of engagement, and reporting templates.
  • Embed security testing gates into the product development lifecycle across devices, firmware, apps, APIs, and cloud.
  • Execute and oversee assessments across medical devices, firmware, wireless protocols, mobile and web apps, and cloud infra.
  • Manage third-party penetration testing vendors, including SOWs, quality reviews, and performance against SLAs.
  • Triage findings, assess exploitability, and evaluate safety and clinical impact with cross-functional teams.
  • Drive remediation with R&D and engineering, track through retest and closure, escalate risks as needed.
  • Conduct threat modeling and attack surface analysis to inform test scoping.
  • Support regulatory and customer requirements with testing evidence for FDA/EU MDR submissions.
  • Contribute results and risk analysis to product security risk files per industry standards.
  • Build program metrics and communicate findings to leadership and stakeholders.
  • Research emerging attack techniques and tooling; evolve testing capabilities and tooling.
  • Assess testing implications of platform migrations, supplier changes, and carve-out activities.

Skills

Burp Suite
Metasploit
Nmap
Wireshark
Ghidra/IDA
Kali
Python
Bash
PowerShell
CVSS

Education

Bachelor's degree in Computer Science, Cybersecurity, Software/Electrical/ Biomedical Engineering, Information Systems, or a related technical discipline
Advanced degree or specialized cybersecurity education

Tools

OWASP
PTES
NIST SP 800-115
MITRE ATT&CK

Job description

Johnson & Johnson is recruiting for a Professional, Program Lead, Penetration Testing Services located in New Brunswick, NJ or West Chester, PA or Palm Beach Gardens, FL or Warsaw, IN or Raynham, MA. The role leads the penetration testing program across medical devices, firmware, apps, APIs, and cloud services.

The position requires strong technical expertise, governance, and collaboration with R&D and engineering to remediate findings and ensure patient safety. Travel up to 10% may be required.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Penetration Testing Program Lead
Penetration Testing Program Lead

Johnson & Johnson MedTech • New Brunswick (NJ)

On-site
USD 94,000 - 170,000
Senior Penetration Testing Program Lead — MedTech Security
Senior Penetration Testing Program Lead — MedTech Security

Johnson & Johnson MedTech • Town of Florida (NY)

On-site
USD 94,000 - 170,000
Vacation time
Holiday pay
Parental Leave
+1
Penetration Testing Program Lead — MedTech Security
Penetration Testing Program Lead — MedTech Security

Johnson & Johnson MedTech • Raynham (MA)

On-site
USD 94,000 - 170,000
Vacation time 120 hours/yr
Sick time 40 hours/yr
Parental Leave 480 hours/yr
PenTesting Program Lead — Secure by Design
PenTesting Program Lead — Secure by Design

Johnson & Johnson Innovative Medicine • Town of Florida (NY)

On-site
USD 94,000 - 170,000
Senior Penetration Testing Program Lead, Medical Devices
Senior Penetration Testing Program Lead, Medical Devices

Antler Co • Raynham (MA)

On-site
USD 94,000 - 170,000
Penetration Testing Program Lead
Penetration Testing Program Lead

Johnson & Johnson MedTech • Warsaw (IN)

On-site
USD 94,000 - 170,000
PenTesting Program Lead — Secure by Design
PenTesting Program Lead — Secure by Design

Antler Co • New Brunswick (NJ)

On-site
USD 94,000 - 170,000
Senior PenTesting Program Lead
Senior PenTesting Program Lead

Antler Co • Warsaw (IN)

On-site
USD 94,000 - 170,000
Travel up to 10%
Product Security Engineer – MedTech & Digital Health
Product Security Engineer – MedTech & Digital Health

Antler Co • Raynham (MA)

On-site
USD 79,000 - 142,000
Product Security Analyst & Engineer (MedTech)
Product Security Analyst & Engineer (MedTech)

Johnson & Johnson MedTech • Raynham (MA)

On-site
USD 90,000 - 130,000