Senior Penetration Testing Program Lead (MedTech)

Antler Co

Town of Florida (NY)

On-site

USD 94,000 - 170,000

Full time

10 days ago
Application generator

Stand out for this role — generate a tailored resume and cover letter in about a minute.

Get past ATS filters

Job summary

The Professional, Program Lead, Penetration Testing Services is a seasoned individual contributor within the Cybersecurity function, Product Security sub-function, accountable for building and running the penetration testing and offensive security services program for the DePuy Synthes product portfolio.

This role establishes the testing methodology, scoping standards, and engagement model that embed Secure by Design verification into the product development lifecycle — spanning medical devices,

Qualifications

  • Minimum 6 years of progressive experience in penetration testing, offensive security, red teaming, or application security assessment.
  • Demonstrated experience leading or managing a penetration testing program, including methodology definition, scoping standards, and vendor oversight.
  • Hands-on proficiency across multiple domains: web application, API, mobile, network, wireless, and cloud penetration testing.
  • Working knowledge of common testing tools and frameworks (Burp Suite, Metasploit, Nmap, Wireshark, Ghidra/IDA, Kali) and scripting proficiency (Python, Bash, PowerShell).
  • Strong understanding of vulnerability classes and taxonomies (OWASP Top 10, CWE) and risk scoring methodologies (CVSS).
  • Experience embedding security testing into an SDLC and driving remediation with engineering teams through verified closure.
  • Excellent written and verbal communication skills, with proven ability to translate technical exploitation detail into business and patient safety risk for non-technical audiences.

Responsibilities

  • Own the end-to-end penetration testing services program for products and connected platforms, including the annual testing roadmap, prioritization model, and capacity planning across internal and external resources.
  • Define and maintain the penetration testing methodology, scoping standards, rules of engagement, and reporting templates aligned to industry frameworks (OWASP, PTES, NIST SP 800-115, MITRE ATT&CK).
  • Embed security testing gates into the product development lifecycle, ensuring Secure by Design verification occurs at defined design, integration, and pre-release milestones.
  • Execute and oversee hands-on assessments across medical devices, embedded firmware, wireless protocols, mobile applications, web applications, APIs, and cloud infrastructure.
  • Manage third-party penetration testing vendors — including scoping, statement of work development, quality review of deliverables, and performance management against SLAs.
  • Triage and validate findings, assess exploitability, and evaluate patient safety and clinical impact in partnership with Product Security, Quality, and Regulatory stakeholders.
  • Drive remediation with R&D and engineering teams, tracking findings through retest and verified closure, and escalating overdue or elevated risks through governance channels.
  • Conduct threat modeling and attack surface analysis to inform test scoping and identify high-value targets prior to engagement.
  • Support regulatory and customer requirements by producing testing evidence for FDA premarket submissions, EU MDR technical files, and hospital security assessments.
  • Contribute penetration testing results and residual risk analysis into product security risk files aligned to AAMI TIR57 and ISO 14971.
  • Build and report program metrics — test coverage across the portfolio, finding severity distribution, remediation aging, and retest pass rates — to leadership and product stakeholders.
  • Research emerging attack techniques, medical device vulnerabilities, and tooling; continuously evolve the testing capability and develop custom tooling and exploits where needed.
  • Assess the testing implications of platform migrations, supplier changes, and separation/carve-out activity affecting the product portfolio and supporting infrastructure.
  • Deliver technical enablement and secure development training to engineering teams, using real findings to strengthen security ownership and cyber culture.

Skills

Penetration testing
Offensive security
Vulnerability assessment
Scripting
Vendor management
Security testing methodologies

Education

Bachelor's degree in Computer Science or related
Advanced cybersecurity education

Tools

Burp Suite
Metasploit
Nmap
Wireshark
Ghidra/IDA
Kali

Job description

The Professional, Program Lead, Penetration Testing Services is a seasoned individual contributor within the Cybersecurity function, Product Security sub-function, accountable for building and running the penetration testing and offensive security services program for the DePuy Synthes product portfolio.

This role establishes the testing methodology, scoping standards, and engagement model that embed Secure by Design verification into the product development lifecycle — spanning medical devices,

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Senior PenTesting Program Lead
Senior PenTesting Program Lead

Antler Co • Warsaw (IN)

On-site
USD 94,000 - 170,000
Travel up to 10%
Senior Penetration Testing Program Lead, Medical Devices
Senior Penetration Testing Program Lead, Medical Devices

Antler Co • Raynham (MA)

On-site
USD 94,000 - 170,000
Penetration Testing Program Lead
Penetration Testing Program Lead

Johnson & Johnson MedTech • Warsaw (IN)

On-site
USD 94,000 - 170,000
Penetration Testing Program Lead — MedTech Security
Penetration Testing Program Lead — MedTech Security

Johnson & Johnson MedTech • Raynham (MA)

On-site
USD 94,000 - 170,000
Vacation time 120 hours/yr
Sick time 40 hours/yr
Parental Leave 480 hours/yr
Senior Penetration Testing Program Lead — MedTech Security
Senior Penetration Testing Program Lead — MedTech Security

Johnson & Johnson MedTech • Town of Florida (NY)

On-site
USD 94,000 - 170,000
Vacation time
Holiday pay
Parental Leave
+1
PenTesting Program Lead — Secure by Design
PenTesting Program Lead — Secure by Design

Antler Co • New Brunswick (NJ)

On-site
USD 94,000 - 170,000
PenTesting Program Lead — Secure by Design
PenTesting Program Lead — Secure by Design

Johnson & Johnson Innovative Medicine • Town of Florida (NY)

On-site
USD 94,000 - 170,000
Penetration Testing Program Lead
Penetration Testing Program Lead

Johnson & Johnson MedTech • New Brunswick (NJ)

On-site
USD 94,000 - 170,000
Program Lead, Penetration Testing — MedTech Security
Program Lead, Penetration Testing — MedTech Security

Johnson & Johnson MedTech • West Chester

On-site
USD 94,000 - 170,000
Product Security Engineer for Medical Devices
Product Security Engineer for Medical Devices

Johnson & Johnson MedTech • Town of Florida (NY)

On-site
USD 79,000 - 142,000