Principal Med Device Security Engineer at Johnson & Johnson Innovative Medicine | AK, US | Rezi

Principal Med Device Security Engineer at Johnson & Johnson Innovative Medicine

Principal Med Device Security Engineer

Johnson & Johnson Innovative Medicine · AK, US

1 weeks ago

Principal Med Device Security Engineer

Johnson & Johnson Innovative Medicine · AK, US

8 days ago
Resume preview

Impress employers and recruiters.
Choose from hundreds of resume examples.

Target Resume Now
Resume preview

Tailor your resume to this Principal Med Device Security Engineer role.

Rezi rewrites your resume against Johnson & Johnson Innovative Medicine's job description. Free.

Resume score gauge reading 58 out of 100

Don't guess if your resume is good enough.

See how it scores against the Principal Med Device Security Engineer posting at Johnson & Johnson Innovative Medicine — free, in seconds.

About the Role

Johnson & Johnson's MedTech cybersecurity team is seeking an experienced Principal Product Security Engineer to ensure security is implemented by design for medical devices. This role will impact development initiatives, shape future product development and industry standards, and own the Product Security process throughout the product development lifecycle. You will leverage your security risk and compliance skills to directly impact patient lives.

Responsibilities

  • Implement J&J’s enterprise Product Security strategy and framework throughout the Heart Recovery portfolio of medical devices and supporting platforms.
  • Provide technical expertise and strategic leadership in securing Impella heart pump technologies, next-generation cardiac support systems, and connected medical devices.
  • Deliver security architecture, cryptographic controls, embedded system protections/controls, and threat mitigation techniques.
  • Support heart recovery throughout new product development phases.
  • Review product security requirements and recommend security design solutions.
  • Complete Quality documentation, threat modeling, and coordinate third-party penetration testing.
  • Perform software architecture review and design recommendations, code analysis, and other security testing.
  • Monitor for new vulnerabilities in marketed devices.
  • Assist with patching and remediation plans for marketed devices.
  • Respond to customer security questionnaires and review security language within contractual agreements.
  • Drive alignment to J&J Product Security’s overarching framework.
  • Support the Product Security strategy and objectives within Heart Recovery.
  • Define and implement secure boot, firmware integrity validation, and anti-tamper mechanisms.
  • Enforce cryptographic protocols for data-at-rest and data-in-transit, ensuring compliance with FDA cybersecurity requirements, NIST 800-175, FIPS 140-3, and IEC 62443.
  • Define and implement key management infrastructure (PKI, HSMs, TPMs, and secure enclave integration).
  • Develop real-time vulnerability assessment techniques for detecting security flaws in wireless communications.
  • Implement Zero Trust security for device-to-cloud connectivity.
  • Oversee secure OTA (over-the-air) update mechanisms.
  • Lead Secure Development Lifecycle practices, integrating threat modeling, static/dynamic analysis, fuzz testing, and formal verification.
  • Work with R&D Engineering to define hardware security architecture.
  • Implement memory safety strategies to mitigate vulnerabilities.
  • Respond to customer cybersecurity questionnaires and contractual language for post-market medical devices.
  • Create and deliver cybersecurity awareness campaigns and other communications.

Requirements

  • 10+ years industry experience in Information Security
  • 8+ years experience with embedded system, IOT, or medical device cybersecurity
  • Bachelor’s degree or equivalent
  • Experience generating Threat models without the use of threat modeling tools
  • Experience performing risk assessments utilizing CVSS 3.1 or higher, with STRIDE per element
  • Ability to write technical security requirements for embedded systems and web platforms based on the latest regulations
  • Understanding and execution of third-party penetration testing, vulnerability scanning, CVSS and/or other general security testing principles
  • Experience supporting regulatory security submissions, ensuring compliance with FDA Cybersecurity Guidance (2025), EU MDR, NIST 800-53, IMDRF, and AAMI TIR57
  • Knowledge of real-time operating systems hardening techniques
  • Knowledge of cloud security principles
  • Ability to generate SBOMs from Software source code and Binaries, Firmware, and Operating Systems
  • Ability to generate pre-market risk assessments against the threat model leveraging STRIDE and post-market risk assessments via SCA SBOM scans.
  • Ability to generate the security architecture views for medical devices
  • Ability to translate technical security requirements into solutions
  • Ability to provide secure coding recommendations and execute reviews
  • Data privacy experience, including HIPAA and GDPR
  • Understanding of industry standards and certifications such as HITRUST & ISO 27001
  • Ability to work autonomously and proactively seek out product security opportunities within heart recovery
  • Ability to lead large projects and proven ability to track to project plan timelines from a security perspective
  • Creative problem-solving skills
  • Customer focus (internal & external)
  • Excellent communication and collaboration skills, able to network, interface and influence at all levels of the organization, cross sector, cross-functionally and globally
  • Strong leadership skills

Skills

  • Product Security
  • Cybersecurity
  • Risk Assessment
  • Compliance
  • Threat Modeling
  • CVSS 3.1
  • STRIDE
  • Embedded Systems Security
  • Medical Device Cybersecurity
  • FDA Cybersecurity Guidance
  • NIST 800-53
  • IMDRF
  • AAMI TIR57
  • Real-time Operating Systems Hardening
  • Cloud Security
  • SBOM Generation
  • Security Architecture
  • Secure Coding
  • HIPAA
  • GDPR
  • HITRUST
  • ISO 27001
  • QNX QOS
  • Yocto
  • Linux Ubuntu
  • Alpine
  • AWS
  • Azure
  • OWASP Top 10
  • CISSP
  • CISM

Location

  • Danvers, Massachusetts, United States of America

Work Type

  • Remote
  • Hybrid
  • Onsite

Experience Level

  • Principal
  • 10+ years industry experience
  • 8+ years experience with embedded system, IOT, or medical device cybersecurity

Education Level

  • Bachelor’s degree or equivalent
  • MS and/or advanced degree

Salary/Compensations

  • $102,000.00 - $177,100.00

Benefits

  • Company's consolidated retirement plan (pension) and savings plan (401(k))
  • Vacation –120 hours per calendar year
  • Sick time - 40 hours per calendar year (varies by state)
  • Holiday pay, including Floating Holidays –13 days per calendar year
  • Work, Personal and Family Time - up to 40 hours per calendar year
  • Parental Leave – 480 hours within one year of the birth/adoption/foster care of a child
  • Bereavement Leave – 240 hours for an immediate family member: 40 hours for an extended family member per calendar year
  • Caregiver Leave – 80 hours in a 52-week rolling period
  • Volunteer Leave – 32 hours per calendar year
  • Military Spouse Time-Off – 80 hours per calendar year

About the Company

  • At Johnson & Johnson, we believe health is everything. Our strength in healthcare innovation empowers us to build a world where complex diseases are preventable, treatable, and curable, where treatments are smarter and less invasive, and solutions are personal. Through our expertise in Innovative Medicine and MedTech, we are uniquely positioned to innovate across the full spectrum of healthcare solutions today to deliver the breakthroughs of tomorrow, and profoundly impact health for humanity.
  • Learn more at jnj.com
  • As guided by Our Credo, Johnson & Johnson is responsible to our employees who work with us throughout the world. We provide an inclusive work environment where each person is considered as an individual. At Johnson & Johnson, we respect the diversity and dignity of our employees and recognize their merit.

Equal Opportunity

  • Johnson & Johnson is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, age, national origin, disability, protected veteran status or other characteristics protected by federal, state or local law.
  • We actively seek qualified candidates who are protected veterans and individuals with disabilities as defined under VEVRAA and Section 503 of the Rehabilitation Act.
  • Johnson & Johnson is committed to providing an interview process that is inclusive of our applicants’ needs. If you are an individual with a disability and would like to request an accommodation, please contact us via https://www.jnj.com/contact-us/careers or contact AskGS to be directed to your accommodation resource.