Jobs and Careers
JO

Senior Product Security Program Manager

Johnson & Johnson
Santa Clara, United Statesfull_timeVerifiedPosted 8 Jul 2025
💰 $238,000/yr($120,000/yr$238,000/yr)

About the role

At Johnson & Johnson, we believe health is everything. Our strength in healthcare innovation empowers us to build a world where complex diseases are prevented, treated, and cured, where treatments are smarter and less invasive, and solutions are personal. Through our expertise in Innovative Medicine and MedTech, we are uniquely positioned to innovate across the full spectrum of healthcare solutions today to deliver the breakthroughs of tomorrow, and profoundly impact health for humanity. Learn more at https://www.jnj.com

Job Function:

Technology Enterprise Strategy & Security

Job Sub Function:

Solution Architecture

Job Category:

Scientific/Technology

All Job Posting Locations:

Cincinnati, Ohio, United States of America, Danvers, Massachusetts, United States of America, Irvine, California, United States of America, Raritan, New Jersey, United States of America, Santa Clara, California, United States of America

Job Description:

We are seeking the best talent for a Senior Product Security Program Manager to join our MedTech Product Security team. The role can be based in Santa Clara or Irvine, CA; Cincinnati, OH; Raritan, NJ; Danvers, MA. Remote work options may be considered on a case-by-case basis and if approved by the Company. This role may require up to 20% travel.

The Senior Product Security Program Manager for Surgery R&D Robotics platforms is responsible for developing and leading the implementation strategy of the global J&J ISRM cybersecurity standards. As the subject matter expert for cybersecurity, you will provide leadership oversight and guide large project teams throughout new product’s development phases, review of product security requirements and recommendations of security design solutions, ensure the team completes Quality documentation, threat modelling, penetration testing, software architecture review and design recommendations, code analysis and other security testing or work as needed.

Additionally, this role will lead teams which are responsible for the multiple surgical robotics post market device activities to include: monitoring of new vulnerabilities, ensuring the product security teams are assisting with patching and remediation plans, as well as responding to all customer security questionnaires and reviewing security language within contractual agreements.

Key Responsibilities:

  • Advise and inform R&D stakeholders on cybersecurity standards and best practices
  • Support and advise senior management, product management, project management and R&D leaders on cybersecurity related activities and issues
  • Continuously review, refine, and review all relevant R&D cybersecurity processes to adapt enterprise requirements
  • Assist project teams in the creation of Cyber Security Plans – including overall security design control requirements, patch management strategy and implementation roadmap.
  • Ensure project teams consider industry standards for system hardening and secure coding
  • Conduct threat modeling (e.g. STRIDE, Attack Trees) and risk assessment workshops
  • Define security rule sets and support their implementation in static and dynamic code analyses tools
  • Guide and train project teams to ensure direct and indirect security requirements are understood and implemented
  • Train and support project teams on definition, execution, and documentation of penetration tests
  • Set up and manage an effective vulnerability screening process across products within the BU
  • Implement and manage supply chain security through Software Bill-of-Materials (SBOM)
  • Support all stakeholders on patch management / vulnerability handling
  • Management of cybersecurity findings (internal & external), regular reporting of incidents and metrics (NIST, CVSS Scoring)
  • Triggering, supporting and leading the incident management process
  • Keeps abreast of information security and business trends in the industry through benchmarking and/or participation in professional association
  • Other MedTech cybersecurity related duties as needed

Qualifications:

Required:

  • BS/MS degree in STEM (science, technology, engineering, mathematics) or equivalent.
  • 10+ years of progressive IT or Cybersecurity responsibilities
  • Collaborative and able to effectively interact and communicate with peers, management, and leadership teams on various technical levels
  • Proficiency in performing risk and impact assessments and determining treatment strategies
  • Familiar with threat modeling, penetration testing, stress testing and vulne

Apply for this role

Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.

Apply Now →Generate Application Kit

Free account required — sign up in 30s

Company

Johnson & Johnson

View company profile →