Product Security Manager
Johnson & JohnsonAbout the role
At Johnson & Johnson, we believe health is everything. Our strength in healthcare innovation empowers us to build a world where complex diseases are prevented, treated, and cured, where treatments are smarter and less invasive, and solutions are personal. Through our expertise in Innovative Medicine and MedTech, we are uniquely positioned to innovate across the full spectrum of healthcare solutions today to deliver the breakthroughs of tomorrow, and profoundly impact health for humanity. Learn more at jnj.com
As guided by Our Credo, Johnson & Johnson is responsible to our employees who work with us throughout the world. We provide an inclusive work environment where each person is considered as an individual. At Johnson & Johnson, we respect the diversity and dignity of our employees and recognize their merit.
Job Function:
Technology Enterprise Strategy & SecurityJob Sub Function:
Solution ArchitectureJob Category:
Scientific/TechnologyAll Job Posting Locations:
Alabama (Any City), Alabama (Any City), Arizona (Any City), Arkansas (Any City), California (Any City), Colorado (Any City), Connecticut (Any City), Delaware (Any City), Florida (Any City), Georgia (Any City), Idaho (Any City), Illinois (Any City), Indiana (Any City), Iowa (Any City), Irvine, California, United States of America, Kansas (Any City), Kentucky (Any City), Louisiana (Any City), Maine (Any City), Maryland (Any City), Massachusetts (Any City), Michigan (Any City), Milpitas, California, United States of America, Minnesota (Any City), Mississippi (Any City) {+ 25 more}Job Description:
We are seeking the best talent for a Product Security Manager to join our MedTech Product Security team. The role is based in Milpitas or Irvine, CA. Remote work options may be considered on a case-by-case basis and if approved by the Company. This may require up to 10% travel.
The Product Security Manager will be responsible for implementation of J&J’s enterprise Product Security strategy and framework throughout Johnson & Johnson Vision (JJV) medical device portfolio. This includes identifying key strategy and goals, collaborating with internal organizations on existing process and policy enhancements, creating and communicating metrics to management, identifying communications plans and raising overall awareness of the capability.
Specific responsibilities include:
- Supporting JJV throughout a new product’s development phases
- Review product security requirements and recommend security design solutions
- Help complete Quality documentation, threat modelling, penetration testing, software architecture review and design recommendations, code analysis and other security testing or work as needed.
- Post market responsibilities for JJV marketed devices include monitoring for new vulnerabilities, assisting with patching and remediation plans, as well as responding to all customer security questionnaires and reviewing security language within contractual agreements.
- Drive adherence to J&J Product Security’s overarching framework:
- Champion Product Security strategy and objectives within JJV
- Partner with internal organizations to enhance existing processes and policies
- Create and present Product Security metrics to management
- Responsible and accountable to implement and enforce Product Security governance model for JJV pre and post market medical devices.
- Perform automated code scanning and coordinate formal security testing.
- Respond to customer cybersecurity questionnaires and contractual language for all post-market medical devices.
- Other MedTech cybersecurity related duties as needed
Qualifications
Required:
- 8 years IT or cybersecurity experience
- Bachelor’s degree or equivalent
- A minimum of 8 years of progressive experience in leadership roles within information technology or cybersecurity functions
- Threat modeling experience
- Data privacy experience, including GDPR and CCPA
- Understanding of HIPAA/HITRUST & ISO 27001
- Understanding of penetration testing, vulnerability scanning, CVSS and/or other general security testing principles
- Ability to work autonomously and proactively seek out security opportunities within JJV
- Knowledge of traditional and real-time operating systems (i.e. QNX, Windows Embedded) hardening techniques
- Ability to create and deliver cybersecurity awareness campaigns and other communications
- Ability to translate t
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s