Manager, Application Security
Johnson & Johnson is recruiting for an Information Security & Risk Management (ISRM) Application Security Manager, located in Warsaw, Poland or Kraków, Poland. Caring for the world, one person at a time has inspired and united the people of Johnson & Johnson for over 130 years. We embrace research and science -- bringing innovative ideas, products, and services to advance the health and well-being of people. At Johnson & Johnson, we believe good health is the foundation of vibrant lives, thriving communities and forward progress. That’s why for more than 130 years, we have aimed to keep people well at every age and every stage of life. Today, as the world’s largest and most broadly-based healthcare company, we are committed to using our reach and size for good. We strive to improve access and affordability, create healthier communities, and put a healthy mind, body and environment within reach of everyone, everywhere. Every day, our more than 130,000 employees across the world are blending heart, science and ingenuity to profoundly change the trajectory of health for humanity. Thriving on a diverse company culture, celebrating the uniqueness of our employees and committed to equity. Proud to be an equal opportunity employer.
The Application Security Manager will be a member of a high-performing Information Security team which is responsible for Application Security strategy, technologies, and engineering. They will be responsible for implementing and maturing security capabilities related to modern software development, Artificial Intelligence, Citizen Development (Low Code / No Code), and applications built on SaaS (Software as a Service) and Cloud platforms.
The Application Security Manager will connect with Johnson & Johnson software development teams and technical business partners to shape practices related to DevSecOps, increase adoption of application security tooling, ensure timely remediation of risk, and provide subject matter expertise related to securing applications.
- Implement and mature Application Security capabilities (e.g., Citizen Development Security, SaaS Security, Artificial Intelligence Security, Cloud Security, etc.) with a focus on automation
- Product Ownership and SDLC adherence
- Provide guidance and consultancy for dev teams
- Drive increased adoption of application security capabilities
- Ensure timely remediation of risk
- Assess new patterns, methods and practices of software development as they arise for enterprise readiness and fitness for purpose
- Participate in business planning to ensure cybersecurity capabilities are appropriately considered and reflected in roadmap
- Connect with and report valuable metrics to senior leadership
- Timely reporting of security incidents or significant security problems to appropriate personnel
- Act as the main point of contact for security issues for their area of influence
- A Bachelor’s degree and a minimum of 6 years of progressive experience in the information security or information technology sector
- Proficiency in English language
- Experience with Product Ownership
- Experience with Cloud platforms (e.g., AWS, Azure, GCP, etc.)
- Knowledge of Artificial Intelligence Security
- Knowledge of securing Low Code / No Code Platforms
- Knowledge of common information security management frameworks such as NIST, OWASP, SANS, CIS
- Understanding of the software development process
- Comprehension of container orchestration methods and the opportunities to automate security practices within them
- Experience with API Security
- Superb communication and collaboration skills; able to network and influence various levels of the organization, cross sector, cross-functionally and globally
- Innovative thinking and leadership with an ability to lead and empower cross-functional, interdisciplinary teams
- Experience working in complex, fast-paced environments
- Ability to drive to short timelines
· Innate interest in people management, team building, and coaching
· Strong external networking experience
Johnson & Johnson is an Affirmative Action and Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, age, national origin, or protected veteran status and will not be discriminated against on the basis of disability.