Description
Johnson & Johnson is recruiting for a Principal Product Security Engineer to be located in Danvers, MA. Remote work options may be considered on a case-by-case basis and if approved by the Company.
At Johnson & Johnson, we believe health is everything. Our strength in healthcare innovation empowers us to build a world where complex diseases are prevented, treated, and cured, where treatments are smarter and less invasive, and solutions are personal. Through our expertise in Innovative Medicine and MedTech, we are uniquely positioned to innovate across the full spectrum of healthcare solutions today to deliver the breakthroughs of tomorrow, and profoundly impact health for humanity. Learn more at https://www.jnj.com/.
For more than 130 years, diversity, equity & inclusion (DEI) has been a part of our cultural fabric at Johnson & Johnson and woven into how we do business every day. Rooted in Our Credo, the values of DEI fuel our pursuit to create a healthier, more equitable world. Our diverse workforce and culture of belonging accelerate innovation to solve the world’s most pressing healthcare challenges.
We know that the success of our business – and our ability to deliver meaningful solutions – depends on how well we understand and meet the diverse needs of the communities we serve. Which is why we foster a culture of inclusion and belonging where all perspectives, abilities and experiences are valued and our people can reach their potential.
At Johnson & Johnson, we all belong.
Are you passionate about security and interested in joining a community of collaborative colleagues working in a Patient First! culture? If that’s you, we have an immediate opportunity for a Principal Product Security Engineer to join the newly formed Product Security team to help ensure security is implemented by design for this top-performing medical device company. This is an exciting opportunity to impact development initiatives that will shape future product development and industry standards. You will own the Product Security process that includes both pre-market and post-market processes engineering teams leverage throughout the product development lifecycle. If you are eager to leverage your security risk and compliance skills to make a difference and directly impact patient lives, this could be perfect for you.
Primary Duties and Responsibilities
- Being at the office in Danvers MA for a minimum of 3 days per week (for candidates within commutable distance to site).
- Partner with engineering teams (cloud, console, pump, etc.) to drive successful adherence to Abiomed’s product security policies, processes, program objectives.
- Create, update, and improve product security processes.
- Act as a SME on cyber security matters and provide guidance to development teams.
- Advocate for proactive inclusion of cyber security input into all phases of the product life cycle, process improvements, CAPAs, strategic product road map planning.
- Deliver documentation for pre-market product development activities including security plans, architecture diagrams, data flow diagrams, threat models, security requirements, Design for Security, SBOM, and risk management documentation.
- Drive and monitor and post-market vulnerability management activities, with adherence to strict timelines.
- Support compliance certification activities, such as SOC2, FedRAMP, ISO 27001, etc.
- Identify, research, evaluate, and integrate new compliance requirements, industry standards, and best practices into the product security programs.
- Maintain relationships with Abiomed’s Information Sharing and Analysis Organizations.
- Guide teams to make decisions that balance business needs with medical device security objectives.
- Work across organizational boundaries and exhibit empathy with customers, both internal and external.
- Perform other related duties and responsibilities, as assigned.
Qualifications
Required:
- Bachelor’s degree
- 5+ years industry experience in Information Security.
- Working knowledge of regulatory standards and compliance frameworks (e.g., NIST Cybersecurity Framework, ISO27001, SOC2, HIPAA, GDPR).
- Experience with security risk management techniques.
- Demonstrated organizational skills, attention to detail, the ability to handle multiple assignments simultaneously in a timely manner and be able to meet assigned deadlines.
- Committed to working with a sense of urgency and embracing new challenges.
- Strong communication and interpersonal skills.
Preferred:
- Experience working in a regulated environment, FDA-regulated
The anticipated base pay range for this position is $99,000- $170,200.
The Company maintains highly competitive, performance-based compensation programs. Under current guidelines, this position is eligible for an annual performance bonus in accordance with the terms of the applicable plan. The annual performance bonus is a cash bonus intended to provide an incentive to achieve annual targeted results by rewarding for individual and the corporation’s performance over a calendar/performance year. Bonuses are awarded at the Company’s discretion on an individual basis.
- Employees and/or eligible dependents may be eligible to participate in the following Company sponsored employee benefit programs: medical, dental, vision, life insurance, short- and long-term disability, business accident insurance, and group legal insurance.
- Employees may be eligible to participate in the Company’s consolidated retirement plan (pension) and savings plan (401(k)).
- Employees are eligible for the following time off benefits:
- Vacation – up to 120 hours per calendar year
- Sick time - up to 40 hours per calendar year; for employees who reside in the State of Washington – up to 56 hours per calendar year
- Holiday pay, including Floating Holidays – up to 13 days per calendar year of Work, Personal and Family Time - up to 40 hours per calendar year
- Additional information can be found through the link below. https://www.careers.jnj.com/employee-benefits
Johnson & Johnson is an Affirmative Action and Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, age, national origin, or protected veteran status and will not be discriminated against on the basis of disability.
For more information on how we support the whole health of our employees throughout their wellness, career and life journey, please visit www.careers.jnj.com.