Staff Product Security Engineer leading cybersecurity efforts for medical devices at Johnson & Johnson. Focus on threats, vulnerabilities, and security strategies within new product development.
Responsibilities
Identify threats and vulnerabilities to patient safety and product integrity, assess current security controls and determine potential impact of a threat and the risk level associated with threat/vulnerability pairs.
Drive architecture, requirements, and design to ensure that decisions incorporate security considerations.
Advise embedded system security software to ensure system hardening and secure coding practices.
Support all stakeholders on patch management, vulnerability handling, and SBOM scanning
Document designs and specifications per design control processes and conform to Industry Standards for Medical Device Software (IEC 62304)
Requirements
Bachelor’s degree in Computer Science, Computer Engineering, Cybersecurity or related degree
6+ years’ experience (or 4+ with M.S.) establishing security architecture or implementing security solutions in consumer products or medical devices
3+ experience in a software engineering or software architectural role in a New Product Development (NPD) environment
Proven experience with threat modeling and risk assessments for connected products or medical devices
Ability to work autonomously and proactively seek out security opportunities within the different surgical robotics teams
Ability to think big picture and have attention to detail – aligning strategic objectives with tactical implementation.
Proven experience with electrical and embedded software design
Experience developing software for embedded Real-Time Operating Systems (RTOS)
Experience developing embedded software systems using Modern C++ (preferably standards 17+)
A results and performance driven demeanor with strong sense of accountability
Understanding of penetration testing, vulnerability scanning, and/or other general security testing principles
Benefits
medical, dental, vision, life insurance
short- and long-term disability
business accident insurance
group legal insurance
consolidated retirement plan (pension)
savings plan (401(k))
long-term incentive program
vacation – up to 120 hours per calendar year
sick time - up to 40 hours per calendar year
holiday pay, including Floating Holidays – up to 13 days per calendar year
Work, Personal and Family Time - up to 40 hours per calendar year
Business Exp Plan & Admin Spec Sr. role at PNC executing growth strategies within physical security. Collaborating with teams for effective planning and reporting to meet business objectives.
Cyber Security Consultant managing governance, risk, and compliance for Var Group in Italy. Focusing on NIS2 and supporting clients on cyber security challenges across industries.
Consultant for cybersecurity and compliant software development supporting medical device manufacturers. Creating security documentation and facilitating workshops in a hybrid or remote setting.
IT - Systemadministrator managing network infrastructure and security solutions for MONTANA. Responsible for optimizing firewalls and coordinating IT projects with external partners in a growing energy company.
Senior IT - Security Manager responsible for IT security and compliance in Hamburg office. Overseeing development, implementation, and continuous improvement of information security management systems.
EHS&S Specialist managing compliance and data systems for global animal - health services. Ensuring EHS standards and documentation across North America locations with hybrid work model.
Senior Manager, IAM Control Assurance supporting identity and access management compliance within a global financial organization. Collaborating with cross - functional teams for regulatory and audit compliance.
Senior Security Engineer focusing on application security for Relativity software products. Collaborating with teams to implement security best practices and address security vulnerabilities.
Senior Security Analyst supporting Certification and Assurance at Mastercard. Managing certifications and conducting control testing against various security standards and frameworks.
Senior Information Security Engineer designing and maintaining security solutions for Utica National Insurance Group. Collaborating across teams to defend against cyber threats and ensure compliance.