Johnson & Johnson

Senior Manager, Medical Devices Product Security

Johnson & Johnson

full-time

Posted on:

Location Type: Hybrid

Location: DanversMassachusettsNew JerseyUnited States

Visit company website

Explore more

AI Apply
Apply

Salary

💰 $122,000 - $212,750 per year

Job Level

About the role

  • Implement J&J’s enterprise Product Security strategy and framework throughout the Heart Recovery portfolio of medical devices and supporting platforms.
  • Provide technical expertise and strategic leadership in securing Impella heart pump technologies, next-generation cardiac support systems, and connected medical devices.
  • Deliver security architecture, cryptographic controls, embedded system protections/controls, and threat mitigation techniques to ensure robust, regulatory-compliant security across the product lifecycle.
  • Support heart recovery throughout a new product’s development phases.
  • Review product security requirements and recommend security design solutions.
  • Complete Quality documentation, threat modelling, coordinate third-party penetration testing, software architecture review and design recommendations, code analysis and other security testing work as needed.
  • Monitor for new vulnerabilities, assist with patching and remediation plans, as well as respond to customer security questionnaires and review security language within contractual agreements as needed.
  • Drive alignment to J&J Product Security’s overarching framework.
  • Support the Product Security strategy and objectives within Heart Recovery.
  • Define and implement secure boot, firmware integrity validation, and anti-tamper mechanisms to protect Heart Recovery Device firmware against unauthorized modification.
  • Define and Enforce cryptographic protocols for data-at-rest and data-in-transit, ensuring compliance with FDA cybersecurity requirements, NIST 800-175, FIPS 140-3, and IEC 62443.
  • Define and implement key management infrastructure (PKI, HSMs, TPMs, and secure enclave integration) for device identity, authentication, and software signing.
  • Develop real-time vulnerability assessment techniques for detecting security flaws in wireless communications (Bluetooth LE, NFC, Wi-Fi, 5G, proprietary RF) used in Heart Recovery’s medical devices.
  • Implement Zero Trust security for device-to-cloud connectivity, integrating mTLS and continuous authentication models into clinical applications.
  • Oversee secure OTA (over-the-air) update mechanisms, ensuring firmware rollbacks, code signing, and supply chain integrity validation.
  • Lead and ensure Secure Development Lifecycle practices are followed, integrating threat modeling, static/dynamic analysis, fuzz testing, and formal verification into the development process.
  • Define and Influence R&D Engineering to define hardware security architecture, including trust zones, hardware root of trust (HRoT), and secure microcontroller protections.
  • Implement memory safety strategies to mitigate buffer overflows, side-channel attacks, and execution vulnerabilities in real-time operating systems (RTOS) and bare-metal firmware.
  • Respond to customer cybersecurity questionnaires and contractual language for post-market medical devices under your responsibility as necessary.

Requirements

  • 10+ years industry experience in Information Security
  • 5+ years experience with embedded system, IOT, or medical device cybersecurity
  • Bachelor’s degree or equivalent
  • Expertise generating Threat models without the use of threat modeling tools.
  • Expertise performing risk assessments utilizing CVSS 3.1 or higher, with STRIDE per element.
  • Experience writing technical security requirements for embedded systems and web platforms based on the latest regulations.
  • Coordination and execution of third-party penetration testing, vulnerability scanning, CVSS and/or other general security testing principles.
  • Experience supporting regulatory security submissions and generating Cybersecurity QMS documentation, ensuring compliance with FDA Cybersecurity Guidance (2025), EU MDR, NIST 800-53, IMDRF, and AAMI TIR57.
  • Experience with real-time operating system hardening and pruning techniques and generating detailed SBOMs with software composition analysis.
  • Experience with cloud security and controls and securely connecting embedded medical devices to the cloud.
  • Experience generating detailed SBOMs from Software source code and Binaries, Firmware, and Operating Systems.
  • Experience generating pre-market risk assessments against the threat model leveraging STRIDE and post-market risk assessments via SCA SBOM scans.
  • Experience generating the security architecture views for medical devices that could include: Global System View, Multi-Patient Harm View, Updateability/Patchability view and, detailing system boundaries, data flows, and external interactions to show risk mitigation, ensuring transparency, and supporting post-market management.
  • Experience translating technical security requirements into solutions.
  • Ability to provide secure coding recommendations and experience executing code reviews.
  • Data privacy experience, including HIPAA and GDPR.
  • Understanding of industry standards and certifications such as HITRUST & ISO 27001, and IEC 81001-5-1.
  • Ability to work autonomously and proactively seek out product security opportunities within heart recovery.
  • Ability to lead large projects and proven ability to track to project plan timelines from a security perspective.
  • Ability to create and deliver cybersecurity awareness campaigns and other communications.
  • Creative problem-solving skills.
  • Customer focus (internal & external).
  • Excellent communication and collaboration skills, able to network, interface and influence at all levels of the organization, cross sector, cross-functionally and globally.
  • Strong leadership skills.
Benefits
  • medical
  • dental
  • vision
  • life insurance
  • short- and long-term disability
  • business accident insurance
  • group legal insurance
  • consolidated retirement plan (pension)
  • savings plan (401(k))
  • Vacation –120 hours per calendar year
  • Sick time - 40 hours per calendar year; for employees who reside in the State of Washington –56 hours per calendar year
  • Holiday pay, including Floating Holidays –13 days per calendar year
  • Work, Personal and Family Time - up to 40 hours per calendar year
  • Parental Leave – 480 hours within one year of the birth/adoption/foster care of a child
  • Condolence Leave – 30 days for an immediate family member: 5 days for an extended family member
  • Caregiver Leave – 10 days
  • Volunteer Leave – 4 days
  • Military Spouse Time-Off – 80 hours
Applicant Tracking System Keywords

Tip: use these terms in your resume and cover letter to boost ATS matches.

Hard Skills & Tools
embedded system cybersecurityIOT securitymedical device cybersecuritythreat modelingrisk assessmentsCVSS 3.1vulnerability scanningsecure codingreal-time operating system hardeningcloud security
Soft Skills
leadershipcommunicationproblem-solvingcustomer focuscollaborationautonomyproactive approachproject managementinfluencecreativity
Certifications
Bachelor's degreeHITRUSTISO 27001IEC 81001-5-1