
Senior Manager, Medical Devices Product Security
Johnson & Johnson
full-time
Posted on:
Location Type: Hybrid
Location: Danvers • Massachusetts • New Jersey • United States
Visit company websiteExplore more
Salary
💰 $122,000 - $212,750 per year
Job Level
Tech Stack
About the role
- Implement J&J’s enterprise Product Security strategy and framework throughout the Heart Recovery portfolio of medical devices and supporting platforms.
- Provide technical expertise and strategic leadership in securing Impella heart pump technologies, next-generation cardiac support systems, and connected medical devices.
- Deliver security architecture, cryptographic controls, embedded system protections/controls, and threat mitigation techniques to ensure robust, regulatory-compliant security across the product lifecycle.
- Support heart recovery throughout a new product’s development phases.
- Review product security requirements and recommend security design solutions.
- Complete Quality documentation, threat modelling, coordinate third-party penetration testing, software architecture review and design recommendations, code analysis and other security testing work as needed.
- Monitor for new vulnerabilities, assist with patching and remediation plans, as well as respond to customer security questionnaires and review security language within contractual agreements as needed.
- Drive alignment to J&J Product Security’s overarching framework.
- Support the Product Security strategy and objectives within Heart Recovery.
- Define and implement secure boot, firmware integrity validation, and anti-tamper mechanisms to protect Heart Recovery Device firmware against unauthorized modification.
- Define and Enforce cryptographic protocols for data-at-rest and data-in-transit, ensuring compliance with FDA cybersecurity requirements, NIST 800-175, FIPS 140-3, and IEC 62443.
- Define and implement key management infrastructure (PKI, HSMs, TPMs, and secure enclave integration) for device identity, authentication, and software signing.
- Develop real-time vulnerability assessment techniques for detecting security flaws in wireless communications (Bluetooth LE, NFC, Wi-Fi, 5G, proprietary RF) used in Heart Recovery’s medical devices.
- Implement Zero Trust security for device-to-cloud connectivity, integrating mTLS and continuous authentication models into clinical applications.
- Oversee secure OTA (over-the-air) update mechanisms, ensuring firmware rollbacks, code signing, and supply chain integrity validation.
- Lead and ensure Secure Development Lifecycle practices are followed, integrating threat modeling, static/dynamic analysis, fuzz testing, and formal verification into the development process.
- Define and Influence R&D Engineering to define hardware security architecture, including trust zones, hardware root of trust (HRoT), and secure microcontroller protections.
- Implement memory safety strategies to mitigate buffer overflows, side-channel attacks, and execution vulnerabilities in real-time operating systems (RTOS) and bare-metal firmware.
- Respond to customer cybersecurity questionnaires and contractual language for post-market medical devices under your responsibility as necessary.
Requirements
- 10+ years industry experience in Information Security
- 5+ years experience with embedded system, IOT, or medical device cybersecurity
- Bachelor’s degree or equivalent
- Expertise generating Threat models without the use of threat modeling tools.
- Expertise performing risk assessments utilizing CVSS 3.1 or higher, with STRIDE per element.
- Experience writing technical security requirements for embedded systems and web platforms based on the latest regulations.
- Coordination and execution of third-party penetration testing, vulnerability scanning, CVSS and/or other general security testing principles.
- Experience supporting regulatory security submissions and generating Cybersecurity QMS documentation, ensuring compliance with FDA Cybersecurity Guidance (2025), EU MDR, NIST 800-53, IMDRF, and AAMI TIR57.
- Experience with real-time operating system hardening and pruning techniques and generating detailed SBOMs with software composition analysis.
- Experience with cloud security and controls and securely connecting embedded medical devices to the cloud.
- Experience generating detailed SBOMs from Software source code and Binaries, Firmware, and Operating Systems.
- Experience generating pre-market risk assessments against the threat model leveraging STRIDE and post-market risk assessments via SCA SBOM scans.
- Experience generating the security architecture views for medical devices that could include: Global System View, Multi-Patient Harm View, Updateability/Patchability view and, detailing system boundaries, data flows, and external interactions to show risk mitigation, ensuring transparency, and supporting post-market management.
- Experience translating technical security requirements into solutions.
- Ability to provide secure coding recommendations and experience executing code reviews.
- Data privacy experience, including HIPAA and GDPR.
- Understanding of industry standards and certifications such as HITRUST & ISO 27001, and IEC 81001-5-1.
- Ability to work autonomously and proactively seek out product security opportunities within heart recovery.
- Ability to lead large projects and proven ability to track to project plan timelines from a security perspective.
- Ability to create and deliver cybersecurity awareness campaigns and other communications.
- Creative problem-solving skills.
- Customer focus (internal & external).
- Excellent communication and collaboration skills, able to network, interface and influence at all levels of the organization, cross sector, cross-functionally and globally.
- Strong leadership skills.
Benefits
- medical
- dental
- vision
- life insurance
- short- and long-term disability
- business accident insurance
- group legal insurance
- consolidated retirement plan (pension)
- savings plan (401(k))
- Vacation –120 hours per calendar year
- Sick time - 40 hours per calendar year; for employees who reside in the State of Washington –56 hours per calendar year
- Holiday pay, including Floating Holidays –13 days per calendar year
- Work, Personal and Family Time - up to 40 hours per calendar year
- Parental Leave – 480 hours within one year of the birth/adoption/foster care of a child
- Condolence Leave – 30 days for an immediate family member: 5 days for an extended family member
- Caregiver Leave – 10 days
- Volunteer Leave – 4 days
- Military Spouse Time-Off – 80 hours
Applicant Tracking System Keywords
Tip: use these terms in your resume and cover letter to boost ATS matches.
Hard Skills & Tools
embedded system cybersecurityIOT securitymedical device cybersecuritythreat modelingrisk assessmentsCVSS 3.1vulnerability scanningsecure codingreal-time operating system hardeningcloud security
Soft Skills
leadershipcommunicationproblem-solvingcustomer focuscollaborationautonomyproactive approachproject managementinfluencecreativity
Certifications
Bachelor's degreeHITRUSTISO 27001IEC 81001-5-1