Unknown Company

Principal Med Device Security Engineer

garden city, sc • Posted 4 days ago
Remote Contract IT & Technology

Johnson & Johnson’s MedTech cybersecurity team is recruiting for an experienced Principal Product Security Engineer. The role can be remote-based or located onsite in Danvers, MA or Raritan, NJ, and will require up to 10% travel.

Responsibilities

The Principal Product Security Engineer will implement J&J’s enterprise Product Security strategy and framework across the Heart Recovery portfolio, providing technical expertise and strategic leadership in securing Impella heart pump technologies and related medical devices.

  • Drive alignment to J&J Product Security’s overarching framework.
  • Support the Product Security strategy and objectives within Heart Recovery.
  • Define and implement secure boot, firmware integrity validation, and anti-tamper mechanisms for device firmware.
  • Enforce cryptographic protocols for data-at-rest and data-in-transit, ensuring compliance with FDA cybersecurity requirements, NIST 800-175, FIPS 140-3, and IEC 62443.
  • Define and implement key management infrastructure (PKI, HSMs, TPMs, and secure enclave integration) for device identity, authentication, and software signing.
  • Develop real-time vulnerability assessment techniques for detecting security flaws in wireless communications (Bluetooth LE, NFC, Wi‑Fi, 5G, proprietary RF).
  • Implement Zero Trust security for device-to-cloud connectivity, integrating mTLS and continuous authentication models.
  • Oversee secure OTA update mechanisms, ensuring firmware rollbacks, code signing, and supply chain integrity validation.
  • Lead Secure Development Lifecycle practices, integrating threat modeling, static/dynamic analysis, fuzz testing, and formal verification.
  • Work with R&D Engineering to define hardware security architecture, including trust zones and hardware root of trust.
  • Implement memory safety strategies to mitigate buffer overflows, side‑channel attacks, and execution vulnerabilities in real‑time operating systems and bare‑metal firmware.
  • Respond to customer cybersecurity questionnaires and contractual language for post‑market medical devices.

Qualifications

Key requirements for this role include:

  • 8+ years of industry experience in Information Security.
  • 5+ years with embedded systems, IoT, or medical device cybersecurity.
  • Bachelor’s degree or equivalent.
  • Experience generating threat models without tools.
  • Experience performing risk assessments using CVSS 3.1 or higher and STRIDE methodology.
  • Ability to write technical security requirements for embedded systems and web platforms.
  • Understanding of third‑party penetration testing, vulnerability scanning, and security testing principles.
  • Experience supporting regulatory security submissions (FDA Guidance 2025, EU MDR, NIST 800‑53, IMDRF, AAMI TIR57).
  • Knowledge of real‑time operating system hardening techniques and cloud security principles.
  • Ability to generate SBOMs from software, firmware, and operating systems.
  • Ability to conduct pre‑market and post‑market risk assessments using STRIDE and SCA SBOM scans.
  • Ability to create security architecture views for medical devices.
  • Strong secure coding and review skills.
  • Data privacy experience (HIPAA, GDPR).
  • Understanding of industry standards and certifications such as HITRUST and ISO 27001.
  • Strong project leadership and ability to track timelines.
  • Excellent communication, collaboration, and leadership skills.
  • Creative problem‑solving and customer focus.

Preferred Qualifications

  • Experience leading or participating in formal security audits.
  • Experience with QNX, QOS, Yocto, Linux Ubuntu, and Alpine.
  • Familiarity with FDA and other global cybersecurity guidance and submission processes.
  • Experience with web application and server hardening (AWS, Azure) and OWASP Top 10.
  • Experience in cybersecurity pre‑sales.
  • Software development experience.
  • Certifications such as CISSP or CISM.
  • MS or advanced degree.

Benefits

  • Vacation – 120 hours per calendar year.
  • Sick time – 40 hours per calendar year (48 in Colorado, 56 in Washington).
  • Holiday pay, including floating holidays – 13 days per calendar year.
  • Work, personal, and family time – up to 40 hours per calendar year.
  • Parental leave – 480 hours within one year of birth/adoption/foster care.
  • Bereavement leave – 240 hours for immediate family; 40 hours for extended family.
  • Caregiver leave – 80 hours in a 52‑week rolling period.
  • Volunteer leave – 32 hours per calendar year.
  • Military spouse time‑off – 80 hours per calendar year.

Pay

$102,000.00 – $177,100.00

EEO Statement

Johnson & Johnson is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, age, national origin, disability, protected veteran status, or other characteristics protected by federal, state or local law. We actively seek qualified candidates who are protected veterans and individuals with disabilities as defined under VEVRAA and Section 503 of the Rehabilitation Act. If you are an individual with a disability and would like to request an accommodation, please contact us at or ask GS to be directed to your accommodation resource.

#J-18808-Ljbffr
Back to Job Search