Johnson & Johnson Logo

Johnson & Johnson

Product Security Manager

Posted 4 Days Ago
Be an Early Applicant
In-Office or Remote
3 Locations
102K-204K Annually
Senior level
In-Office or Remote
3 Locations
102K-204K Annually
Senior level
Lead implementation of J&J Product Security strategy for Johnson & Johnson Vision devices. Support security across product development, perform threat modeling, code scanning, penetration testing, post-market vulnerability monitoring and remediation, respond to customer security questionnaires, drive governance, metrics, and cross-functional security improvements.
The summary above was generated by AI

At Johnson & Johnson, we believe health is everything. Our strength in healthcare innovation empowers us to build a world where complex diseases are prevented, treated, and cured, where treatments are smarter and less invasive, and solutions are personal. Through our expertise in Innovative Medicine and MedTech, we are uniquely positioned to innovate across the full spectrum of healthcare solutions today to deliver the breakthroughs of tomorrow, and profoundly impact health for humanity. Learn more at jnj.com

As guided by Our Credo, Johnson & Johnson is responsible to our employees who work with us throughout the world.  We provide an inclusive work environment where each person is considered as an individual.  At Johnson & Johnson, we respect the diversity and dignity of our employees and recognize their merit.

Job Function:

Technology Enterprise Strategy & Security

Job Sub Function:

Solution Architecture

Job Category:

Scientific/Technology

All Job Posting Locations:

Alabama (Any City), Alabama (Any City), Arizona (Any City), Arkansas (Any City), California (Any City), Colorado (Any City), Connecticut (Any City), Delaware (Any City), Florida (Any City), Georgia (Any City), Idaho (Any City), Illinois (Any City), Indiana (Any City), Iowa (Any City), Irvine, California, United States of America, Kansas (Any City), Kentucky (Any City), Louisiana (Any City), Maine (Any City), Maryland (Any City), Massachusetts (Any City), Michigan (Any City), Milpitas, California, United States of America, Minnesota (Any City), Mississippi (Any City) {+ 25 more}

Job Description:

We are seeking the best talent for a Product Security Manager to join our MedTech Product Security team. The role is based in Milpitas or Irvine, CA. Remote work options may be considered on a case-by-case basis and if approved by the Company. This may require up to 10% travel.

The Product Security Manager will be responsible for implementation of J&J’s enterprise Product Security strategy and framework throughout Johnson & Johnson Vision (JJV) medical device portfolio. This includes identifying key strategy and goals, collaborating with internal organizations on existing process and policy enhancements, creating and communicating metrics to management, identifying communications plans and raising overall awareness of the capability.

Specific responsibilities include:

  • Supporting JJV throughout a new product’s development phases
  • Review product security requirements and recommend security design solutions
  • Help complete Quality documentation, threat modelling, penetration testing, software architecture review and design recommendations, code analysis and other security testing or work as needed.
  • Post market responsibilities for JJV marketed devices include monitoring for new vulnerabilities, assisting with patching and remediation plans, as well as responding to all customer security questionnaires and reviewing security language within contractual agreements.
  • Drive adherence to J&J Product Security’s overarching framework:
  • Champion Product Security strategy and objectives within JJV
  • Partner with internal organizations to enhance existing processes and policies
  • Create and present Product Security metrics to management
  • Responsible and accountable to implement and enforce Product Security governance model for JJV pre and post market medical devices.
  • Perform automated code scanning and coordinate formal security testing.
  • Respond to customer cybersecurity questionnaires and contractual language for all post-market medical devices.
  • Other MedTech cybersecurity related duties as needed

Qualifications

Required:

  • 8 years IT or cybersecurity experience
  • Bachelor’s degree or equivalent
  • A minimum of 8 years of progressive experience in leadership roles within information technology or cybersecurity functions
  • Threat modeling experience
  • Data privacy experience, including GDPR and CCPA
  • Understanding of HIPAA/HITRUST & ISO 27001
  • Understanding of penetration testing, vulnerability scanning, CVSS and/or other general security testing principles
  • Ability to work autonomously and proactively seek out security opportunities within JJV
  • Knowledge of traditional and real-time operating systems (i.e. QNX, Windows Embedded) hardening techniques
  • Ability to create and deliver cybersecurity awareness campaigns and other communications
  • Ability to translate technical security requirements into solutions
  • Ability to provide secure coding recommendations
  • Ability to lead large projects and proven ability to track to project plan timelines from a security perspective
  • Ability to write technical security requirements for embedded systems and web platforms
  • Creative problem-solving skills
  • Customer focus (internal & external)
  • Excellent communication and collaboration skills, able to network, interface and influence at all levels of the organization, cross sector, cross-functionally and globally
  • Strong leadership skills

Preferred:

  • Experience leading or participating in formal security audits (i.e. HITRUST, SOC2, FedRAMP)
  • Familiarity with FDA and/or other global regulatory cybersecurity guidance requirements and submission process
  • Experience with web applications and server hardening (i.e. AWS, Azure) including knowledge of OWASP Top 10 and blue teaming techniques
  • Experience in cybersecurity pre-sales
  • Software development experience
  • CISSP or other security certification
  • MS and/or advanced degree

Johnson & Johnson is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, age, national origin, disability, protected veteran status or other characteristics protected by federal, state or local law. We actively seek qualified candidates who are protected veterans and individuals with disabilities as defined under VEVRAA and Section 503 of the Rehabilitation Act. 

Johnson & Johnson is committed to providing an interview process that is inclusive of our applicants’ needs. If you are an individual with a disability and would like to request an accommodation, external applicants please contact us via https://www.jnj.com/contact-us/careers , internal employees contact AskGS to be directed to your accommodation resource.

Required Skills:



Preferred Skills:



The anticipated base pay range for this position is :

$118,000.00 - $203,550.00

Additional Description for Pay Transparency:

The above salary range is for the Milpitas, CA (SF Bay Area) location. The salary range for all other locations is: $102,000 - $177,100.
Subject to the terms of their respective plans, employees are eligible to participate in the Company’s consolidated retirement plan (pension) and savings plan (401(k)).
Subject to the terms of their respective policies and date of hire, employees are eligible for the following time off benefits:
• Vacation –120 hours per calendar year
• Sick time - 40 hours per calendar year; for employees who reside in the State of Colorado –48 hours per calendar year; for employees who reside in the State of Washington –56 hours per calendar year
• Holiday pay, including Floating Holidays –13 days per calendar year
• Work, Personal and Family Time - up to 40 hours per calendar year
• Parental Leave – 480 hours within one year of the birth/adoption/foster care of a child
• Bereavement Leave – 240 hours for an immediate family member: 40 hours for an extended family member per calendar year
• Caregiver Leave – 80 hours in a 52-week rolling period10 days
• Volunteer Leave – 32 hours per calendar year
• Military Spouse Time-Off – 80 hours per calendar year
For additional general information on Company benefits, please go to: - https://www.careers.jnj.com/employee-benefits

Similar Jobs

22 Hours Ago
Remote
USA
105K-105K Annually
Mid level
105K-105K Annually
Mid level
Marketing Tech
The Founding Account Executive will lead sales for a new vertical, managing the full sales cycle, prospecting clients, shaping sales processes, and collaborating with senior leadership.
Top Skills: Crm SoftwareSalesforce
22 Hours Ago
Remote
USA
116K-137K Annually
Senior level
116K-137K Annually
Senior level
Marketing Tech
The GTM Ops Manager will establish and manage a sales strategy for a new vertical, including building a playbook, overseeing hiring, and analyzing performance metrics. This role requires ownership of the funnel and the ability to operate in ambiguous environments.
Top Skills: LookerMetabaseSalesforceSQL
22 Hours Ago
Remote
USA
138K-168K Annually
Senior level
138K-168K Annually
Senior level
Marketing Tech
Responsible for leading a new marketing vertical, managing agency partners, creating marketing strategies, and collaborating with product teams to drive results.
Top Skills: MarketingOmnichannel Strategies

What you need to know about the San Francisco Tech Scene

San Francisco and the surrounding Bay Area attracts more startup funding than any other region in the world. Home to Stanford University and UC Berkeley, leading VC firms and several of the world’s most valuable companies, the Bay Area is the place to go for anyone looking to make it big in the tech industry. That said, San Francisco has a lot to offer beyond technology thanks to a thriving art and music scene, excellent food and a short drive to several of the country’s most beautiful recreational areas.

Key Facts About San Francisco Tech

  • Number of Tech Workers: 365,500; 13.9% of overall workforce (2024 CompTIA survey)
  • Major Tech Employers: Google, Apple, Salesforce, Meta
  • Key Industries: Artificial intelligence, cloud computing, fintech, consumer technology, software
  • Funding Landscape: $50.5 billion in venture capital funding in 2024 (Pitchbook)
  • Notable Investors: Sequoia Capital, Andreessen Horowitz, Bessemer Venture Partners, Greylock Partners, Khosla Ventures, Kleiner Perkins
  • Research Centers and Universities: Stanford University; University of California, Berkeley; University of San Francisco; Santa Clara University; Ames Research Center; Center for AI Safety; California Institute for Regenerative Medicine

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account