Staff Product Security Engineer leading cybersecurity efforts for medical devices at Johnson & Johnson. Focus on threats, vulnerabilities, and security strategies within new product development.
Responsibilities
Identify threats and vulnerabilities to patient safety and product integrity, assess current security controls and determine potential impact of a threat and the risk level associated with threat/vulnerability pairs.
Drive architecture, requirements, and design to ensure that decisions incorporate security considerations.
Advise embedded system security software to ensure system hardening and secure coding practices.
Support all stakeholders on patch management, vulnerability handling, and SBOM scanning
Document designs and specifications per design control processes and conform to Industry Standards for Medical Device Software (IEC 62304)
Requirements
Bachelor’s degree in Computer Science, Computer Engineering, Cybersecurity or related degree
6+ years’ experience (or 4+ with M.S.) establishing security architecture or implementing security solutions in consumer products or medical devices
3+ experience in a software engineering or software architectural role in a New Product Development (NPD) environment
Proven experience with threat modeling and risk assessments for connected products or medical devices
Ability to work autonomously and proactively seek out security opportunities within the different surgical robotics teams
Ability to think big picture and have attention to detail – aligning strategic objectives with tactical implementation.
Proven experience with electrical and embedded software design
Experience developing software for embedded Real-Time Operating Systems (RTOS)
Experience developing embedded software systems using Modern C++ (preferably standards 17+)
A results and performance driven demeanor with strong sense of accountability
Understanding of penetration testing, vulnerability scanning, and/or other general security testing principles
Benefits
medical, dental, vision, life insurance
short- and long-term disability
business accident insurance
group legal insurance
consolidated retirement plan (pension)
savings plan (401(k))
long-term incentive program
vacation – up to 120 hours per calendar year
sick time - up to 40 hours per calendar year
holiday pay, including Floating Holidays – up to 13 days per calendar year
Work, Personal and Family Time - up to 40 hours per calendar year
Product Specialist BDE responsible for advising on Networks and Cybersecurity at Datacom. Supporting development of product strategies and sales ideas to drive customer success.
Security Guard at Commissionaires Nova Scotia ensuring safety, security, and protection for clients. Engaging veteran personnel in critical roles across various environment.
Fachkraft für Schutz und Sicherheit supporting public and private safety while protecting individuals and assets. Engage in preventing conflicts and recognizing dangers across various settings.
Senior Software Engineer at eBay developing cloud - native security services and mentoring teams. Focused on high availability and secure coding practices with a scalable infrastructure.
Project manager for IT infrastructure within IT security projects at DATAGROUP. Engaging in project management and communication with technical teams and clients.
Senior SAP Security Consultant designing future SAP security solutions for clients. Engaging with technological challenges and supporting digital transformation efforts.
Cybersecurity Engineer managing identity and access controls for enterprise applications at Truist. Expertise in Microsoft Entra and troubleshooting access issues in complex environments.
Cybersecurity Compliance Consultant performing SOX IT compliance testing at Truist. Assessing corporate cybersecurity compliance and managing risk and compliance functions across various locations.
IT Security Consultant conducting technical audits and consulting on cybersecurity for various sectors. Developing tailored security strategies and ensuring compliance with regulations.
Senior Consultant in IT Security conducting audits and creating security strategies. Advising clients in cybersecurity and ensuring compliance with regulations.