HimalayasHimalayas logo
Johnson & JohnsonJJ

Senior Product Security Cloud Engineer

Johnson & Johnson is an American multinational corporation that develops, manufactures, and sells a broad range of products in the healthcare field, focusing on innovative medicines and medical technologies.

Johnson & Johnson

Employee count: 5000+

Salary: 94k-152k USD

United States only

Stay safe on Himalayas

Never send money to companies. Jobs on Himalayas will never require payment from applicants.

At Johnson & Johnson, we believe health is everything. Our strength in healthcare innovation empowers us to build a world where complex diseases are prevented, treated, and cured, where treatments are smarter and less invasive, and solutions are personal. Through our expertise in Innovative Medicine and MedTech, we are uniquely positioned to innovate across the full spectrum of healthcare solutions today to deliver the breakthroughs of tomorrow, and profoundly impact health for humanity. Learn more at jnj.com

As guided by Our Credo, Johnson & Johnson is responsible to our employees who work with us throughout the world. We provide an inclusive work environment where each person is considered as an individual. At Johnson & Johnson, we respect the diversity and dignity of our employees and recognize their merit.

Job Function:

Technology Enterprise Strategy & Security

Job Sub Function:

Security & Controls

Job Category:

Scientific/Technology

All Job Posting Locations:

Alabama (Any City), Alabama (Any City), Alaska (Any City), Arizona (Any City), Arkansas (Any City), California (Any City), Colorado (Any City), Connecticut (Any City), Danvers, Massachusetts, United States of America, Delaware (Any City), Florida (Any City), Georgia (Any City), Hawaii (Any City), Idaho (Any City), Illinois (Any City), Indiana (Any City), Iowa (Any City), Kansas (Any City), Kentucky (Any City), Louisiana (Any City), Maine (Any City), Maryland (Any City), Massachusetts (Any City), Michigan (Any City), Minnesota (Any City) {+ 27 more}

Job Description:

Johnson & Johnson’s MedTech cybersecurity team is recruiting for an experienced Senior Product Security Cloud Engineer. The role can be remote-based or located onsite in Danvers, MA or Raritan, NJ. The role must work US East Coast hours and requires up to 10% travel.

As the world’s most comprehensive MedTech business, J&J MedTech Companies are building on a century of experience, merging science and technology, to shape the future of health and benefit even more people around the world. With our unparalleled breadth, depth and reach across heart recovery, surgery, orthopedics and interventional solutions, we’re working to profoundly change the way care is delivered. We are in this for life. For more information, visit https://www.jnjmedtech.com/en-US

At Johnson & Johnson, we all belong.

Are you passionate about security and interested in joining a community of collaborative colleagues working in a Patient First! culture? If that’s you, we have an immediate opportunity for a Sr. Manager Medical Devices Product Security to join the Product Cybersecurity team to help ensure security is implemented by design for this top-performing medical device company. This is an exciting opportunity to impact development initiatives that will shape future product development and industry standards. You will own the Product Security process for the products that you will support throughout the product development lifecycle which includes both pre-market and post-market processes engineering teams. If you are eager to leverage your security risk and compliance skills to make a difference and directly impact patient lives, this could be perfect for you.

Purpose: The Senior Product Security Cloud Engineer should have MS Azure experience and will be responsible for implementation of J&J’s enterprise Product Security strategy and framework for the Heart Recovery cloud and supporting platforms. This role will join Abiomed, part of Johnson & Johnson MedTech, to provide MS Azure Cloud technical expertise and strategic leadership in securing Impella heart pump cloud technologies, next-generation cardiac support systems, and connected medical devices to the MS Azure cloud. This role is responsible for delivering MS Azure cloud security architecture, cryptographic controls and Public Key Infrastructure (PKI) , cloud security protections/controls, and threat mitigation techniques to ensure robust, regulatory-compliant security across the product lifecycle. Specific responsibilities include supporting heart recovery throughout a new product’s development phases, define product security requirements and recommend security design solutions, complete Quality documentation that includes development of the following: product security plan, security requirements definition, threat modeling, cybersecurity architecture views per FDA pre-Market Guidance for Medical Devices, cybersecurity risk assessment leveraging STRIDE and CVSS, Software Bill of Materials (SBOM), Software Composition Analysis (SCA) against the SBOM, SAST (Static Application Security Testing), DAST (Dynamic Application Security Testing), additional security testing including coordinating internal and external Pen Testing, and development of the cybersecurity risk management report, code analysis and other security testing work as needed.

Additionally, this position will have post-market MS Azure Cloud responsibilities for Heart Recovery marketed devices delivered monthly that include monitoring for new vulnerabilities (CVEs), developing the monthly cybersecurity documentation with approvals, assisting with patching and remediation plans. The role may also include supporting and responding to customer security questionnaires and reviewing security language within contractual agreements as needed.

  • Experience with MS Azure cloud security architecture and design

  • Experience with connected medical devices or IOTs connected to the cloud supporting secure data transmission and connectivity

  • Drive alignment of the Cloud security controls and adherence to the J&J Product Security’s overarching framework.

  • Experience creating or enhancing Cybersecurity Threat Model and Risk Assessment using STRIDE per element and CVSS 3.1 frameworks for the Cloud environment.

  • Experience implementing PKI and cryptographic controls with .

  • Understanding of FDA Pre-Market Guidance for Medical Device Appendix 1 and how to apply it to Cloud environments to achieve 524B compliance.

  • Define the security requirements required for USA 510k, EU MDR, and Japan PDMA compliance for Cloud solutions

  • Support the Product Security strategy and objectives within Heart Recovery

  • Define and enforce cryptographic protocols for data-at-rest and data-in-transit, ensuring compliance with FDA cybersecurity requirements, NIST 800-175, FIPS 140-3, and IEC 62443.

  • Define and implement key management infrastructure (PKI, cloud-based HSMs)) for device identity, authentication, and software signing.

  • Partner with R&D Engineering to implement managed identities across MS Azure services and security VMs and APIs within the Cloud Solution.

  • Implement Zero Trust security for device-to-cloud connectivity, integrating mTLS and continuous authentication models into clinical applications.

  • Oversee secure OTA (over-the-air) update mechanisms, ensuring software and firmware rollbacks, code signing, and supply chain integrity validation.

Primary Duties and Responsibilities

  • Partner with engineering teams (cloud, console) to drive successful adherence to the product security policies, processes, framework and program objectives.
  • Create, update, and improve product security processes for the cloud infrastructure and application.
  • Advise on cybersecurity matters and provide guidance to engineering and cross-functional teams.
  • Advocate for proactive inclusion of cybersecurity controls and processes into all phases of the product life cycle, process improvements, strategic product road map planning.
  • Deliver documentation for pre-market product development activities including security plans, threat models, security requirements, SBOM, and risk management documentation.
  • Drive and monitor monthly post-market vulnerability management activities, with adherence to strict timelines.
  • Perform threat modeling and cybersecurity risk assessment on Cloud infrastructure and applications.
  • Collaborate with the development team to integrate security measures into the CI/CD pipeline and the DevSecOps processes.
  • Continuous improvement and integration of Wiz and MS Defender Scores and monthly reports.
  • Support compliance certification activities, such as SOC2, FedRAMP, ISO 27001, C5 in Germany, etc.
  • Identify, research, evaluate, and integrate new compliance requirements, industry standards, and best practices into the product security programs.
  • Guide teams to make decisions that balance business needs with medical device security objectives within the MS Azure cloud.
  • Perform other related duties and responsibilities, as assigned.

Qualifications

Required:

  • Bachelor’s degree or equivalent
  • 5+ years industry experience in CyberSecurity.
  • 5+ years industry experience within MS Azure cloud
  • Experience working in a Cloud Scrum/Agile Azure DevOps environment.
  • Familiarity with some or all of these tools: Snyk, Veracode, Wiz, JIRA, Confluence.
  • Experience with Containerization technologies such as Docker and Kubernetes.
  • Working knowledge of regulatory standards and compliance frameworks (e.g., NIST Cybersecurity Framework, ISO27001, SOC2, HIPAA, GDPR).
  • Experience with security risk management techniques.
  • Demonstrated organizational skills, attention to detail, the ability to handle multiple assignments simultaneously in a timely manner and be able to meet assigned deadlines.
  • Committed to working with a sense of urgency and embracing new challenges.
  • Strong communication and interpersonal skills.

Preferred:

  • Experience working in an FDA-regulated environment.
  • Experience working with medical devices connected to the MS Azure Cloud
  • CISM or CISSP or CCSP certification

Johnson & Johnson is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, age, national origin, disability, protected veteran status or other characteristics protected by federal, state or local law. We actively seek qualified candidates who are protected veterans and individuals with disabilities as defined under VEVRAA and Section 503 of the Rehabilitation Act.

Johnson & Johnson is committed to providing an interview process that is inclusive of our applicants’ needs. If you are an individual with a disability and would like to request an accommodation, please contact us via https://www.jnj.com/contact-us/careers or contact AskGS to be directed to your accommodation resource.

#JNJTECH

Required Skills:

Preferred Skills:

The anticipated base pay range for this position is :

$94,000.00 - $151,800.00

Additional Description for Pay Transparency:

Subject to the terms of their respective plans, employees are eligible to participate in the Company’s consolidated retirement plan (pension) and savings plan (401(k)).

Subject to the terms of their respective policies and date of hire, employees are eligible for the following time off benefits:
• Vacation –120 hours per calendar year
• Sick time - 40 hours per calendar year; for employees who reside in the State of Colorado –48 hours per calendar year; for employees who reside in the State of Washington –56 hours per calendar year
• Holiday pay, including Floating Holidays –13 days per calendar year
• Work, Personal and Family Time - up to 40 hours per calendar year
• Parental Leave – 480 hours within one year of the birth/adoption/foster care of a child
• Bereavement Leave – 240 hours for an immediate family member: 40 hours for an extended family member per calendar year
• Caregiver Leave – 80 hours in a 52-week rolling period10 days
• Volunteer Leave – 32 hours per calendar year
• Military Spouse Time-Off – 80 hours per calendar year

For additional general information on Company benefits, please go to: - https://www.careers.jnj.com/employee-benefits

About the job

Apply before

Posted on

Job type

Full Time

Experience level

Salary

Salary: 94k-152k USD

Education

Bachelor degree

Experience

5 years minimum

Location requirements

Hiring timezones

United States +/- 0 hours

About Johnson & Johnson

Learn more about Johnson & Johnson and their company culture.

View company profile

At Johnson & Johnson, we believe good health is the foundation of vibrant lives, thriving communities, and forward progress. That's why for almost 140 years, we have aimed to keep people well at every age and every stage of life. Today, as the world's largest and most broadly based healthcare company, we are committed to using our reach and size for good. We strive to improve access and affordability, create healthier communities, and put a healthy mind, body, and environment within reach of everyone, everywhere. Every day, our more than 138,000 employees across the world are blending heart, science, and ingenuity to profoundly change the trajectory of health for humanity.

Our strength in healthcare innovation empowers us to build a world where complex diseases are prevented, treated, and cured, where treatments are smarter and less invasive, and solutions are personal. Through our expertise in Innovative Medicine and MedTech, we are uniquely positioned to innovate across the full spectrum of healthcare solutions today to deliver the breakthroughs of tomorrow. We are proud to collaborate and partner with a wide range of suppliers who support our businesses around the world. We believe acting ethically and responsibly is not only the right thing to do, but also the right thing to do for our business, as reflected in our Code of Business Conduct. Our commitment extends to our people, who are our most important asset. We invest in them through a culture of learning and development and a structured approach to leadership development, unlocking human potential. We are dedicated to tackling the world's most complex and pervasive health challenges and have a long history of advancing surgical care through our innovative portfolio.

Claim this profileJohnson & Johnson logoJJ

Johnson & Johnson

View company profile

Similar remote jobs

Here are other jobs you might want to apply for.

View all remote jobs

4 remote jobs at Johnson & Johnson

Explore the variety of open remote roles at Johnson & Johnson, offering flexible work options across multiple disciplines and skill levels.

View all jobs at Johnson & Johnson

Remote companies like Johnson & Johnson

Find your next opportunity by exploring profiles of companies that are similar to Johnson & Johnson. Compare culture, benefits, and job openings on Himalayas.

View all companies

Find your dream job

Sign up now and join over 100,000 remote workers who receive personalized job alerts, curated job matches, and more for free!

Sign up
Himalayas profile for an example user named Frankie Sullivan