Johnson & Johnson logo

Lead Product Security Engineer

Johnson & Johnson
August 08, 2026
Remote friendly (Raritan, NJ)
United States
IT
Product Security Analyst (Product Security)

Responsibilities:
- Partner with engineering and cross-functional teams (cloud, console, pump, etc.) to drive adherence to the product security program.
- Deliver pre-market documentation: security plans, architecture/data flow diagrams, threat models, requirements, SBOM, and risk documentation.
- Define and implement key management infrastructure (PKI, HSMs, TPMs, secure enclave integration) for device identity, authentication, and software signing.
- Monitor and drive post-market vulnerability management within strict timelines.
- Support compliance certification activities (e.g., SOC2, FedRAMP, ISO 27001).
- Identify, evaluate, and integrate new compliance requirements and industry standards/trends into the product security program.
- Help teams balance business needs with security objectives; empathize with customers (internal/external).

Qualifications:
- Bachelor’s degree in Computer Science, Information Systems, or related field.
- 4+ years industry experience in Information Security.
- Working knowledge of regulatory standards and compliance frameworks (e.g., NIST Cybersecurity Framework, ISO 27001, SOC2, HIPAA, GDPR).
- Experience with security risk management.
- Experience in a regulated environment (FDA-regulated preferred).
- Strong organizational skills, attention to detail, and ability to meet deadlines; strong communication and interpersonal skills.

Travel: Up to 20%.