Johnson & Johnson logo

Lead Product Security Engineer

Johnson & Johnson
August 08, 2026
Remote friendly (Danvers, MA)
United States
IT
Responsibilities:
- Partner with engineering and cross-functional teams (cloud, console, pump, etc.) to ensure adherence to the product security program.
- Provide pre-market documentation: security plans, architecture/data flow diagrams, threat models, requirements, SBOM, and risk documentation.
- Define and implement key management infrastructure (PKI, HSMs, TPMs, secure enclave integration) for device identity, authentication, and software signing.
- Monitor and drive post-market vulnerability management within strict timelines.
- Support compliance certification activities (e.g., SOC 2, FedRAMP, ISO 27001).
- Identify and integrate new compliance requirements and industry standards/trends into the security program.
- Help teams balance business needs with security objectives.
- Perform other related duties as assigned.

Qualifications:
- Bachelor’s degree in Computer Science, Information Systems, or related field.
- 4+ years of Information Security experience.
- Working knowledge of regulatory/compliance frameworks (NIST CSF, ISO 27001, SOC 2, HIPAA, GDPR).
- Experience with security risk management.
- Regulated environment experience (FDA-regulated preferred).
- Strong organization, attention to detail, ability to manage multiple priorities and meet deadlines; urgency and communication skills.

Other:
- Up to 20% travel.
- Anticipated base pay range: $94,000–$151,800.

Benefits (as listed): medical, dental, vision, life insurance, short/long-term disability, business accident insurance, group legal; retirement plan/401(k); vacation and sick time; holidays; work/personal/family time; parental leave; caregiver/volunteer/military spouse time off.