Lead Product Security Engineer
Johnson & Johnson
August 30, 2026
On-site
Raritan, NJ
IT
J&J Heart Recovery β Product Security Analyst (Product Security team)
Primary Duties And Responsibilities:
- Partner with engineering and cross-functional teams (cloud, console, pump, etc.) to drive adherence to the product security program.
- Deliver pre-market documentation: security plans, architecture and data flow diagrams, threat models, requirements, SBOM, and risk documentation.
- Define and implement key management infrastructure (PKI, HSMs, TPMs, secure enclave integration) for device identity, authentication, and software signing.
- Monitor and drive post-market vulnerability management with adherence to strict timelines.
- Support compliance certifications (e.g., SOC2, FedRAMP, ISO 27001).
- Identify and integrate new compliance requirements and industry standards/trends into the product security program.
- Guide decisions balancing business needs with security objectives.
- Perform other related duties as assigned.
Job Qualifications:
- Bachelorβs degree in Computer Science, Information Systems, or related field.
- 4+ years industry experience in Information Security.
- Working knowledge of regulatory standards and compliance frameworks (e.g., NIST Cybersecurity Framework, ISO 27001, SOC2, HIPAA, GDPR).
- Experience with security risk management techniques and tactics.
- Experience in a regulated environment (FDA-regulated preferred).
- Strong organizational skills, attention to detail, ability to handle multiple assignments and meet deadlines.
- Strong communication and interpersonal skills.
Other:
- Up to 20% travel.
Primary Duties And Responsibilities:
- Partner with engineering and cross-functional teams (cloud, console, pump, etc.) to drive adherence to the product security program.
- Deliver pre-market documentation: security plans, architecture and data flow diagrams, threat models, requirements, SBOM, and risk documentation.
- Define and implement key management infrastructure (PKI, HSMs, TPMs, secure enclave integration) for device identity, authentication, and software signing.
- Monitor and drive post-market vulnerability management with adherence to strict timelines.
- Support compliance certifications (e.g., SOC2, FedRAMP, ISO 27001).
- Identify and integrate new compliance requirements and industry standards/trends into the product security program.
- Guide decisions balancing business needs with security objectives.
- Perform other related duties as assigned.
Job Qualifications:
- Bachelorβs degree in Computer Science, Information Systems, or related field.
- 4+ years industry experience in Information Security.
- Working knowledge of regulatory standards and compliance frameworks (e.g., NIST Cybersecurity Framework, ISO 27001, SOC2, HIPAA, GDPR).
- Experience with security risk management techniques and tactics.
- Experience in a regulated environment (FDA-regulated preferred).
- Strong organizational skills, attention to detail, ability to handle multiple assignments and meet deadlines.
- Strong communication and interpersonal skills.
Other:
- Up to 20% travel.