Johnson & Johnson logo

Principal Product Security Engineer

Johnson & Johnson
August 19, 2026
On-site
Santa Clara, CA
IT
Principal Product Security Engineer (Santa Clara, CA) β€” up to 10% travel.

Relocation to the San Francisco Bay area will be considered on a case-by-case basis.

Position Summary:
Senior technical cybersecurity expert securing connected medical devices, robotic systems, embedded platforms, cloud services, and supporting digital health ecosystems throughout the product lifecycle. Provides hands-on leadership across product teams by identifying risks, defining security requirements, assessing security, guiding remediation, and verifying security controls in regulated medical device products.

Primary Responsibilities:
- Serve as cybersecurity technical lead for complex medical device/digital health programs.
- Provide technical direction for security design, implementation, verification, vulnerability remediation, and risk treatment.
- Drive security-by-design; mentor software/systems/cloud/embedded teams.
- Develop/review/maintain cybersecurity requirements for embedded systems, apps, cloud, and connected devices.
- Perform security reviews/assessments, attack surface analysis; evaluate authn/authz, crypto, secure boot, key management, access control, logging/monitoring, updates, and OS hardening.
- Lead threat modeling and cybersecurity risk assessments; develop risk-based mitigations.
- Coordinate security testing (SAST, SCA, scanning, fuzzing, pen testing, config review, architecture assessments) and ensure traceability to risks/requirements/release.
- Lead vulnerability management and post-market security; support disclosure, patching, and surveillance.
- Provide technical input for releases, quality/regulatory submissions; support audits and customer security materials.

Qualifications:
Required:
- BS in CS/Cybersecurity/Software Engineering/Computer Engineering or equivalent.
- 8+ years in cybersecurity/product security/cloud security.
- Expertise in threat modeling, secure development, vulnerability management, pen testing, security design review, cybersecurity risk assessment.
- Experience securing embedded/connected medical devices/IoT/robotics/cloud-connected or similar cyber-physical products.
- Strong knowledge of authn/authz, cryptography, secure boot, key management, OS/network hardening, logging/monitoring, secure updates.
- Experience writing/reviewing/validating technical cybersecurity requirements.
- Ability to lead complex initiatives across cross-functional teams and communicate effectively.
Preferred:
- Medical devices/healthcare tech/surgical robotics/regulated software/connect health experience.
- FDA/global medical device cybersecurity expectations.
- Standards/frameworks: ISO 14971, AAMI TIR57, IEC 62304, IEC 81001-5-1, HIPAA, GDPR, HITRUST, ISO 27001, OWASP Top 10, SOC 2, FedRAMP.
- AWS/Azure and web/cloud security; secure infrastructure design.
- Coding experience (C/C++/C#/Java/Python or similar).
- Certifications: CISSP, CSSLP, GIAC, GICSP, or similar.
- MS degree.

Benefits (time off, subject to policy/date of hire):
- Vacation: 120 hours/year; Sick time: 40 hours/year (CO/Washington: 48/56); Holiday pay (incl. Floating Holidays): 13 days/year; Work/Personal/Family Time: up to 40 hours/year; Parental Leave: 480 hours; Bereavement Leave: 240 hours immediate family (40 extended family/year); Caregiver Leave: 80 hours (52-week rolling); Volunteer Leave: 32 hours/year; Military Spouse Time-Off: 80 hours/year.