Product Security Senior Manager
Johnson & Johnson
Johnson & Johnson’s MedTech Product Security team is recruiting for an experienced Product Security Senior Manager to be based at any of our DePuy Synthes sites, with preference for US. Remote work options may be considered on a case-by-case basis and if approved by the Company.
DePuy Synthes, part of the Johnson & Johnson Medical Devices Companies, provides one of the most comprehensive orthopedics portfolios in the world. DePuy Synthes solutions, in specialties including joint reconstruction, trauma, craniomaxillofacial, spinal surgery and sports medicine, are designed to advance patient care while delivering clinical and economic value to health care systems worldwide.
Caring for the world, one person at a time has inspired and united the people of Johnson & Johnson for over 130 years. We embrace research and science -- bringing innovative ideas, products and services to advance the health and well-being of people.
The Product Security Senior Manager will be responsible for implementation of J&J’s enterprise Product Security strategy and framework throughout Johnson & Johnson DePuy Synthes orthopedics portfolio. This includes identifying key strategy and goals, collaborating with internal organizations on existing process and policy enhancements, creating and communicating metrics to senior management, identifying communications plans and raising overall awareness of the capability. Specific responsibilities include supporting DePuy Synthes throughout a new product’s development phases, review product security requirements and recommend security design solutions, help complete Quality documentation, threat modelling, penetration testing, software architecture review and design recommendations, code analysis and other security testing or work as needed.
Additionally, post market responsibilities for DePuy Synthes’ marketed devices include monitoring for new vulnerabilities, assisting with patching and remediation plans, as well as responding to all customer security questionnaires and reviewing security language within contractual agreements.
- Drive adherence to J&J Product Security’s overarching framework.
- Champion Product Security strategy and objectives within DePuy Synthes.
- Partner with internal organizations to enhance existing processes and policies.
- Create and present Product Security metrics to management.
- Responsible and accountable to implement and enforce Product Security governance model for DePuy Synthes pre and post market medical devices.
- Perform automated code scanning and coordinate formal security testing.
- Respond to customer cybersecurity questionnaires and contractual language for all post-market medical devices.
- Other MedTech cybersecurity related duties as needed.
- Bachelor’s degree or equivalent work experience.
Experience and Skills:
- 10 years of IT or cybersecurity experience.
- Threat modeling experience.
- Data privacy experience, including GDPR and CCPA.
- Understanding of HIPAA/HITRUST & ISO 27001.
- Understanding of penetration testing, vulnerability scanning, CVSS and/or other general security testing principles.
- Ability to work autonomously and proactively seek out security opportunities within DePuy Synthes.
- Knowledge of traditional and real-time operating systems (i.e. QNX, Windows Embedded) hardening techniques.
- Ability to create and deliver cybersecurity awareness campaigns and other communications.
- Ability to translate technical security requirements into solutions.
- Ability to provide secure coding recommendations.
- Ability to lead large projects and proven ability to track to project plan timelines from a security perspective.
- Ability to write technical security requirements for embedded systems and web platforms.
- Creative problem-solving skills.
- Customer focus (internal & external).
- Excellent communication and collaboration skills, able to network, interface and influence at all levels of the organization, cross sector, cross-functionally and globally.
- Strong leadership skills.
- Experience leading or participating in formal security audits (i.e. HITRUST, SOC2, FedRAMP).
- Familiarity with FDA and/or other global regulatory cybersecurity guidance requirements and submission process.
- Experience with web applications and server hardening (i.e. AWS, Azure) including knowledge of OWASP Top 10 and blue teaming techniques.
- Experience in cybersecurity pre-sales.
- Software development experience.
- CISSP or other security certification.
- MS and/or advanced degree.
Johnson & Johnson is an Affirmative Action and Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, age, national origin, or protected veteran status and will not be discriminated against on the basis of disability.
For more information on how we support the whole health of our employees throughout their wellness, career and life journey, please visit www.careers.jnj.com .
Anticipated Salary Range: $118,000-$177,000
The Company maintains highly competitive, performance-based compensation programs. Under current guidelines, this position is eligible for an annual performance bonus in accordance with the terms of the applicable plan. The annual performance bonus is a cash bonus intended to provide an incentive to achieve annual targeted results by rewarding for individual and the corporation’s performance over a calendar/performance year. Bonuses are awarded at the Company’s discretion on an individual basis.