Exp, Analyst, Security Engineer Product
PharmaMedTechRegulatory AffairsQuality Assurancesasemafdacroraveinform
Job description
At Johnson & Johnson, we believe health is everything. Our strength in healthcare innovation empowers us to build a world where complex diseases are prevented, treated, and cured, where treatments are smarter and less invasive, and solutions are personal. Through our expertise in Innovative Medicine and MedTech, we are uniquely positioned to innovate across the full spectrum of healthcare solutions today to deliver the breakthroughs of tomorrow, and profoundly impact health for humanity. Learn more at jnj.com As guided by Our Credo, Johnson & Johnson is responsible to our employees who work with us throughout the world. We provide an inclusive work environment where each person is considered as an individual. At Johnson & Johnson, we respect the diversity and dignity of our employees and recognize their merit. Job Function: Technology Product & Platform Management Job Sub Function: Technical Product Management Job Category: Scientific/Technology All Job Posting Locations: New Brunswick, New Jersey, United States of America, Palm Beach Gardens, Florida, United States of America, Raynham, Massachusetts, United States of America, Warsaw, Indiana, United States of America, West Chester, Pennsylvania, United States of America Job Description: DePuy Synthes is recruiting for a(n) Exp, Analyst, Security Engineer Product located in New Brunswick, NJ or West Chester, PA or Palm Beach Gardens, FL or Warsaw, IN or Raynham, MA. Job Overview This role supports the protection of DePuy Synthes digital products and connected medical technologies by embedding security practices throughout the product lifecycle. The Exp, Analyst, Security Engineer Product partners closely with engineering, quality, regulatory, and IT teams to identify risks early, design secure solutions, and ensure products meet cybersecurity and regulatory expectations. This is an exciting opportunity to directly impact patient safety and product trust while working in a highly regulated, innovation‑driven environment and r eports into the DePuy Synthes Technology organization. Key Responsibilities Integrate security requirements and controls into the design and development of digital and connected products. Perform product security risk assessments, threat modeling, and vulnerability analysis across the product lifecycle. Partner with product development, quality, and regulatory teams to support secure design reviews and remediation activities. Support security testing activities, including static and dynamic analysis, penetration testing coordination, and vulnerability validation. Track, document, and manage product security findings to closure in alignment with internal governance processes. Contribute to the development and maintenance of product security standards, procedures, and best practices. Monitor emerging cybersecurity threats, vulnerabilities, and regulatory guidance relevant to medical devices and digital health. Support audits, assessments, and regulatory inquiries related to product cybersecurity. Qualifications Education Required: Bachelor’s degree in Computer Science , Engineering, Information Security, or a related technical field. Preferred: Master’s degree in Cybersecurity, Computer Engineering, or a related discipline. Experience and Skills Required: 2 – 4 years of relevant professional experience in cybersecurity, product security, or secure software development. Working knowledge of secure development lifecycle (SDLC) practices and security‑by‑design principles. Experience conducting security risk assessments, threat modeling, or vulnerability analysis. Familiarity with common security standards and frameworks (e.g., ISO, NIST, OWASP). Ability to collaborate effectively with cross‑functional technical and non‑technical teams. Strong analytical, documentation, and communication skills. Preferred: Experience supporting cybersecurity activities in a regulated industry (medical devices, healthcare, or life sciences). Hands‑on exposure to security testing tools and techniques (e.g., SAST, DAST, dependency scanning). Knowledge of cloud, embedded, or connected device security concepts. Understanding of regulatory cybersecurity expectations (e.g., FDA premarket/ postmarket guidance). Experience contributing to internal security policies, standards, or governance processes. Other: Language: English proficiency required . Travel: Up to 10% domestic travel. Certifications (Preferred): CISSP, CSSLP, GSEC, or equivalent
Stand out for this role
NoxPharm tailors your CV to this job description by aligning your experience with the role requirements and terminology. Built for pharma & life sciences.
Tailor my CV now — free to trySimilar Pharma jobs
Associate, Project Management (Pharmaceutical Labeling)
Open Scientific — Hauppauge, us
Maintenance Coordinator
Open Scientific — Bohemia, us
Manufacturing Operators - Pharmaceutical
Open Scientific — Melville, us
Pharmaceutical Mechanics - Packaging, Production, Maintanence
Open Scientific — Hauppauge, us
Warehouse - Pharmaceutical
Open Scientific — Hauppauge, us
Pharmaceutical Machine Operators
Open Scientific — Hauppauge, us