Professional, Prog Lead, PenTesting Svcs
PharmaMedTechClinical ResearchRegulatory AffairsQuality Assurancepythonemafdamdrcrorave
Job description
At Johnson & Johnson, we believe health is everything. Our strength in healthcare innovation empowers us to build a world where complex diseases are prevented, treated, and cured, where treatments are smarter and less invasive, and solutions are personal. Through our expertise in Innovative Medicine and MedTech, we are uniquely positioned to innovate across the full spectrum of healthcare solutions today to deliver the breakthroughs of tomorrow, and profoundly impact health for humanity. Learn more at jnj.com As guided by Our Credo, Johnson & Johnson is responsible to our employees who work with us throughout the world. We provide an inclusive work environment where each person is considered as an individual. At Johnson & Johnson, we respect the diversity and dignity of our employees and recognize their merit. Job Function: Technology Enterprise Strategy & Security Job Sub Function: Solution Architecture Job Category: Scientific/Technology All Job Posting Locations: New Brunswick, New Jersey, United States of America, Palm Beach Gardens, Florida, United States of America, Raynham, Massachusetts, United States of America, Warsaw, Indiana, United States of America, West Chester, Pennsylvania, United States of America Job Description: DePuy Synthes is recruiting for a(n) Professional, Prog Lead, PenTesting Svcs located in New Brunswick, NJ or West Chester, PA or Palm Beach Gardens, FL or Warsaw, IN or Raynham, MA. Job Overview The Professional, Program Lead, Penetration Testing Services is a seasoned individual contributor within the Cybersecurity function, Product Security sub-function, accountable for building and running the penetration testing and offensive security services program for the DePuy Synthes product portfolio. This role establishes the testing methodology , scoping standards, and engagement model that embed Secure by Design verification into the product development lifecycle — spanning medical devices, embedded firmware, mobile applications, APIs, and supporting cloud services. The Program Lead manages internal testers and third-party assessment partners, translates technical findings into patient safety and business risk, and drives remediation to closure with R&D and engineering teams. Applying advanced technical skills and industry-leading practices, this role serves as the authoritative voice on product security testing across the enterprise. Key Responsibilities Own the end-to-end penetration testing services program for products and connected platforms, including the annual testing roadmap, prioritization model, and capacity planning across internal and external resources. Define and maintain the penetration testing methodology , scoping standards, rules of engagement, and reporting templates aligned to industry frameworks (OWASP, PTES, NIST SP 800-115, MITRE ATT&CK). Embed security testing gates into the product development lifecycle, ensuring Secure by Design verification occurs at defined design, integration, and pre-release milestones. Execute and oversee hands-on assessments across medical devices, embedded firmware, wireless protocols, mobile applications, web applications, APIs, and cloud infrastructure. Manage third-party penetration testing vendors — including scoping, statement of work development, quality review of deliverables, and performance management against SLAs. Triage and validate findings, assess exploitability, and evaluate patient safety and clinical impact in partnership with Product Security, Quality, and Regulatory stakeholders. Drive remediation with R&D and engineering teams, tracking findings through retest and verified closure, and escalating overdue or elevated risks through governance channels. Conduct threat modeling and attack surface analysis to inform test scoping and identify high-value targets prior to engagement. Support regulatory and customer requirements by producing testing evidence for FDA premarket submissions, EU MDR technical files, and hospital security assessments. Contribute penetration testing results and residual risk analysis into product security risk files aligned to AAMI TIR57 and ISO 14971. Build and report program metrics — test coverage across the portfolio, finding severity distribution, remediation aging, and retest pass rates — to leadership and product stakeholders. Research emerging attack techniques, medical device vulnerabilities, and tooling; continuously evolve the testing capability and develop custom tooling and exploits where needed. Assess the testing implications of platform migrations, supplier changes, and separation/carve-out activity affecting the product portfolio and supporting infrastructure. Deliver technical enablement and secure development training to engineering teams, using real findings to strengthen security ownership and cyber culture. Qualifications Education Bachelor's degree in Computer Science , Cybersecurity, Software/Electrical/ Biomedical Engineering, Information Systems, or a related technical discipline. Advanced degree or specialized cybersecurity education (preferred). Experience and Skills Required: Minimum 6 years of progressive experience in penetration testing, offensive security, red teaming, or application s
Stand out for this role
NoxPharm tailors your CV to this job description by aligning your experience with the role requirements and terminology. Built for pharma & life sciences.
Tailor my CV now — free to trySimilar Pharma jobs
Associate, Project Management (Pharmaceutical Labeling)
Open Scientific — Hauppauge, us
Maintenance Coordinator
Open Scientific — Bohemia, us
Manufacturing Operators - Pharmaceutical
Open Scientific — Melville, us
Pharmaceutical Mechanics - Packaging, Production, Maintanence
Open Scientific — Hauppauge, us
Warehouse - Pharmaceutical
Open Scientific — Hauppauge, us
Pharmaceutical Machine Operators
Open Scientific — Hauppauge, us