Professional, Quality Steward
PharmaMedTechRegulatory AffairsQuality Assurancesasregulatory submissionemafdaiso 13485mdr
Job description
At Johnson & Johnson, we believe health is everything. Our strength in healthcare innovation empowers us to build a world where complex diseases are prevented, treated, and cured, where treatments are smarter and less invasive, and solutions are personal. Through our expertise in Innovative Medicine and MedTech, we are uniquely positioned to innovate across the full spectrum of healthcare solutions today to deliver the breakthroughs of tomorrow, and profoundly impact health for humanity. Learn more at jnj.com As guided by Our Credo, Johnson & Johnson is responsible to our employees who work with us throughout the world. We provide an inclusive work environment where each person is considered as an individual. At Johnson & Johnson, we respect the diversity and dignity of our employees and recognize their merit. Job Function: Technology Product & Platform Management Job Sub Function: Technical Product Management Job Category: Scientific/Technology All Job Posting Locations: New Brunswick, New Jersey, United States of America, Palm Beach Gardens, Florida, United States of America, Raynham, Massachusetts, United States of America, Warsaw, Indiana, United States of America, West Chester, Pennsylvania, United States of America Job Description: DePuy Synthes is recruiting for a Professional, Quality Steward located in New Brunswick, NJ or West Chester, PA or Palm Beach Gardens, FL or Warsaw, IN or Raynham, MA. Job Overview The Professional, Quality Steward is an established and productive individual contributor within the Cybersecurity function, accountable for embedding Secure by Design principles into the DePuy Synthes medical device and connected product portfolio. This role serves as the quality and security steward across the total product lifecycle — partnering with R&D, Product Management, Engineering, Regulatory Affairs, and Quality to ensure security requirements are defined early, designed in, verified through testing, and sustained through postmarket monitoring. Working under moderate supervision, the analyst applies practical knowledge of product security, secure development practices, and medical device regulatory expectations to ensure products are safe, secure, compliant, and defensible to regulators and customers. Key Responsibilities Serve as the product security steward for assigned product lines, embedding Secure by Design requirements into the product development lifecycle from concept through end-of-support. Define and document security requirements, design inputs, and acceptance criteria in collaboration with product owners, systems engineers, and R&D teams during early design phases. Facilitate threat modeling and security architecture reviews for connected devices, embedded software, mobile applications, and supporting cloud services; ensure identified threats are mitigated and traceable to controls. Conduct and coordinate product security risk assessments aligned to AAMI TIR57 and ISO 14971, ensuring cybersecurity risk is integrated with overall product risk management files. Generate, validate , and maintain Software Bills of Materials (SBOMs) for products; monitor third-party and open-source components for known vulnerabilities and drive remediation planning. Support secure software development practices, including secure coding standards, static and dynamic analysis, dependency scanning, and integration of security gates into CI/CD pipelines. Coordinate penetration testing and security verification activities with internal teams and third-party assessors; triage findings, assess exploitability and patient safety impact, and track remediation to closure. Prepare and review cybersecurity documentation for regulatory submissions, aligned to FDA premarket cybersecurity guidance, EU MDR, and applicable international requirements. Operate postmarket vulnerability management for released products — monitoring threat intelligence, performing impact analysis, and supporting coordinated vulnerability disclosure and customer advisories. Develop and maintain customer-facing security artifacts, including MDS2 forms, security white papers, and responses to hospital and health system security assessments. Partner with Quality and Regulatory to ensure product security activities are captured in design history files, design controls, and the Quality Management System. Establish and report product security metrics — design review coverage, vulnerability aging, SBOM currency, and remediation SLA performance — to leadership and program stakeholders. Assess security implications of product changes, platform migrations, supplier changes, and separation/carve-out activity affecting the product portfolio. Deliver Secure by Design training and enablement to engineering and product teams to strengthen security ownership and cyber culture. Qualifications Education Bachelor's degree in Computer Science , Cybersecurity, Software/Biomedical/ Electrical Engineering, Information Systems, or a related technical discipline. Master's degree in Cybersecurity, Computer Science, or Biomedical Engineering. Experience and Skills Required: 4 + years of experience in product security, application security, secure software development, or a related
Stand out for this role
NoxPharm tailors your CV to this job description by aligning your experience with the role requirements and terminology. Built for pharma & life sciences.
Tailor my CV now — free to trySimilar Pharma jobs
Aide de Laboratoire (H/F) - Immunologie
Eurofins — Lyon, fr
Technicien laboratoire en Bactériologie F/H - CDD 6 mois à temps complet
Eurofins — Les Mureaux, fr
Technicien de laboratoire en Bactériologie F/H
Eurofins — Les Mureaux, fr
Stage Analista Chimico - Pharma
Eurofins — Vimodrone, it
Mitarbeiter (m/w/d) Probenvorbereitung
Eurofins — Hamburg, de
Préleveur : Infirmier ou Technicien H/F
Eurofins — Plougastel-Daoulas, fr