Principal, Security Architect
Johnson & Johnson
- Location
- New Brunswick New Jersey United States of America
- Work model
- On-Site
- Level
- Principal
- H-1B history
- 2 approvals (FY2023)
- Posted
- Aug 25, 2026
Skills
About this role
At Johnson & Johnson, we believe health is everything. Our strength in healthcare innovation empowers us to build a world where complex diseases are prevented, treated, and cured, where treatments are smarter and less invasive, and solutions are personal. Through our expertise in Innovative Medicine and MedTech, we are uniquely positioned to innovate across the full spectrum of healthcare solutions today to deliver the breakthroughs of tomorrow, and profoundly impact health for humanity. Learn more at jnj.com As guided by Our Credo, Johnson & Johnson is responsible to our employees who work with us throughout the world. We provide an inclusive work environment where each person is considered as an individual. At Johnson & Johnson, we respect the diversity and dignity of our employees and recognize their merit. Job Function: Technology Enterprise Strategy & Security Job Sub Function: Security & Controls Job Category: Scientific/Technology All Job Posting Locations: New Brunswick, New Jersey, United States of America, Palm Beach Gardens, Florida, United States of America, Raritan, New Jersey, United States of America, Raynham, Massachusetts, United States of America, Warsaw, Indiana, United States of America, West Chester, Pennsylvania, United States of America Job Description: DePuy Synthes is recruiting for a Principal, Security Architect, located in the United States. The Security Architect designs, evaluates, and strengthens the security architecture that protects DePuy Synthes' technology assets, data, and operational environments. Sitting within the Technology Enterprise Strategy & Security organization, this role serves as a technical authority on security controls— assessing system and network configurations, identifying vulnerabilities and exposures, performing root-cause analysis, and contributing to the design, development, and implementation of countermeasures and security tooling across the enterprise. This role is responsible for advancing the organization' s Zero Trust, Secure by Design, and Resilient by Design strategy, ensuring security and resilience are embedded into every technology platform, architecture decision, and transformation initiative.
Key Responsibilities
Lead the development of Secure by Design, Resilient by Design, and Zero Trust architectures across cloud, network, endpoint, identity, application, data, and OT environments. Conduct security architecture reviews, threat modeling, and risk assessments for new and existing solutions. Drive the enterprise Zero Trust strategy, including identity, segmentation, least privilege, and continuous verification capabilities. Design network segmentation and micro-segmentation architectures to protect critical assets and reduce lateral movement. Define vulnerability and exposure management strategies, including risk-based prioritization and remediation. Develop resilient security architectures that strengthen containment, recovery, and business continuity capabilities. Design endpoint security controls, hardening standards, device compliance frameworks, and EDR/XDR integrations. Establish secure architectures for cloud, AI, data, and application environments, including secure development, DevSecOps , and AI governance practices. Develop OT security architectures that protect manufacturing, laboratory , and connected device environments. Partner with Enterprise and Solution Architects to embed security, resilience, and compliance requirements across transformation initiatives. Evaluate architectures and configurations against frameworks including NIST, NIST Zero Trust, CIS, ISO 27001, and applicable regulatory requirements. Drive security automation, tooling integrations, and engineering improvements that enhance enterprise defenses. Perform root-cause analysis of security findings and incidents, recommending strategic and