yoinka

Principal Product Security Engineer

Johnson & Johnson

Santa Clara, California, United States of AmericaPrincipalH-1B sponsor company
Sign in to applyVerified 1h ago
Location
Santa Clara, California, United States of America
Work model
On-Site
Level
Principal
H-1B history
2 approvals (FY2023)
Posted
Aug 19, 2026

Skills

Cybersecurity

About this role

At Johnson & Johnson, we believe health is everything. Our strength in healthcare innovation empowers us to build a world where complex diseases are prevented, treated, and cured, where treatments are smarter and less invasive, and solutions are personal. Through our expertise in Innovative Medicine and MedTech, we are uniquely positioned to innovate across the full spectrum of healthcare solutions today to deliver the breakthroughs of tomorrow, and profoundly impact health for humanity. Learn more at jnj.com As guided by Our Credo, Johnson & Johnson is responsible to our employees who work with us throughout the world.  We provide an inclusive work environment where each person is considered as an individual.  At Johnson & Johnson, we respect the diversity and dignity of our employees and recognize their merit. Job Function: Technology Enterprise Strategy & Security Job Sub Function: Security & Controls Job Category: People Leader All Job Posting Locations: Santa Clara, California, United States of America Job Description: Johnson & Johnson’s MedTech cybersecurity team is recruiting for an experienced Principal Product Security Engineer to be based in Santa Clara, CA. This may require up to 10% travel. Relocation to the San Francisco Bay area will be considered on a case-by-case basis.  About MedTech Fueled by innovation at the intersection of biology and technology, we’re developing the next generation of smarter, less invasive, more personalized treatments. Your unique talents will help patients on their journey to wellness. Learn more at https://www.jnj.com/medtech.

Position

Summary The Principal Product Security Engineer is a senior technical cybersecurity expert responsible for securing connected medical devices, robotic systems, embedded platforms, cloud services, and supporting digital health ecosystems throughout the product lifecycle. This role provides hands-on technical leadership across multiple product teams by identifying cybersecurity risks, developing security requirements, performing security assessments, guiding remediation, and verifying that security controls are appropriately implemented within regulated medical device products.

Primary Responsibilities

Technical Product Security Leadership Serve as the cybersecurity technical lead for complex medical device and digital health product development programs. Provide technical direction on security design, implementation, verification, vulnerability remediation, and risk treatment activities. Drive security-by-design practices throughout the product development lifecycle. Influence engineering tradeoffs by balancing cybersecurity risk, patient safety, clinical workflow, usability, and product constraints. Mentor software, systems, cloud, and embedded engineering teams on secure development practices. Security Engineering Develop, review, and maintain cybersecurity requirements for embedded systems, software applications, cloud services, and connected medical devices. Perform detailed security design reviews, implementation assessments, configuration reviews, and attack surface analysis. Evaluate authentication, authorization, cryptography, secure boot, key management, access control, logging, monitoring, update mechanisms, and operating system hardening implementations. Provide practical secure coding and design recommendations to engineering teams. Identify design weaknesses early and partner with teams to implement technically feasible mitigations. Threat Modeling and Cybersecurity Risk Assessment Lead threat modeling activities for products, platforms, system features, and supporting services. Analyze threats, vulnerabilities, abuse cases, misuse cases, and chained attack paths. Perform cybersecurity risk assessments and evaluate risk control effectiveness. Assess potential impact to patient safety, clinical operations, confidentiality, integrity, availability, and product performance. Develop risk-based mitigation strategies and

Listing verified 1h ago. Applications go through the company's official careers site.

← Back to Yoinka