Principal Product Security Engineer
$118k - $203.55kJohnson & Johnson Innovative Medicine
At Johnson & Johnson, we believe health is everything. Our strength in healthcare innovation empowers us to build a world where complex diseases are prevented, treated, and cured, where treatments are smarter and less invasive, and solutions are personal. Through our expertise in Innovative Medicine and MedTech, we are uniquely positioned to innovate across the full spectrum of healthcare solutions today to deliver the breakthroughs of tomorrow, and profoundly impact health for humanity. Learn more at jnj.com
As guided by Our Credo, Johnson & Johnson is responsible to our employees who work with us throughout the world. We provide an inclusive work environment where each person is considered as an individual. At Johnson & Johnson, we respect the diversity and dignity of our employees and recognize their merit.
Job Function:
Technology Enterprise Strategy & SecurityJob Sub Function:
Security & ControlsJob Category:
People LeaderAll Job Posting Locations:
Santa Clara, California, United States of AmericaJob Description:
Johnson & Johnson’s MedTech cybersecurity team is recruiting for an experienced Principal Product Security Engineer to be based in Santa Clara, CA. This may require up to 10% travel.
Relocation to the San Francisco Bay area will be considered on a case-by-case basis.
About MedTech
Fueled by innovation at the intersection of biology and technology, we’re developing the next generation of smarter, less invasive, more personalized treatments.
Your unique talents will help patients on their journey to wellness. Learn more at
Position Summary
The Principal Product Security Engineer is a senior technical cybersecurity expert responsible for securing connected medical devices, robotic systems, embedded platforms, cloud services, and supporting digital health ecosystems throughout the product lifecycle.
This role provides hands-on technical leadership across multiple product teams by identifying cybersecurity risks, developing security requirements, performing security assessments, guiding remediation, and verifying that security controls are appropriately implemented within regulated medical device products.
Primary Responsibilities
Technical Product Security Leadership
- Serve as the cybersecurity technical lead for complex medical device and digital health product development programs.
- Provide technical direction on security design, implementation, verification, vulnerability remediation, and risk treatment activities.
- Drive security-by-design practices throughout the product development lifecycle.
- Influence engineering tradeoffs by balancing cybersecurity risk, patient safety, clinical workflow, usability, and product constraints.
- Mentor software, systems, cloud, and embedded engineering teams on secure development practices.
Security Engineering
- Develop, review, and maintain cybersecurity requirements for embedded systems, software applications, cloud services, and connected medical devices.
- Perform detailed security design reviews, implementation assessments, configuration reviews, and attack surface analysis.
- Evaluate authentication, authorization, cryptography, secure boot, key management, access control, logging, monitoring, update mechanisms, and operating system hardening implementations.
- Provide practical secure coding and design recommendations to engineering teams.
- Identify design weaknesses early and partner with teams to implement technically feasible mitigations.
Threat Modeling and Cybersecurity Risk Assessment
- Lead threat modeling activities for products, platforms, system features, and supporting services.
- Analyze threats, vulnerabilities, abuse cases, misuse cases, and chained attack paths.
- Perform cybersecurity risk assessments and evaluate risk control effectiveness.
- Assess potential impact to patient safety, clinical operations, confidentiality, integrity, availability, and product performance.
- Develop risk-based mitigation strategies and support the objective evidence needed to demonstrate control effectiveness.
Security Testing and Validation
- Perform or coordinate security testing activities including static analysis, software composition analysis, vulnerability scanning, fuzz testing, penetration testing, secure configuration reviews, and architecture assessments.
- Analyze test results and translate findings into clear, actionable remediation plans.
- Support independent security assessments and third-party penetration testing activities.
- Verify the effectiveness of implemented security controls and compensating controls.
- Ensure security testing outputs are traceable to product risks, requirements, and release decisions.
Vulnerability Management and Post-Market Security
- Analyze vulnerabilities affecting commercial, open-source, cloud, infrastructure, and internally developed software components.
- Evaluate exploitability and product impact using CVSS and product-specific cybersecurity risk assessment methods.
- Lead technical investigations, root cause analysis, remediation planning, and compensating control evaluation.
- Support patching strategies, remediation roadmaps, coordinated vulnerability disclosure, and post-market surveillance activities.
- Partner with product support and customer-facing teams to provide technically accurate cybersecurity responses.
Regulatory, Quality, and Customer Support
- Provide cybersecurity technical input for product releases, design reviews, quality documentation, and regulatory submissions.
- Support cybersecurity deliverables such as product security plans, threat models, SBOM-related assessments, vulnerability assessments, penetration test summaries, security architecture documentation, and customer-facing security materials.
- Participate in audits, assessments, and regulatory inspections as a product cybersecurity technical expert.
- Review customer security questionnaires and cybersecurity contractual language for technical accuracy.
- Communicate complex security topics clearly to technical and non-technical stakeholders.
Qualifications
Required:
- Bachelor's degree in Computer Science, Cybersecurity, Software Engineering, Computer Engineering, or equivalent practical experience.
- 8+ years of experience in cybersecurity, product security, cloud security, or related technical disciplines.
- Demonstrated expertise in threat modeling, secure software development, vulnerability management, penetration testing, security design review, and cybersecurity risk assessment.
- Experience securing embedded systems, connected medical devices, IoT products, robotics platforms, cloud-connected systems, or other cyber-physical products.
- Strong technical understanding of authentication, authorization, cryptography, secure boot, key management, operating system hardening, network security, logging, monitoring, and secure update mechanisms.
- Experience writing, reviewing, and validating technical cybersecurity requirements.
- Ability to translate complex cybersecurity risks into practical engineering recommendations and risk-based product decisions.
- Experience using vulnerability scoring and assessment methodologies such as CVSS.
- Ability to independently lead technically complex security initiatives across multiple cross-functional teams.
- Excellent written and verbal communication skills, including the ability to influence engineering and program stakeholders without direct authority.
Preferred:
- Experience with medical devices, healthcare technology, surgical robotics, regulated software, or connected health platforms.
- Familiarity with FDA medical device cybersecurity expectations and global medical device cybersecurity regulatory requirements.
- Working knowledge of standards and frameworks such as ISO 14971, AAMI TIR57, IEC 62304, IEC 81001-5-1, HIPAA, GDPR, HITRUST, ISO 27001, OWASP Top 10, SOC 2, or FedRAMP.
- Experience with AWS, Azure, cloud security, web application security, and secure infrastructure design.
- Software development experience in C, C++, C#, Java, Python, or similar languages.
- CISSP, CSSLP, GIAC, GICSP, or similar security certification.
- Master's degree in Cybersecurity, Computer Science, Engineering, or related discipline.
- Experience supporting formal security audits, regulatory submissions, or product security customer engagements.
Characteristics of Success
- Solves complex product security problems across multiple product lines without relying on direct people management authority.
- Identifies cybersecurity concerns early enough to influence design and implementation decisions.
- Improves security posture through hands-on technical analysis, practical remediation guidance, and verification of control effectiveness.
- Builds credibility with engineering teams by providing technically sound, feasible, and risk-informed recommendations.
- Maintains strong traceability between cybersecurity risks, requirements, controls, verification activities, and release decisions.
- Communicates cybersecurity risk in a way that supports patient safety, regulatory defensibility, and business decision-making.
Johnson & Johnson is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, age, national origin, disability, protected veteran status or other characteristics protected by federal, state or local law. We actively seek qualified candidates who are protected veterans and individuals with disabilities as defined under VEVRAA and Section 503 of the Rehabilitation Act.
Johnson & Johnson is committed to providing an interview process that is inclusive of our applicants’ needs. If you are an individual with a disability and would like to request an accommodation, external applicants please contact us via , internal employees contact AskGS to be directed to your accommodation resource.
#JNJTECH
Required Skills:
Preferred Skills:
The anticipated base pay range for this position is :
$118,000.00 - $203,550.00Additional Description for Pay Transparency:
Subject to the terms of their respective plans, employees are eligible to participate in the Company’s consolidated retirement plan (pension) and savings plan (401(k)). Subject to the terms of their respective policies and date of hire, employees are eligible for the following time off benefits:• Vacation –120 hours per calendar year
• Sick time - 40 hours per calendar year; for employees who reside in the State of Colorado –48 hours per calendar year; for employees who reside in the State of Washington –56 hours per calendar year
• Holiday pay, including Floating Holidays –13 days per calendar year
• Work, Personal and Family Time - up to 40 hours per calendar year
• Parental Leave – 480 hours within one year of the birth/adoption/foster care of a child
• Bereavement Leave – 240 hours for an immediate family member: 40 hours for an extended family member per calendar year
• Caregiver Leave – 80 hours in a 52-week rolling period10 days
• Volunteer Leave – 32 hours per calendar year
• Military Spouse Time-Off – 80 hours per calendar year For additional general information on Company benefits, please go to: -
$144.8k - $261.45k
What You'll DoOwn the design and delivery of AI-driven security features, from Azure OpenAI integrations to retrieval-... ...and build capabilities that deepen findings across products.Guide product security engineers, developers, and product teams as a technical partner....SuggestedFull timeTemporary workLocal areaWorldwide- ...delivered for millions of patients worldwide.We’re a team of engineers, clinicians, and innovators united by one purpose: to make... ...DescriptionPrimary Function of Position We are seeking a Staff Product Security engineer to join the software team within the Endoluminal...SuggestedLocal areaWorldwideFlexible hours
$136.5k - $253.5k
...innovators who want to make an impact on the world of technology. Seeking a highly motivated engineer who can drive improvement to Cadence’s synthesis and place & route products from a design perspective. The position provides an excellent opportunity to work closely...PrincipalFull time- ...data center networks, enterprise networking, wireless infrastructure, and passive optical access networks. The successful product definition engineer has deep technical credibility both inside and outside of Semtech, as well as good analytical and communication skills;...PrincipalFull time
$148.32k - $203.94k
...feature set that enables customers to differentiate their products with higher performance, smaller size, lower power, and better... ...SummaryWe are seeking a curious, motivated, and talented Principal Product Engineer to accelerate the development and deployment of SiTime’s...Principal$150.68k - $225.7k
...Marvell is a place to thrive, learn, and lead. Your Team, Your ImpactMarvell is seeking a highly motivated and experienced Principal Board Product Engineer to lead board-level product engineering activities from prototype through volume production. This role will serve as...PrincipalPermanent employmentContract workInternshipWork from home$102.3k - $209.5k
The Principal Supply Chain Product Engineer is a recognized technical leader responsible for ensuring that products are designed, validated, and manufactured with robust, scalable, and cost-effective test solutions. This role serves as a key advisor across Product Engineering...PrincipalTemporary workWork at officeFlexible hours$136.88k - $205k
...Marvell is a place to thrive, learn, and lead. Your Team, Your ImpactThe Optics PTE team take world-class Silicon Photonics products, Optical light Engine, and DCI transceiver modules from early R&D/NPI to volume production. The team owns end-to-end manufacturing solution...PrincipalPermanent employmentFull timeInternshipWork from home$185k - $240k
...architectures to meet their unique infrastructure requirements. Discover more at Role Overview As an Astera Labs Principal Product Application Engineer , you will need to provide technical guidance to customers to overcome design challenges, generate collateral for...PrincipalFull timeLocal areaFlexible hours$221.2k - $387.1k
Company DescriptionIt all started when engineer Fred Luddy wrote code that automated a tedious... ...people.Job DescriptionThe ServiceNow Security Organization (SSO) The ServiceNow... ...build against, partnering with ServiceNow's product AI security research team to apply frontier...PrincipalWork at officeImmediate startRemote workFlexible hours$177k - $302k
...advance faster than ever.We build and support advanced memory products that power next‑generation systems across the industry. We work... ..., you’ll be the technical connection between customers and engineering for our DRAM portfolio, including HBM, DDR, and GDDR. You’ll guide...PrincipalFull timeLocal areaImmediate start- ...in Santa Clara, CA seeks a hands-on Cyber Defense Engineering architect to tackle hard, undefined security problems for a platform used by thousands of enterprises... ...controls, and governance, partnering with the product AI security team to apply frontier research internally...Principal
$170k - $277k
...Palo Alto Networks, Inc. is seeking a Principal Software Engineer to drive the technical leadership of innovative cloud security solutions. The ideal candidate will have over 15 years of experience in software engineering and a strong command of programming languages...Principal$172k - $349k
Principal Security Software Engineer (Storage)This role has been designed as ‘’Onsite’ with an expectation that you will primarily work from an HPE office... ..., develops and troubleshoots software for HPE Storage products and integrates them with other HPE Cloud Products and...PrincipalFull timeWork experience placementWork at officeLocal areaImmediate start$139k - $224k
...: Johnson & Johnson, MedTech is recruiting for a Staff Software Product Security Engineer located in Santa Clara, CA (not remote). Johnson & Johnson MedTech innovates at the intersection of biology and technology. With a focus on treating with pinpoint precision in...Full timeWork experience placement$160k - $220k
...the intersection of networking and security. At Fortinet, our mission is to safeguard... ...an experienced and innovative Principal AI Security Engineer to join our Corporate Information Security... ...threat modeling for AI-related products, such as chatbots, MCPs implementations...PrincipalFull timeWork experience placementWorldwide$110k - $175k
...industry leaders . Our focus on system-level tests, feature validation, and meticulous bug analysis underpins the reliability of our products. With expertise in testing and debugging embedded systems, we ensure that our enterprise PCIe NVMe SSD products meet the highest...Principal$170k - $277k
...outcomes. Job Summary In the Layer-7 Security Software team, we are responsible for at... ...every PANOS release. Our code reaches many product lines in the company, and is the critical... ...Identification and Content Inspection Engine runs on Hardware, Virtualized, Container...PrincipalFull timeWork at office- ...architecture to design/model implantation team, and bring ideas to successful siliconMinimum Qualifications: - Master Degree in Electrical Engineering, Computer Science or Computer Engineering. - At least 5 years of CPU related Architect/RTL/Verification/Implementation design...PrincipalWork experience placement
$182k - $319k
...and the top 3 non-X86 server providers engineering solutions for this generation and the next... ...the future together.The Senior Principal, Design Engineering will be responsible... ..., storage & server systems and related products. In this position you will help develop...PrincipalLocal area$200k - $250k
Job Title: Principal RTL Design Engineer - PCIe / CXL / High-Speed SoCLocation: Santa Clara, CACompensation: $200K - $250K base DOE plus bonus and... ...of high-performance ASICs that power industry-leading products for hyperscale and enterprise customers. This position offers...Principal$185k - $230k
...connectivity fabric that powers rack-scale AI infrastructure. As a Principal Engineer on the Physical Design team, you will own the backend... ...timing, power, and signoff decisions that directly determine product PPA and time-to-market. This is a hands-on technical...PrincipalFull timeFlexible hours$182.36k - $273.2k
...Your ImpactIn this role you’ll be a member of the Data Center Engineering business group. Our group owns the digital design of high... ...language such as Perl/Python.• Proven track record of delivering production-quality designs on aggressive development schedules.• Domain...PrincipalPermanent employmentFull timeInternshipWork from home$136.88k - $205k
...learn, and lead. Your Team, Your ImpactThe Network and Compute Product Engineering organization at Marvell serves as a core technical... ...data centers and emerging AI workloads.What You Can ExpectAs a Principal Product Engineer within the Networking and Compute organization...PrincipalPermanent employmentFull timeInternshipWork from home$184k - $274k
...top 5 networking OEMs, and the top 3 non-X86 server providers engineering solutions for this generation and the next.Our customers experience... ...systems that keep next-generation Networking, Server, and AI products running. You will collaborate seamlessly across Celestica’s...PrincipalNight shift$210.87k - $329.86k
...seeking a high-impact, visionary Senior Principal AI Engineer to architect, design, and oversee the... .... Your mission is to develop a secure, multi-agent AI system and build a digital... ...minimum of 5 years of dedicated, hands-on production coding in Large Language Model (LLM)...PrincipalTemporary workWork at officeLocal areaWorldwideShift work- ...every system generates data that must be stored, managed, and made accessible over time. That’s where we come in. We combine deep engineering expertise with global-scale manufacturing to deliver the storage systems that make AI possible, powering hyperscale data centers,...PrincipalTemporary workImmediate startRemote workWorldwideFlexible hoursShift work
$136.5k - $253.5k
...most innovative companies, delivering extraordinary electronic products from chips to boards to systems for the most dynamic market... ...teamsPosition Requirements/Qualifications: BS degree in Electrical Engineering with a minimum of 7 years of experience OR MS with a minimum...PrincipalFull time$240k - $379.5k
...of how work gets done across engineering and enterprise workflows! As... ..., the identity and security controls built primarily for... ...and reliably.We are seeking a Principal Engineer to help define and... ...the right infrastructure into production.What you will be doing:Architect...PrincipalFull time$154.68k - $231.7k
...layout, packaging, prototype validation and production ramp up.The SubSystem Physical... ...hardening Working with Senior and Junior engineers to deliver reference floorplan, fully synthesized... ..., PCIE/CXL highly preferredEthernet, Security and peripheral interfaces through hands...PrincipalPermanent employmentFull timeInternshipWork from homeRelocation
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Principal Product Security Engineer. Be the first to apply!
- senior principal engineer Santa Clara, CA
- director data engineering Santa Clara, CA
- data center chief engineer Santa Clara, CA
- director quality engineering Santa Clara, CA
- director of product engineering Santa Clara, CA
- chief design engineer Santa Clara, CA
- chief engineer Santa Clara, CA
- senior chief engineer Santa Clara, CA
- principal engineer Santa Clara, CA
- senior director engineering Santa Clara, CA

