Sign up to access all features of our service.
  • Job search
  • Favorites
  • Create a CV
    New
  • Salaries
  • Subscriptions

Principal Product Security Engineer

$118k - $203.55k

Jobleads-US

At Johnson & Johnson, we believe health is everything. Our strength in healthcare innovation empowers us to build a world where complex diseases are prevented, treated, and cured, where treatments are smarter and less invasive, and solutions are personal. Through our expertise in Innovative Medicine and MedTech, we are uniquely positioned to innovate across the full spectrum of healthcare solutions today to deliver the breakthroughs of tomorrow, and profoundly impact health for humanity. Learn more at jnj.com

As guided by Our Credo, Johnson & Johnson is responsible to our employees who work with us throughout the world. We provide an inclusive work environment where each person is considered as an individual. At Johnson & Johnson, we respect the diversity and dignity of our employees and recognize their merit.

Job Function:

Technology Enterprise Strategy & Security

Job Sub Function:

Security & Controls

Job Category:

People Leader

All Job Posting Locations:

Santa Clara, California, United States of America

Job Description:

Johnson & Johnson's MedTech cybersecurity team is recruiting for an experienced Principal Product Security Engineer to be based in Santa Clara, CA. This may require up to 10% travel.

Relocation to the San Francisco Bay area will be considered on a case-by-case basis.

About MedTech

Fueled by innovation at the intersection of biology and technology, we're developing the next generation of smarter, less invasive, more personalized treatments.

Your unique talents will help patients on their journey to wellness. Learn more at

Position Summary

The Principal Product Security Engineer is a senior technical cybersecurity expert responsible for securing connected medical devices, robotic systems, embedded platforms, cloud services, and supporting digital health ecosystems throughout the product lifecycle.

This role provides hands-on technical leadership across multiple product teams by identifying cybersecurity risks, developing security requirements, performing security assessments, guiding remediation, and verifying that security controls are appropriately implemented within regulated medical device products.

Primary Responsibilities

Technical Product Security Leadership

  • Serve as the cybersecurity technical lead for complex medical device and digital health product development programs.
  • Provide technical direction on security design, implementation, verification, vulnerability remediation, and risk treatment activities.
  • Drive security-by-design practices throughout the product development lifecycle.
  • Influence engineering tradeoffs by balancing cybersecurity risk, patient safety, clinical workflow, usability, and product constraints.
  • Mentor software, systems, cloud, and embedded engineering teams on secure development practices.

Security Engineering

  • Develop, review, and maintain cybersecurity requirements for embedded systems, software applications, cloud services, and connected medical devices.
  • Perform detailed security design reviews, implementation assessments, configuration reviews, and attack surface analysis.
  • Evaluate authentication, authorization, cryptography, secure boot, key management, access control, logging, monitoring, update mechanisms, and operating system hardening implementations.
  • Provide practical secure coding and design recommendations to engineering teams.
  • Identify design weaknesses early and partner with teams to implement technically feasible mitigations.

Threat Modeling and Cybersecurity Risk Assessment

  • Lead threat modeling activities for products, platforms, system features, and supporting services.
  • Analyze threats, vulnerabilities, abuse cases, misuse cases, and chained attack paths.
  • Perform cybersecurity risk assessments and evaluate risk control effectiveness.
  • Assess potential impact to patient safety, clinical operations, confidentiality, integrity, availability, and product performance.
  • Develop risk-based mitigation strategies and support the objective evidence needed to demonstrate control effectiveness.

Security Testing and Validation

  • Perform or coordinate security testing activities including static analysis, software composition analysis, vulnerability scanning, fuzz testing, penetration testing, secure configuration reviews, and architecture assessments.
  • Analyze test results and translate findings into clear, actionable remediation plans.
  • Support independent security assessments and third-party penetration testing activities.
  • Verify the effectiveness of implemented security controls and compensating controls.
  • Ensure security testing outputs are traceable to product risks, requirements, and release decisions.

Vulnerability Management and Post-Market Security

  • Analyze vulnerabilities affecting commercial, open-source, cloud, infrastructure, and internally developed software components.
  • Evaluate exploitability and product impact using CVSS and product-specific cybersecurity risk assessment methods.
  • Lead technical investigations, root cause analysis, remediation planning, and compensating control evaluation.
  • Support patching strategies, remediation roadmaps, coordinated vulnerability disclosure, and post-market surveillance activities.
  • Partner with product support and customer-facing teams to provide technically accurate cybersecurity responses.

Regulatory, Quality, and Customer Support

  • Provide cybersecurity technical input for product releases, design reviews, quality documentation, and regulatory submissions.
  • Support cybersecurity deliverables such as product security plans, threat models, SBOM-related assessments, vulnerability assessments, penetration test summaries, security architecture documentation, and customer-facing security materials.
  • Participate in audits, assessments, and regulatory inspections as a product cybersecurity technical expert.
  • Review customer security questionnaires and cybersecurity contractual language for technical accuracy.
  • Communicate complex security topics clearly to technical and non-technical stakeholders.

Qualifications

Required:

  • Bachelor's degree in Computer Science, Cybersecurity, Software Engineering, Computer Engineering, or equivalent practical experience.
  • 8+ years of experience in cybersecurity, product security, cloud security, or related technical disciplines.
  • Demonstrated expertise in threat modeling, secure software development, vulnerability management, penetration testing, security design review, and cybersecurity risk assessment.
  • Experience securing embedded systems, connected medical devices, IoT products, robotics platforms, cloud-connected systems, or other cyber-physical products.
  • Strong technical understanding of authentication, authorization, cryptography, secure boot, key management, operating system hardening, network security, logging, monitoring, and secure update mechanisms.
  • Experience writing, reviewing, and validating technical cybersecurity requirements.
  • Ability to translate complex cybersecurity risks into practical engineering recommendations and risk-based product decisions.
  • Experience using vulnerability scoring and assessment methodologies such as CVSS.
  • Ability to independently lead technically complex security initiatives across multiple cross-functional teams.
  • Excellent written and verbal communication skills, including the ability to influence engineering and program stakeholders without direct authority.

Preferred:

  • Experience with medical devices, healthcare technology, surgical robotics, regulated software, or connected health platforms.
  • Familiarity with FDA medical device cybersecurity expectations and global medical device cybersecurity regulatory requirements.
  • Working knowledge of standards and frameworks such as ISO 14971, AAMI TIR57, IEC 62304, IEC 81001-5-1, HIPAA, GDPR, HITRUST, ISO 27001, OWASP Top 10, SOC 2, or FedRAMP.
  • Experience with AWS, Azure, cloud security, web application security, and secure infrastructure design.
  • Software development experience in C, C++, C#, Java, Python, or similar languages.
  • CISSP, CSSLP, GIAC, GICSP, or similar security certification.
  • Master's degree in Cybersecurity, Computer Science, Engineering, or related discipline.
  • Experience supporting formal security audits, regulatory submissions, or product security customer engagements.

Characteristics of Success

  • Solves complex product security problems across multiple product lines without relying on direct people management authority.
  • Identifies cybersecurity concerns early enough to influence design and implementation decisions.
  • Improves security posture through hands-on technical analysis, practical remediation guidance, and verification of control effectiveness.
  • Builds credibility with engineering teams by providing technically sound, feasible, and risk-informed recommendations.
  • Maintains strong traceability between cybersecurity risks, requirements, controls, verification activities, and release decisions.
  • Communicates cybersecurity risk in a way that supports patient safety, regulatory defensibility, and business decision-making.

Johnson & Johnson is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, age, national origin, disability, protected veteran status or other characteristics protected by federal, state or local law. We actively seek qualified candidates who are protected veterans and individuals with disabilities as defined under VEVRAA and Section 503 of the Rehabilitation Act.

Johnson & Johnson is committed to providing an interview process that is inclusive of our applicants' needs. If you are an individual with a disability and would like to request an accommodation, external applicants please contact us via , internal employees contact AskGS to be directed to your accommodation resource.

#JNJTECH

The anticipated base pay range for this position is :

$118,000.00 - $203,550.00

Additional Description for Pay Transparency:

Subject to the terms of their respective plans, employees are eligible to participate in the Company's consolidated retirement plan (pension) and savings plan (401(k)).

Subject to the terms of their respective policies and date of hire, employees are eligible for the following time off benefits:

  • Vacation -120 hours per calendar year
  • Sick time - 40 hours per calendar year; for employees who reside in the State of Colorado -48 hours per calendar year; for employees who reside in the State of Washington -56 hours per calendar year
  • Holiday pay, including Floating Holidays -13 days per calendar year
  • Work, Personal and Family Time - up to 40 hours per calendar year
  • Parental Leave - 480 hours within one year of the birth/adoption/foster care of a child
  • Bereavement Leave - 240 hours for an immediate family member: 40 hours for an extended family member per calendar year
  • Caregiver Leave - 80 hours in a 52-week rolling period10 days
  • Volunteer Leave - 32 hours per calendar year
  • Military Spouse Time-Off - 80 hours per calendar year

For additional general information on Company benefits, please go to: -

#J-18808-Ljbffr Jobleads-US
Vacancy posted 5 hours ago
Similar jobs that could be interesting for youBased on the Principal Product Security Engineer in Kentucky vacancy
  • $142.6k - $196k

     ...transformation. Join the future of product security at Bose. At Bose, security and stability...  ...innovation. We are seeking a Security Engineer to support the security initiatives for...  ...the next wave of innovation at Bose. Principal Duties and Responsibilities Architecting... 
    Suggested

    Bose

    Eastern, KY
    1 day ago
  • $123.55k - $142k

    ## Senior Product Security EngineerApplylocations: Golden, CO: Indianapolis, IN - Hague Rdtime type: Full timeposted on: Posted Todayjob requisition...  ...the full system lifecycle. The Senior Product Security Engineer will have a strong ownership stake to ensure Allegion’s... 
    Suggested
    Temporary work
    Flexible hours

    Allegion Canada Inc.

    Eastern, KY
    5 days ago
  •  ...our expertise across connectivity, AI, security and more, we’ll map a new way forward. Working...  ...'re looking for a senior/staff security engineer who is a genuine PKI expert, comfortable...  ..., and manage digital identity for our products, with particular depth needed in... 
    Suggested
    Full time
    Contract work

    Rivian VW Group

    Eastern, KY
    3 days ago
  • $182k - $228k

     ...growth, innovation, and content expansion, with complementary product and content capabilities that enable users to unearth even...  ...us! About the Role We're looking for a Senior Product Security Engineer to lead the design and implementation of secure, scalable, and... 
    Suggested
    Local area

    AlphaSense, Inc.

    Eastern, KY
    5 days ago
  •  ...generational company at a true inflection point. We have strong product-market fit and world-class investor support. We’re...  ...getting started. Role Overview As a Senior Software Engineer on the Product Security team at Harvey, you will have the opportunity to build... 
    Suggested
    Work experience placement

    Harvey

    Eastern, KY
    4 days ago
  •  ...Unleash AI Innovators, Securely Software is being rewritten in real time. AI agents are...  ...security agents working alongside your engineers, finding, fixing, and governing risk at...  ...direct and trust. Job Summary Snyk's Product Security team works consultatively with... 
    Shift work
    Early shift

    Snyk Ltd.

    Eastern, KY
    1 day ago
  • # Product Security EngineerUnited States15 hours agoID 1292957Price on request## DetailsEmployment type: Full-timeRemote: YesCompany: YipitDataLevel...  ...About The Role: YipitData is looking for a Product Security Engineer to help build security into the products and services we... 
    Work at office
    Remote work
    Flexible hours

    Bazeta

    Eastern, KY
    1 day ago
  •  ...Zof AI is seeking a Product Security Engineer to own the security posture of a platform that reads, executes, and modifies customer source code. This role covers isolation between agent workloads and tenants, secrets and credential handling, supply chain security, and... 
    Full time

    Zof AI

    Eastern, KY
    5 days ago
  •  ...and other critical infrastructure that developers need to securely scale their products to large organizations.We recently raised a $100M Series...  ...success.We are a highly collaborative group with a strong engineering mindset. Our security program is shaped by hands-on... 
    Work experience placement
    Remote work

    CyberJob

    Canada, KY
    2 days ago
  • $136.5k - $187.66k

     ...About the Job: LaunchDarkly's Product Security team is hiring a Product Security Engineer II to strengthen how we secure the platform engineers build with every day. You'll bring depth in security fundamentals and program design as a member of a small, high-leverage... 
    Full time
    Work at office

    Cervin

    Eastern, KY
    5 days ago
  •  ...Product Security Engineer San Francisco Engineering Hybrid Full-time About BackOps BackOps AI transforms supply-chain operations with agentic AI that automates complex workflows, freeing teams to focus on what matters most. Headquartered in... 
    Full time
    Work at office
    Flexible hours

    Theory Ventures

    Eastern, KY
    5 days ago
  •  ...on TRM to make the world safer and more secure. About the Team The Security team...  ...are looking for an Application Security Engineer to build mission-critical infrastructure...  ..., and application security at TRM for products as built and deployed. From designing the... 
    Summer work
    Immediate start
    Worldwide

    Apply

    Eastern, KY
    1 day ago
  • $250k - $285k

     ...high-performing team that believes in each other, come build with us at Crusoe. About This Role We’re seeking a Staff Product Security Engineer with deep AI/ML security expertise to strengthen Crusoe’s security posture across applications, infrastructure, and... 
    Temporary work

    DCYB

    Eastern, KY
    2 days ago
  •  ...Johnson & Johnson's MedTech cybersecurity team is recruiting a Principal Product Security Engineer to be based in Santa Clara, CA. This role may require up to 10% travel, with relocation considered on a case-by-case basis. The position provides hands-on technical leadership... 
    Relocation

    Jobleads-US

    Kentucky
    5 hours ago
  •  ...Ondo Finance is hiring a Senior Security Engineer – Product Security to own how we ship secure products. You will be a security partner for product engineering, driving threat modeling, owning secure code reviews for new features, and maintaining AppSec tooling and the... 

    Jobleads-US

    Kentucky
    1 day ago
  •  ...YipitData is looking for a Product Security Engineer to help build security into the products and services we deliver to customers. In this role, you will partner closely with Engineering and Product teams throughout the development lifecycle. You will assess new products... 
    Remote job

    Jobleads-US

    Kentucky
    1 day ago
  •  ...Jito is hiring an engineer to own product and protocol security across multiple product lines. You will report to the Head of Security and collaborate with an Enterprise Security Engineer on internal infrastructure, identity, and detection. This is an engineering role... 

    Jobleads-US

    Kentucky
    2 days ago
  • $165k - $200k

     ...financially smart kids and navigate life together. Its suite of products — including the Greenlight app, debit card, Safe Family GPS...  ...We are seeking an experienced and motivated Staff Product Security Engineer to join our growing Security team. This individual will be... 
    Work at office
    Local area
    Remote work
    Work from home
    Flexible hours
    Day shift

    Owl Ventures, LP

    Eastern, KY
    5 days ago
  •  ...uncharted. By combining our expertise across connectivity, AI, security and more, we’ll map a new way forward. Working together,...  ...more sustainable for everyone. Role Summary: As the Product Security Engineer, you will work closely with the product security... 
    Full time
    Contract work

    Rivian VW Group

    Eastern, KY
    5 days ago
  •  ...Close is seeking a Product Security Engineer to build and lead security efforts across backend and frontend stacks. You will own vulnerability remediation, threat modeling, and tooling optimization while collaborating with Engineering, SRE, and auditors. The role emphasizes... 
    Remote job

    Jobleads-US

    Kentucky
    1 day ago
  • $157k - $184k

     ...Chainguard is the trusted source for open source. By delivering hardened, secure, and production-ready builds of all the open source software engineers and AI agents rely on, Chainguard helps organizations build faster, stay compliant, and eliminate risk. Our customers... 
    Remote job
    Local area
    Flexible hours

    Jobleads-US

    Kentucky
    5 hours ago
  •  ...RX Global is seeking an experienced Principal Application Security Engineer to lead application security across our global technology estate. You will partner with engineering leadership to embed Secure by Design and ensure security is built into the SDLC. Reporting... 
    Principal

    Reed Exhibitions Australia Pty Ltd

    Eastern, KY
    5 days ago
  •  ...workflows, reporting, and AI. Underneath that product is a broad technical surface — Python...  ...providers that handle sensitive customer data. Security work happens across it all today, but the ownership is spread across Engineering, Infrastructure, and Security & Trust. We’... 
    Remote job
    Contract work
    Live in
    Local area
    Immediate start

    Jobleads-US

    Kentucky
    1 day ago
  • $217k - $303.9k

    # Staff Product Security EngineerUnited States15 hours agoID 1292913Price on request## DetailsEmployment type: Full-timeRemote: YesCompany:...  ...visit redditinc.com . Reddit is hiring a Staff Product Security Engineer to make the secure path the easiest path for engineers and AI... 
    For contractors
    Work experience placement
    Remote work

    Bazeta

    Eastern, KY
    1 day ago
  • GoodLeap, LLC is seeking a Senior Product Security Engineer to partner with product and engineering teams, balancing security by default with rapid delivery. You will design and test AI/LLM features, review designs before code exists, and own product security outcomes for... 

    GoodLeap, LLC

    Eastern, KY
    15 hours ago
  • About Iru Iru is the AI-powered security & IT platform used by the world’s fastest-growing companies to secure their users,...  ...The Opportunity We're seeking a highly technical Senior Product Security Engineer for a 6-month contract (40 hours/week) to embed security into... 
    Contract work
    Remote work

    Iru, Inc.

    Eastern, KY
    15 hours ago
  •  ...The Principal Product Engineer will drive the development, yield optimization, and deployment of MEMS-based timing products. This technical leadership role focuses on managing complex mixed-signal or MEMS products throughout their high-volume manufacturing lifecycle,... 
    Principal

    Niuro

    Eastern, KY
    5 days ago
  • $180k - $400k

     ...the Role This is our first dedicated security hire, and it's a rare chance to define the...  ...posture end-to-end. We have strong engineering fundamentals and a solid foundation; now...  ...perform threat modeling and hardening of new products Internet-facing APIs - Our high-... 
    Remote job

    Jobleads-US

    Kentucky
    1 day ago
  •  ...DoppelDoppel seeks a Product Security Engineer to embed security into engineering workflows, scale our security program, and mentor engineers across the product lifecycle. You will collaborate with product and cloud teams to design secure AI-assisted solutions, govern... 
    Remote job
    Flexible hours

    Jobleads-US

    Kentucky
    3 days ago
  •  ...WorkOS is seeking a security-focused engineer to lead secure design with engineering teams, and to perform offensive security testing across our products. You will shape security by default and help reduce risk while partnering with developers to implement pragmatic mitigations... 
    Remote job

    Jobleads-US

    Canada, KY
    2 days ago

Do you want to receive more vacancies?

Subscribe and receive similar vacancies to Principal Product Security Engineer. Be the first to apply!