Principal Med Device Security Engineer
Johnson & Johnson · Slab City, NH · 1 mo ago
Hybrid$102k–$177k/yrFull-time
About the role
Johnson & Johnson’s MedTech cybersecurity team is recruiting for an experienced Principal Product Security Engineer. The role can be remote-based or located onsite in Danvers, MA or Raritan, NJ. This role will require up to 10% travel.
Responsibilities
- Own the Product Security process for the products that you will support throughout the product development lifecycle which includes both pre-market and post-market processes engineering teams.
- Support heart recovery throughout a new product’s development phases, review product security requirements and recommend security design solutions, complete Quality documentation, threat modelling, coordinate third-party penetration testing, software architecture review and design recommendations, code analysis and other security testing work as needed.
- Monitor for new vulnerabilities, assist with patching and remediation plans, respond to customer security questionnaires and review security language within contractual agreements as needed.
- Drive alignment to J&J Product Security’s overarching framework.
- Define and implement secure boot, firmware integrity validation, and anti-tamper mechanisms to protect Heart Recovery Device firmware against unauthorized modification.
- Enforce cryptographic protocols for data-at-rest and data-in-transit, ensuring compliance with FDA cybersecurity requirements, NIST 800-175, FIPS 140-3, and IEC 62443.
- Define and implement key management infrastructure (PKI, HSMs, TPMs, and secure enclave integration) for device identity, authentication, and software signing.
- Develop real-time vulnerability assessment techniques for detecting security flaws in wireless communications (Bluetooth LE, NFC, Wi-Fi, 5G, proprietary RF) used in Heart Recovery’s medical devices.
- Implement Zero Trust security for device-to-cloud connectivity, integrating mTLS and continuous authentication models into clinical applications.
- Oversee secure OTA (over-the-air) update mechanisms, ensuring firmware rollbacks, code signing, and supply chain integrity validation.
- Lead Secure Development Lifecycle practices, integrating threat modeling, static/dynamic analysis, fuzz testing, and formal verification into the development process.
- Work with R&D Engineering to define hardware security architecture, including trust zones, hardware root of trust (HRoT), and secure microcontroller protections.
- Implement memory safety strategies to mitigate buffer overflows, side-channel attacks, and execution vulnerabilities in real-time operating systems (RTOS) and bare-metal firmware.
- Respond to customer cybersecurity questionnaires and contractual language for post-market medical devices under your responsibility as necessary.
Requirements
- 8+ years industry experience in Information Security
- 5+ years experience with embedded system, IoT, or medical device cybersecurity
- Bachelor’s degree or equivalent
- Experience generating Threat models without the use of threat modeling tools
- Experience performing risk assessments utilizing CVSS 3.1 or higher, with STRIDE per element
- Understanding and execution of third-party penetration testing, vulnerability scanning, CVSS and/or other general security testing principles
- Experience supporting regulatory security submissions, ensuring compliance with FDA Cybersecurity Guidance (2025), EU MDR, NIST 800-53, IMDRF, and AAMI TIR57
- Knowledge of real-time operating systems hardening techniques
- Knowledge of cloud security principles
- Ability to generate SBOMs from Software source code and Binaries, Firmware, and Operating Systems
- Ability to generate pre-market risk assessments against the threat model leveraging STRIDE and post-market risk assessments via SCA SBOM scans
- Ability to generate the security architecture views for medical devices that could include: Global System View, Multi-Patient Harm View, Updateability/Patchability view and, detailing system boundaries, data flows, and external interactions to show risk mitigation, ensuring transparency, and supporting post-market management
- Ability to translate technical security requirements into solutions
- Ability to provide secure coding recommendations and execute reviews
- Data privacy experience, including HIPAA and GDPR
- Understanding of industry standards and certifications such as HITRUST & ISO 27001
- Ability to work autonomously and proactively seek out product security opportunities within heart recovery
- Proven ability to track to project plan timelines from a security perspective
- Ability to create and deliver cybersecurity awareness campaigns and other communications
- Creative problem-solving skills
- Customer focus (internal & external)
- Excellent communication and collaboration skills, able to network, interface and influence at all levels of the organization, cross sector, cross-functionally and globally
- Strong leadership skills
Preferred Experience
- Leading or participating in formal security audits
- Familiarity with FDA and/or other global regulatory cybersecurity guidance requirements and submission process
- Experience with Operating Systems such as QNX QOS, Yocto, Linux Ubuntu. Alpine
- Familiarity with cloud security principles
- Experience in cybersecurity pre-sales
- Software development experience
- CISSP, CISM, or other security certification
- MS and/or advanced degree