Principal Med Device Security Engineer
Remote / Online - Candidates ideally in
Garden City, Finney County, Kansas, 29756, USA
Listed on 2026-10-07
Garden City, Finney County, Kansas, 29756, USA
Listing for:
Johnson & Johnson
Remote/Work from Home
position Listed on 2026-10-07
Job specializations:
-
IT/Tech
Cybersecurity, Information Security & Data Protection
Job Description & How to Apply Below
Johnson & Johnson’s Med Tech cybersecurity team is recruiting for an experienced Principal Product Security Engineer. The role can be remote-based or located onsite in Danvers, MA or Raritan, NJ, and will require up to 10% travel.
ResponsibilitiesThe Principal Product Security Engineer will implement J&J’s enterprise Product Security strategy and framework across the Heart Recovery portfolio, providing technical expertise and strategic leadership in securing Impella heart pump technologies and related medical devices.
- Drive alignment to J&J Product Security’s overarching framework.
- Support the Product Security strategy and objectives within Heart Recovery.
- Define and implement secure boot, firmware integrity validation, and anti-tamper mechanisms for device firmware.
- Enforce cryptographic protocols for data-at-rest and data-in-transit, ensuring compliance with FDA cybersecurity requirements, NIST 800-175, FIPS 140-3, and IEC 62443.
- Define and implement key management infrastructure (PKI, HSMs, TPMs, and secure enclave integration) for device identity, authentication, and software signing.
- Develop real-time vulnerability assessment techniques for detecting security flaws in wireless communications (Bluetooth LE, NFC, Wi‑Fi, 5G, proprietary RF).
- Implement Zero Trust security for device-to-cloud connectivity, integrating mTLS and continuous authentication models.
- Oversee secure OTA update mechanisms, ensuring firmware rollbacks, code signing, and supply chain integrity validation.
- Lead Secure Development Lifecycle practices, integrating threat modeling, static/dynamic analysis, fuzz testing, and formal verification.
- Work with R&D Engineering to define hardware security architecture, including trust zones and hardware root of trust.
- Implement memory safety strategies to mitigate buffer overflows, side‑channel attacks, and execution vulnerabilities in real‑time operating systems and bare‑metal firmware.
- Respond to customer cybersecurity questionnaires and contractual language for post‑market medical devices.
Key requirements for this role include:
- 8+ years of industry experience in Information Security.
- 5+ years with embedded systems, IoT, or medical device cybersecurity.
- Bachelor’s degree or equivalent.
- Experience generating threat models without tools.
- Experience performing risk assessments using CVSS 3.1 or higher and STRIDE methodology.
- Ability to write technical security requirements for embedded systems and web platforms.
- Understanding of third‑party penetration testing, vulnerability scanning, and security testing principles.
- Experience supporting regulatory security submissions (FDA Guidance 2025, EU MDR, NIST 800‑53, IMDRF, AAMI TIR
57). - Knowledge of real‑time operating system hardening techniques and cloud security principles.
- Ability to generate SBOMs from software, firmware, and operating systems.
- Ability to conduct pre‑market and post‑market risk assessments using STRIDE and SCA SBOM scans.
- Ability to create security architecture views for medical devices.
- Strong secure coding and review skills.
- Data privacy experience (HIPAA, GDPR).
- Understanding of industry standards and certifications such as HITRUST and ISO 27001.
- Strong project leadership and ability to track timelines.
- Excellent communication, collaboration, and leadership skills.
- Creative problem‑solving and customer focus.
- Experience leading or participating in formal security audits.
- Experience with QNX, QOS, Yocto, Linux Ubuntu, and Alpine.
- Familiarity with FDA and other global cybersecurity guidance and submission processes.
- Experience with web application and server hardening (AWS, Azure) and OWASP Top 10.
- Experience in cybersecurity pre‑sales.
- Software development experience.
- Certifications such as CISSP or…
To View & Apply for jobs on this site that accept applications from your location or country, tap the button below to make a Search.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
Search for further Jobs Here:
×