×
Register Here to Apply for Jobs or Post Jobs. X
More jobs:

Principal Med Device Security Engineer

Remote / Online - Candidates ideally in
Danvers, Essex County, Massachusetts, 01923, USA
Listing for: 6942-ABIOMED Inc. Legal Entity
Per diem, Remote/Work from Home position
Listed on 2026-07-18
Job specializations:
  • Security
    Cybersecurity
Salary/Wage Range or Industry Benchmark: 102000 - 177100 USD Yearly USD 102000.00 177100.00 YEAR
Job Description & How to Apply Below

Principal Product Security Engineer

Johnson & Johnson’s Med Tech cybersecurity team is recruiting for an experienced Principal Product Security Engineer. The role can be remote-based or located onsite in Danvers, MA or Raritan, NJ and requires up to 10% travel.

Responsibilities
  • Own the Product Security process for products throughout the product development lifecycle, supporting both pre‑market and post‑market processes.
  • Design security architecture, cryptographic controls, embedded system protections/controls, and threat mitigation techniques to ensure regulatory‑compliant security across the product lifecycle.
  • Support heart recovery throughout a new product’s development phases, review product security requirements, recommend security design solutions, complete quality documentation, threat modelling, and coordinate third‑party penetration testing.
  • Conduct software architecture reviews and design recommendations, code analysis, and other security testing work as needed.
  • Provide post‑market responsibilities for Heart Recovery marketed devices, including monitoring new vulnerabilities, assisting with patching and remediation plans, responding to customer security questionnaires, and reviewing security language within contractual agreements.
  • Drive alignment to J&J Product Security’s overarching framework and support the Product Security strategy and objectives within Heart Recovery.
  • Define and implement secure boot, firmware integrity validation, and anti‑tamper mechanisms to protect Heart Recovery Device firmware against unauthorized modification.
  • Enforce cryptographic protocols for data‑at‑rest and data‑in‑transit, ensuring compliance with FDA cybersecurity requirements, NIST 800‑175, FIPS 140‑3, and IEC 62443.
  • Define and implement key management infrastructure (PKI, HSMs, TPMs, and secure enclave integration) for device identity, authentication, and software signing.
  • Develop real‑time vulnerability assessment techniques for detecting security flaws in wireless communications (Bluetooth LE, NFC, Wi‑Fi, 5G, proprietary RF) used in Heart Recovery’s medical devices.
  • Implement Zero Trust security for device‑to‑cloud connectivity, integrating mTLS and continuous authentication models into clinical applications.
  • Oversee secure OTA (over‑the‑air) update mechanisms, ensuring firmware rollbacks, code signing, and supply chain integrity validation.
  • Lead Secure Development Lifecycle practices, integrating threat modeling, static/dynamic analysis, fuzz testing, and formal verification into the development process.
  • Work with R&D Engineering to define hardware security architecture, including trust zones, hardware root of trust (HRoT), and secure microcontroller protections.
  • Implement memory safety strategies to mitigate buffer overflows, side‑channel attacks, and execution vulnerabilities in real‑time operating systems (RTOS) and bare‑metal firmware.
  • Respond to customer cybersecurity questionnaires and contractual language for post‑market medical devices under responsibility as necessary.
Qualifications
  • 8+ years industry experience in Information Security.
  • 5+ years experience with embedded system, IoT, or medical device cybersecurity.
  • Bachelor’s degree or equivalent.
  • Experience generating threat models without the use of threat modeling tools.
  • Experience performing risk assessments utilizing CVSS 3.1 or higher, with STRIDE per element.
  • Ability to write technical security requirements for embedded systems and web platforms based on the latest regulations.
  • Understanding and execution of third‑party penetration testing, vulnerability scanning, CVSS and/or other general security testing principles.
  • Experience supporting regulatory security submissions, ensuring compliance with FDA Cybersecurity Guidance (2025), EU MDR, NIST 800‑53, IMDRF, and AAMI TIR
    57.
  • Knowledge of real‑time operating systems hardening techniques.
  • Knowledge of cloud security principles.
  • Ability to generate SBOMs from Software source code and Binaries, Firmware, and Operating Systems.
  • Ability to generate pre‑market risk assessments against the threat model leveraging STRIDE and post‑market risk assessments via SCA SBOM scans.
  • Ability to generate the security…
Position Requirements
5+ Years work experience
To View & Apply for jobs on this site that accept applications from your location or country, tap the button below to make a Search.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
 
 
 
Search for further Jobs Here:
(Try combinations for better Results! Or enter less keywords for broader Results)
Location
Increase/decrease your Search Radius (miles)
0
200
Filters
Education Level
Experience Level (years)
Posted in last:
Salary