Lead Product Security Engineer

Johnson & Johnson

Confirmed live yesterday High trust
Hybrid

Quick summary

Work type
Hybrid
Location
Danvers, MARaritan, NJ
Salary
$94,000–$151,800 / yr
Posted
58 days ago
Freshness
Confirmed live yesterday

Market check

Salary context

Below market

How this pay compares to similar roles

Similar $185k
This role $123k
$78k most similar roles pay here $241k

This role pays less than 95% of similar roles. Most pay $154,914–$216,000 — the shaded band above. At the midpoint, this role pays about $123k versus about $185k for comparable roles.

Based on 240 similar postings.

Employer

About Johnson & Johnson

Johnson & Johnson is a multinational corporation operating in three main segments: consumer health products, pharmaceuticals, and medical devices, known for brands like Tylenol, Band-Aid, and Janssen. Industry: Pharmaceuticals & Medical Devices

Johnson & Johnson currently has 46 open roles on FindRole.

Listed pay typically runs $117,000–$201,250 across 42 roles with salary data.

Most-posted roles

View all roles at Johnson & Johnson

At a glance

TL;DR · Lead Product Security Engineer

Lead Product Security Engineer joins the newly formed Product Security team to ensure security is implemented by design for medical devices. This role involves owning the product security process across both pre-market and post-market phases, partnering with cross-functional engineering teams to drive adherence to the company's security program. Key responsibilities include delivering documentation such as threat models, software bills of materials, and risk assessments while managing vulnerability activities under strict timelines. The candidate will implement key management infrastructure involving PKI, HSMs, TPMs, and secure enclave integration for device identity and authentication. Required skills include experience with security risk management, information security, and regulatory standards like NIST, ISO 27001, SOC2, HIPAA, and GDPR. This role addresses the critical challenge of maintaining cybersecurity integrity within a regulated medical device manufacturing environment to ensure high-quality patient outcomes.

What you'll do

  • Deliver pre-market documentation including security plans, threat models, data flow diagrams, and SBOMs.
  • Define and implement key management infrastructure for device identity, authentication, and software signing.
  • Manage post-market vulnerability activities while adhering to strict reporting timelines.
  • Support compliance certification activities such as SOC2, FedRAMP, and ISO 27001.
  • Integrate new compliance requirements and industry standards into the product security program.
  • Guide cross-functional teams to balance business needs with security objectives.
  • Drive adherence to the company's product security program across all engineering teams.

What we're looking for

  • Bachelor’s degree in Computer Science, Information Systems, or a related field.
  • 4+ years of industry experience in Information Security.
  • Working knowledge of regulatory standards and compliance frameworks such as NIST, ISO 27001, SOC2, HIPAA, and GDPR.
  • Experience with security risk management techniques and tactics.
  • Experience working in a regulated environment, preferably one that is FDA-regulated.
  • Strong communication and interpersonal skills to collaborate across cross-functional teams.
  • Demonstrated organizational skills and the ability to manage multiple assignments simultaneously under tight deadlines.

More like this

Similar roles

Principal Product Security Engineer

Johnson & Johnson

Remote (Santa Clara, CA) 23 days ago $118,000$203,550
Threat Modeling Vulnerability Management Penetration Testing CVSS SBOM Cloud Security AWS Azure C C++ C# Java Python Cryptography Secure Boot ISO 14971 AAMI TIR57 IEC 62304 IEC 81001-5-1 HIPAA GDPR HITRUST ISO 27001 OWASP Top 10 SOC 2 FedRAMP
8+ yrs exp Remote

Staff Product Security Engineer

Abbott

St. Paul, MN 22 days ago $113,300$226,700
C/C++ Python Linux Embedded Systems Firmware Secure Boot PKI Certificate Management TPM STRIDE OWASP SBOM CVE NIST Cybersecurity Framework IEC 62304 ISO 14971 RTOS
8+ yrs exp

Senior Product Security Engineer

Anduril Industries

Fort Collins, CO 151 days ago $144,000$191,000
C/C++ Golang Rust Python Linux Firmware IoT Embedded Systems Reverse Engineering Anti-tamper Cyber Survivability JSIG ICD 503 CSEIG SSECG NIST SP 800-160 CMMC Programmable Logic Devices
8+ yrs exp

Staff Product Security Engineer

Reddit

Remote 135 days ago $217,000$303,900
Go Python CI/CD LLM Authentication Authorization Cloud-Native Platforms Product Security Application Security Software Engineering
8+ yrs exp Remote

Software Engineer, Product Security

Rockwell Automation

Mayfield Heights, OH +1 28 days ago
Python Go TypeScript Node.js MongoDB Kubernetes Helm REST APIs Microservices Containers GitHub Azure DevOps CI/CD SAST SCA DAST SBOM OWASP Top 10 CWE
5+ yrs exp Hybrid

Product Security Engineer

Adobe

New York, NY +2 115 days ago $149,400$216,300
LLM Azure OpenAI Python React FastAPI Celery Redis Kubernetes Argo Vector Databases Prompt Engineering Retrieval-Augmented Generation Git CI/CD Azure JavaScript GitHub Copilot Cursor Threat Modeling
4+ yrs exp