Principal Med Device Security Engineer

Johnson & Johnson

Confirmed live today High trust
Closes in 6 days

Quick summary

Work type
On-site
Location
Danvers, MA
Salary
$102,000–$177,100 / yr
Posted
9 days ago
Freshness
Confirmed live today
Closes
Sep 30, 2026 (soon)

Market check

Salary context

Below market

How this pay compares to similar roles

Similar $184k
This role $140k
$87k most similar roles pay here $239k

This role pays less than 90% of similar roles. Most pay $151,475–$217,500 — the shaded band above. At the midpoint, this role pays about $140k versus about $184k for comparable roles.

Based on 240 similar postings.

Employer

About Johnson & Johnson

Johnson & Johnson is a multinational corporation operating in three main segments: consumer health products, pharmaceuticals, and medical devices, known for brands like Tylenol, Band-Aid, and Janssen. Industry: Pharmaceuticals & Medical Devices

Johnson & Johnson currently has 73 open roles on FindRole.

Listed pay typically runs $109,000–$177,100 across 68 roles with salary data.

Most-posted roles

View all roles at Johnson & Johnson

At a glance

TL;DR · Principal Med Device Security Engineer

Principal Med Device Security Engineer The Principal Med Device Security Engineer joins the Product Cybersecurity team to provide technical expertise and strategic leadership for the Heart Recovery portfolio, including Impella heart pump technologies and connected medical devices. This role involves owning the product security process throughout the development lifecycle, where you will implement security architecture, cryptographic controls, and threat mitigation techniques. You will perform threat modeling using STRIDE, conduct risk assessments via CVSS 3.1, and manage secure boot, firmware integrity, and key management infrastructure like PKI and HSMs. Day-to-day tasks include reviewing software architecture, performing code analysis, and managing over-the-air updates. You will utilize technologies such as Bluetooth LE, NFC, Wi-Fi, 5G, and RTOS while ensuring compliance with FDA, NIST, and IEC standards to protect critical medical devices from unauthorized modifications and ensure robust data security for patient safety.

What you'll do

  • Implement security architecture, cryptographic controls, and threat mitigation techniques for medical devices across the product lifecycle.
  • Perform threat modeling, risk assessments using STRIDE/CVSS, and code analysis to ensure secure hardware and software designs.
  • Develop and manage secure boot, firmware integrity validation, and anti-tamper mechanisms for heart recovery technologies.
  • Manage post-market security activities including vulnerability monitoring, patching plans, and responding to customer security questionnaires.
  • Ensure compliance with regulatory standards such as FDA guidance, NIST 800-175, FIPS 140-3, and IEC 62443.
  • Oversee secure over-the-air (OTA) update mechanisms and manage key management infrastructure including PKI and HSMs.
  • Lead Secure Development Lifecycle practices by integrating static/dynamic analysis and fuzz testing into the engineering process.
  • Generate Software Bill of Materials (SBOM) and security architecture views to support risk mitigation and transparency.

What we're looking for

  • Must have 10+ years of industry experience in Information Security.
  • Must have 8+ years of experience with embedded systems, IoT, or medical device cybersecurity.
  • Must possess a Bachelor’s degree or equivalent.
  • Ability to generate threat models without tools and perform risk assessments using CVSS 3.1 or higher with STRIDE per element.
  • Ability to write technical security requirements for embedded systems and web platforms based on current regulations.
  • Experience supporting regulatory submissions including FDA Cybersecurity Guidance, EU MDR, NIST 800-53, IMDRF, and AAMI TIR57.
  • Knowledge of real-time operating systems hardening, cloud security principles, and generating SBOMs from source code and binaries.
  • Experience with specific operating systems (QNX, QOS, Yocto, Linux Ubuntu, Alpine) and web application hardening (preferred).

More like this

Similar roles

Principal Product Security Engineer

Johnson & Johnson

Remote (Santa Clara, CA) 36 days ago $118,000–$203,550
Threat Modeling Vulnerability Management Penetration Testing CVSS SBOM Cloud Security AWS Azure C C++ C# Java Python Cryptography Secure Boot ISO 14971 AAMI TIR57 IEC 62304 IEC 81001-5-1 HIPAA GDPR HITRUST ISO 27001 OWASP Top 10 SOC 2 FedRAMP
8+ yrs exp Remote

Principal Security Engineer

JPMorgan Chase

Seattle, WA 38 days ago
AI Security Engineering Kubernetes Container Security CI/CD Endpoint Protection anti‑virus Product Management Automation

Professional Quality Steward

Johnson & Johnson

New Brunswick, NJ +4 2 days ago $79,000–$142,000
Secure by Design Threat Modeling STRIDE SAST DAST SCA SBOM SPDX CycloneDX CI/CD DevSecOps AWS Azure IoT IoMT ISO 14971 IEC 62304 ISO 13485 AAMI TIR57 OWASP Top 10 CWE CVSS
4+ yrs exp Hybrid

Professional Program Lead, Penetration Testing Services

Johnson & Johnson

New Brunswick, NJ +4 2 days ago $94,000–$170,000
Penetration Testing Offensive Security Red Teaming Application Security OWASP Top 10 NIST SP 800-115 MITRE ATT&CK CVSS Burp Suite Metasploit Nmap Wireshark Ghidra IDA Python Bash PowerShell AWS Azure CI/CD DevSecOps Firmware Security Reverse Engineering JTAG UART Bluetooth BLE Zigbee ISO 14971 AAMI TIR57
6+ yrs exp Hybrid

Principal Product Security Program Leader

Amd

San Jose, CA 37 days ago $240,000–$360,000
Product Security PSIRT Secure Development Lifecycle (SDL) SAST Coverity CodeQL SCA SBOM Black Duck SPDX CycloneDX Threat Modeling ISO/SAE 21434 NIST SSDF FPGA Vivado Vitis PetaLinux Yocto Xen ISO/IEC 27001 CVSS CVE
Hybrid

Principal Embedded Security Engineer

Motorola Solutions

Los Angeles, CA 108 days ago $180,000–$260,000
C/C++ Linux AES TLS SSL IPsec MACsec VPN DMVPN HMAC DSA Python FIPS 140-3 CSfC NIST
10+ yrs exp Hybrid