Principal Product Security Engineer

Johnson & Johnson

Confirmed live yesterday High trust
Remote

Quick summary

Work type
Remote
Location
Santa Clara, CA
Salary
$118,000–$203,550 / yr
Posted
23 days ago
Freshness
Confirmed live yesterday

Market check

Salary context

Below market

How this pay compares to similar roles

Similar $194k
This role $161k
$102k most similar roles pay here $267k

This role pays less than 85% of similar roles. Most pay $169,687–$218,437 — the shaded band above. At the midpoint, this role pays about $161k versus about $194k for comparable roles.

Based on 240 similar postings.

Employer

About Johnson & Johnson

Johnson & Johnson is a multinational corporation operating in three main segments: consumer health products, pharmaceuticals, and medical devices, known for brands like Tylenol, Band-Aid, and Janssen. Industry: Pharmaceuticals & Medical Devices

Johnson & Johnson currently has 46 open roles on FindRole.

Listed pay typically runs $117,000–$201,250 across 42 roles with salary data.

Most-posted roles

View all roles at Johnson & Johnson

At a glance

TL;DR · Principal Product Security Engineer

Principal Product Security Engineer The Principal Product Security Engineer joins the MedTech cybersecurity team to serve as a technical lead for complex medical device and digital health product development programs. This role involves securing connected medical devices, robotic systems, embedded platforms, and cloud services throughout the product lifecycle. Key responsibilities include performing threat modeling, conducting security design reviews, managing vulnerabilities using CVSS metrics, and overseeing security testing such as static analysis, fuzzing, and penetration testing. The candidate will develop technical requirements for authentication, cryptography, secure boot, and operating system hardening while ensuring compliance with regulatory standards like FDA expectations and ISO 14971. Required skills include expertise in cloud security, infrastructure design, and programming in C, C++, C#, Java, or Python. This role addresses the critical challenge of protecting patient safety and clinical operations within regulated medical device ecosystems.

What you'll do

  • Lead cybersecurity design, implementation, and risk treatment for medical devices and digital health products.
  • Develop and maintain security requirements for embedded systems, software applications, and cloud services.
  • Conduct threat modeling to identify vulnerabilities, abuse cases, and potential impacts on patient safety.
  • Perform security testing including static analysis, penetration testing, and vulnerability scanning.
  • Manage the lifecycle of vulnerabilities by performing root cause analysis and coordinating remediation plans.
  • Provide technical input for regulatory submissions, quality documentation, and product security plans.
  • Review customer security questionnaires and ensure accuracy in cybersecurity contractual language.
  • Mentor engineering teams on secure development practices and provide practical coding recommendations.

What we're looking for

  • Bachelor's degree in Computer Science, Cybersecurity, Software Engineering, Computer Engineering, or equivalent practical experience.
  • 8+ years of experience in cybersecurity, product security, cloud security, or related technical disciplines.
  • Demonstrated expertise in threat modeling, secure software development, vulnerability management, penetration testing, security design review, and risk assessment.
  • Experience securing embedded systems, connected medical devices, IoT products, robotics platforms, or other cyber-physical products.
  • Strong technical understanding of authentication, cryptography, secure boot, key management, and operating system hardening.
  • Ability to translate complex cybersecurity risks into practical engineering recommendations and risk-based product decisions.
  • Experience with medical devices, healthcare technology, surgical robotics, or regulated software (preferred).
  • Familiarity with medical device regulations, security frameworks like ISO 27001/OWASP, cloud platforms, and programming languages such as C++, Java, or Python (preferred).

More like this

Similar roles

Lead Product Security Engineer

Johnson & Johnson

Danvers, MA +1 58 days ago $94,000$151,800
Cybersecurity PKI SBOM SOC2 FedRAMP ISO 27001 NIST Cybersecurity Framework HIPAA GDPR Risk Management Data Flow Diagrams Product Security Vulnerability Management
4+ yrs exp Hybrid

Principal Security Engineer

JPMorgan Chase

Seattle, WA 25 days ago
AI Security Engineering Kubernetes Container Security CI/CD Endpoint Protection anti‑virus Product Management Automation

Senior Security Engineer I, Product Security

Oscar Health

Remote (San Francisco, CA) 8 days ago
Application Security SAST DAST Vulnerability Management AI Integration Model Context Protocol (MCP) Code Review Risk Assessment Software Development
4+ yrs exp Remote

Senior Security Engineer I, Product Security

Oscar Health

Los Angeles, CA 8 days ago
Application Security SAST DAST Vulnerability Management AI Integration Model Context Protocol (MCP) Source Code Review Risk Assessment Software Development
4+ yrs exp Hybrid

Senior Security Engineer I, Product Security

Oscar Health

Tempe, AZ 8 days ago
SAST DAST SDLC Vulnerability Management Code Review AI Integration Model Context Protocol (MCP) Software Development Risk Assessment Source Code Review
4+ yrs exp Hybrid

Senior Product Security Engineer

Anduril Industries

Fort Collins, CO 151 days ago $144,000$191,000
C/C++ Golang Rust Python Linux Firmware IoT Embedded Systems Reverse Engineering Anti-tamper Cyber Survivability JSIG ICD 503 CSEIG SSECG NIST SP 800-160 CMMC Programmable Logic Devices
8+ yrs exp