Professional Program Lead, Penetration Testing Services
Quick summary
- Work type
- Hybrid
- Location
- New Brunswick, NJWest Chester, PAPalm Beach Gardens, FLWarsaw, INRaynham, MA
- Salary
- $94,000–$170,000 / yr
- Posted
- 2 days ago
- Freshness
- Confirmed live today
- Closes
- Sep 29, 2026 (soon)
- Nearby
- 99+ roles within 25 mi
Employer
About Johnson & Johnson
Johnson & Johnson is a multinational corporation operating in three main segments: consumer health products, pharmaceuticals, and medical devices, known for brands like Tylenol, Band-Aid, and Janssen. Industry: Pharmaceuticals & Medical Devices
Johnson & Johnson currently has 73 open roles on FindRole.
Listed pay typically runs $109,000–$177,100 across 68 roles with salary data.
Most-posted roles
- Platform Engineer 5
- Technical Product Owner 4
- Scientist 3
- Technical Platform Owner Manager 3
- Data Engineer 2
At a glance
TL;DR · Professional Program Lead, Penetration Testing Services
Professional, Prog Lead, PenTesting Svcs serves as a seasoned individual contributor within the Cybersecurity function to build and run the penetration testing and offensive security services program for the DePuy Synthes product portfolio. This role establishes testing methodologies, scoping standards, and engagement models to embed Secure by Design verification into the development lifecycle for medical devices, embedded firmware, mobile applications, APIs, and cloud services. The individual manages internal testers and third-party partners while translating technical findings into patient safety and business risks. Key responsibilities include managing the annual testing roadmap, performing threat modeling, and ensuring compliance with frameworks like OWASP, NIST SP 800-115, and MITRE ATT&CK. Required skills include proficiency in Burp Suite, Metasploit, Nmap, Wireshark, Ghidra, and scripting languages such as Python, Bash, and PowerShell to secure the medical device ecosystem.
Skills
What you'll do
- Manage the end-to-end penetration testing program including roadmap planning, prioritization, and resource capacity management.
- Define and maintain security testing methodologies, scoping standards, and reporting templates aligned to industry frameworks.
- Embed security testing gates into the product development lifecycle for medical devices, firmware, mobile apps, and cloud services.
- Execute hands-on assessments across various platforms including wireless protocols, APIs, web applications, and embedded systems.
- Manage third-party penetration testing vendors by developing statements of work and overseeing deliverable quality.
- Triage findings to assess exploitability and translate technical risks into patient safety and business impact.
- Drive remediation efforts with engineering teams by tracking vulnerabilities through retesting and verified closure.
- Produce technical evidence for regulatory submissions such as FDA premarket filings and EU MDR technical files.
What we're looking for
- Bachelor's degree in Computer Science, Cybersecurity, Engineering, Information Systems, or a related technical discipline.
- Advanced degree or specialized cybersecurity education (preferred).
- Minimum 6 years of experience in penetration testing, offensive security, red teaming, or application security assessment.
- Demonstrated experience leading a penetration testing program including methodology definition, scoping standards, and vendor oversight.
- Hands-on proficiency in web, API, mobile, network, wireless, and cloud penetration testing using tools like Burp Suite, Metasploit, and Nmap.
- Proficiency in scripting languages such as Python, Bash, or PowerShell.
- OSCP, OSCE, GPEN, GWAPT, or GXPN certification required or in progress.
- OSWE, GRTP, CRTO, or CISSP certifications (preferred).