Professional Quality Steward

Johnson & Johnson

Confirmed live today High trust
Closes in 5 days Hybrid

Quick summary

Work type
Hybrid
Location
New Brunswick, NJWest Chester, PAPalm Beach Gardens, FLWarsaw, INRaynham, MA
Salary
$79,000–$142,000 / yr
Posted
2 days ago
Freshness
Confirmed live today
Closes
Sep 29, 2026 (soon)

Market check

Salary context

Below market

How this pay compares to similar roles

Similar $184k
This role $110k
$62k most similar roles pay here $239k

This role pays less than 92% of similar roles. Most pay $146,400–$222,000 — the shaded band above. At the midpoint, this role pays about $110k versus about $184k for comparable roles.

Based on 239 similar postings.

Employer

About Johnson & Johnson

Johnson & Johnson is a multinational corporation operating in three main segments: consumer health products, pharmaceuticals, and medical devices, known for brands like Tylenol, Band-Aid, and Janssen. Industry: Pharmaceuticals & Medical Devices

Johnson & Johnson currently has 73 open roles on FindRole.

Listed pay typically runs $109,000–$177,100 across 68 roles with salary data.

Most-posted roles

View all roles at Johnson & Johnson

At a glance

TL;DR · Professional Quality Steward

Professional, Quality Steward The Professional, Quality Steward serves as a dedicated individual contributor within the Cybersecurity function to embed Secure by Design principles into the DePuy Synthes medical device and connected product portfolio. This role acts as a security steward across the total product lifecycle, collaborating with R&D, Engineering, and Regulatory teams to ensure products are safe, secure, and compliant. Key responsibilities include defining security requirements, performing threat modeling for embedded software and mobile applications, managing Software Bills of Materials (SBOMs), and conducting risk assessments aligned to AAMI TIR57 and ISO 14971. The role requires expertise in secure coding practices, SAST/DAST tools, and vulnerability management. Candidates must navigate complex medical device regulatory requirements, including FDA guidance and EU MDR, while managing postmarket vulnerability monitoring and developing customer-facing security artifacts for the medical technology sector.

What you'll do

  • Embed Secure by Design principles into the medical device product development lifecycle from concept to end-of-support.
  • Define and document security requirements, design inputs, and acceptance criteria in collaboration with engineering and R&D teams.
  • Facilitate threat modeling and security architecture reviews for connected devices, mobile applications, and cloud services.
  • Conduct and coordinate product security risk assessments aligned to AAMI TIR57 and ISO 14971 standards.
  • Generate, validate, and maintain Software Bills of Materials (SBOMs) while monitoring third-party components for vulnerabilities.
  • Coordinate penetration testing and security verification activities while triaging findings and tracking remediation to closure.
  • Prepare and review cybersecurity documentation for regulatory submissions including FDA premarket guidance and EU MDR requirements.
  • Manage postmarket vulnerability intelligence, impact analysis, and the creation of customer-facing security artifacts like MDS2 forms.

What we're looking for

  • Bachelor's degree in Computer Science, Cybersecurity, Software/Biomedical/Electrical Engineering, Information Systems, or a related technical discipline.
  • Master's degree in Cybersecurity, Computer Science, or Biomedical Engineering.
  • 4+ years of experience in product security, application security, secure software development, or a related cybersecurity engineering discipline.
  • Demonstrated experience applying Secure by Design principles across a product development lifecycle.
  • Hands-on experience with threat modeling methodologies for embedded, mobile, or connected systems.
  • Working knowledge of secure coding practices, common vulnerability classes (OWASP Top 10, CWE), and application security testing tools.
  • Experience with vulnerability management, including CVE analysis, CVSS scoring, and risk-based remediation prioritization.
  • Familiarity with SBOM generation, formats (SPDX, CycloneDX), and third-party/open-source component risk management.
  • MedTech or medical device experience (preferred).
  • Knowledge of FDA premarket and postmarket guidance, EU MDR, IEC 62304, ISO 14971, ISO 13485, and AAMI TIR57/TIR97 (preferred).
  • CSSLP, GWAPT, OSCP, CEH, CISIS, or equivalent product/application security certification (preferred).

More like this

Similar roles

Principal Product Security Engineer

Johnson & Johnson

Remote (Santa Clara, CA) 36 days ago $118,000–$203,550
Threat Modeling Vulnerability Management Penetration Testing CVSS SBOM Cloud Security AWS Azure C C++ C# Java Python Cryptography Secure Boot ISO 14971 AAMI TIR57 IEC 62304 IEC 81001-5-1 HIPAA GDPR HITRUST ISO 27001 OWASP Top 10 SOC 2 FedRAMP
8+ yrs exp Remote

Principal Med Device Security Engineer

Johnson & Johnson

Danvers, MA 9 days ago $102,000–$177,100
Embedded Security Threat Modeling PKI Zero Trust mTLS Firmware Integrity RTOS SCA SBOM CVSS STRIDE NIST 800-53 FIPS 140-3 IEC 62443 Bluetooth LE Wi-Fi 5G AWS Azure Linux QNX Yocto
10+ yrs exp

Chief SW Engineer

Visa

Austin, TX 48 days ago $195,800–$313,500
GenAI Distributed Systems Cloud-native Architecture Microservices Java Spring REST gRPC API Gateways Containers DevOps Infrastructure Automation Observability Security Caching
10+ yrs exp Hybrid

Quality Specialist, EW

Anduril Industries

Irvine, CA 90 days ago
PCBAs Root Cause Analysis AS9100 ISO9001 IATF 16949 IPC-A-610 IPC-A-620 Lean TQM Jira MES ERP Teamcenter CAD X-ray Inspection Wire Diagrams First Article Inspection (FAI) MRB RMA
2+ yrs exp

Specialist, Quality Engineer, Playwright

Nationwide

Columbus, OH +2 7 days ago $95,500–$177,500
Microsoft Playwright Angular REST API JSON Postman Bruno GitHub Actions Harness Jenkins CI/CD Tosca Agile Performance Testing Regression Testing Test Data Management
4+ yrs exp Hybrid