Jj

Jj

Principal Product Security Cloud Engineer

Company

Jj

Role

Principal Product Security Cloud Engineer

Location

United States of America

Job type

Full time

Posted

Yesterday

Share this job

Salary

$102k - $177k/yearly

Job description

At Johnson & Johnson, we believe health is everything. Our strength in healthcare innovation empowers us to build a world where complex diseases are prevented, treated, and cured, where treatments are smarter and less invasive, and solutions are personal. Through our expertise in Innovative Medicine and MedTech, we are uniquely positioned to innovate across the full spectrum of healthcare solutions today to deliver the breakthroughs of tomorrow, and profoundly impact health for humanity. Learn more at jnj.com

As guided by Our Credo, Johnson & Johnson is responsible to our employees who work with us throughout the world.  We provide an inclusive work environment where each person is considered as an individual.  At Johnson & Johnson, we respect the diversity and dignity of our employees and recognize their merit.

Job Function:

Technology Enterprise Strategy & Security

Job Sub Function:

Security & Controls

Job Category:

Scientific/Technology

All Job Posting Locations:

Alabama (Any City), Alabama (Any City), Alaska (Any City), Arizona (Any City), Arkansas (Any City), California (Any City), Colorado (Any City), Connecticut (Any City), Danvers, Massachusetts, United States of America, Delaware (Any City), Florida (Any City), Georgia (Any City), Hawaii (Any City), Idaho (Any City), Illinois (Any City), Indiana (Any City), Iowa (Any City), Kansas (Any City), Kentucky (Any City), Louisiana (Any City), Maine (Any City), Maryland (Any City), Massachusetts (Any City), Michigan (Any City), Minnesota (Any City) {+ 27 more}

Job Description:

We are seeking the best talent for a Principal Product Security Cloud Engineer specializing in MS Azure to join our MedTech Product Security team. The role can be Remote-based or located onsite in Danvers, MA or Raritan, NJ. The role must work US East Coast hours and will require up to 10-15% travel.

As the world’s most comprehensive MedTech business, J&J MedTech Companies are building on a century of experience, merging science and technology, to shape the future of health and benefit even more people around the world. With our unparalleled breadth, depth and reach across heart recovery, surgery, orthopedics and interventional solutions, we’re working to profoundly change the way care is delivered. We are in this for life. For more information, visit https://www.jnjmedtech.com/en-US

At Johnson & Johnson, we all belong.

Are you passionate about security and interested in joining a community of collaborative colleagues working in a Patient First! culture? If that’s you, we have an immediate opportunity for a Sr. Manager Medical Devices Product Security to join the Product Cybersecurity team to help ensure security is implemented by design for this top-performing medical device company. This is an exciting opportunity to impact development initiatives that will shape future product development and industry standards. You will own the Product Security process for the products that you will support throughout the product development lifecycle which includes both pre-market and post-market processes engineering teams.  If you are eager to leverage your security risk and compliance skills to make a difference and directly impact patient lives, this could be perfect for you. 

Purpose: The Principal Product Security Cloud Engineer should have MS Azure experience and will be responsible for implementation of J&J’s enterprise Product Security strategy and framework for the Heart Recovery cloud and supporting platforms. This role will join Abiomed, part of Johnson & Johnson MedTech, to provide MS Azuree Cloud technical expertise and strategic leadership in securing Impella heart pump cloud technologies, next-generation cardiac support systems, and connected medical devices to the MS Azure cloud. This role is responsible for delivering MS Azure cloud security architecture, cryptographic controls and Public Key Infrastructure (PKI) , cloud security protections/controls, and threat mitigation techniques to ensure robust, regulatory-compliant security across the product lifecycle.  

Specific responsibilities include supporting heart recovery throughout a new product’s development phases, define product security requirements and recommend security design solutions, complete Quality documentation that includes development of the following: product security plan, security requirements definition, threat modeling, cybersecurity architecture views per FDA pre-Market Guidance for Medical Devices, cybersecurity risk assessment leveraging STRIDE and CVSS, Software Bill of Materials (SBOM), Software Composition Analysis (SCA) against the SBOM, SAST (Static Application Security Testing), DAST (Dynamic Application Security Testing), additional security testing including coordinating internal and external Pen Testing, and development of the cybersecurity risk management report, code analysis and other security testing work as needed. 

Additionally, this position will have post-market MS Azure Cloud responsibilities for Heart Recovery marketed devices delivered monthly that include monitoring for new vulnerabilities (CVEs), developing the monthly cybersecurity documentation with approvals, assisting with patching and remediation plans.  The role may also include supporting and responding to customer security questionnaires and reviewing security language within contractual agreements as needed.

  • Experience with MS Azure cloud security architecture and design

  • Experience with connected medical devices or IOTs connected to the cloud supporting secure data transmission and connectivity

  • Drive alignment of the Cloud security controls and adherence to the J&J Product Security’s overarching framework.

  • Experience creating a Cybersecurity Threat Model and Risk Assessment using STRIDE per element and CVSS frameworks for the Cloud environment.

  • Experience implementing PKI and cryptographic controls.

  • Understanding of FDA Pre-Market Guidance for Medical Device Appendix 1 and how to apply it to Cloud environments to achieve 524B compliance.

  • Define the security requirements required for USA 510k, EU MDR, and Japan PDMA compliance for Cloud solutions

  • Support the Product Security strategy and objectives within Heart Recovery

  • Define and enforce cryptographic protocols for data-at-rest and data-in-transit, ensuring compliance with FDA cybersecurity requirements, NIST 800-175, FIPS 140-3, and IEC 62443.

  • Define and implement key management infrastructure (PKI, cloud-based HSMs)) for device identity, authentication, and software signing.

  • Implementing managed identities across MS Azure services and security VMs and APIs within the Cloud Solution.

  • Implement Zero Trust security for device-to-cloud connectivity, integrating mTLS and continuous authentication models into clinical applications.

  • Oversee secure OTA (over-the-air) update mechanisms, ensuring software and firmware rollbacks, code signing, and supply chain integrity validation.

Primary Duties and Responsibilities

  • Partner with engineering teams (cloud, console) to drive successful adherence to the product security policies, processes, framework and program objectives.
  • Create, update, and improve product security processes for the cloud infrastructure and application.
  • Act as an SME on cybersecurity matters and provide guidance to engineering and cross-functional teams.
  • Advocate for proactive inclusion of cybersecurity controls and processes into all phases of the product life cycle, process improvements, strategic product road map planning.
  • Deliver monthly documentation for pre-market product development activities including security plans, threat models, security requirements, SBOM, and risk management documentation.
  • Drive and monitor post-market vulnerability management activities, with adherence to monthly strict timelines.
  • Perform threat modeling and cybersecurity risk assessment on Cloud infrastructure and applications.
  • Collaborate with the development team to integrate security measures into the CI/CD pipeline and the DevSecOps processes.
  • Continuous improvement of Wiz and MS Defender Scores and monthly reports.
  • Support compliance certification activities, such as SOC2, FedRAMP, ISO 27001, etc.
  • Identify, research, evaluate, and integrate new compliance requirements, industry standards, and best practices into the product security programs.
  • Maintain relationships with Abiomed’s Information Sharing and Analysis Organizations.
  • Guide teams to make decisions that balance business needs with medical device security objectives within the MS Azure cloud.
  • Work across organizational boundaries and exhibit empathy with customers, both internal and external.
  • Perform other related duties and responsibilities, as assigned.

Qualifications

Required: 

  • Bachelor’s degree or equivalent
  • 8-10+ years industry experience in CyberSecurity.
  • 8+ years industry experience within MS Azure cloud
  • Experience working in a Cloud Scrum/Agile Azure DevOps environment.
  • Familiarity with some or all of these tools: Snyk, Veracode, Wiz, JIRA, Confluence.
  • Experience with Containerization technologies such as Docker and Kubernetes.
  • Working knowledge of regulatory standards and compliance frameworks (e.g., NIST Cybersecurity Framework, ISO27001, SOC2, HIPAA, GDPR).
  • Experience with security risk management techniques.
  • Dmonstrated organizational skills, attention to detail, the ability to handle multiple assignments simultaneously in a timely manner and be able to meet assigned deadlines.
  • Committed to working with a sense of urgency and embracing new challenges.
  • Strong communication and interpersonal skills.

Preferred:

  • Experience working in an FDA-regulated environment.
  • Experience working with medical devices connected to the MS Azure Cloud
  • CISM or CISSP certification

Johnson & Johnson is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, age, national origin, disability, protected veteran status or other characteristics protected by federal, state or local law. We actively seek qualified candidates who are protected veterans and individuals with disabilities as defined under VEVRAA and Section 503 of the Rehabilitation Act. 

Johnson & Johnson is committed to providing an interview process that is inclusive of our applicants’ needs. If you are an individual with a disability and would like to request an accommodation, external applicants please contact us via https://www.jnj.com/contact-us/careers , internal employees contact AskGS to be directed to your accommodation resource.

#JNJTECH

#LI-HYBRID

#LI-REMOTE

Required Skills:

Cloud Security, Cybersecurity Risk Assessment, Threat Modeling

 

 

Preferred Skills:

 

 

The anticipated base pay range for this position is :

$102,000.00 - $177,100.00

Additional Description for Pay Transparency:

Subject to the terms of their respective plans, employees are eligible to participate in the Company’s consolidated retirement plan (pension) and savings plan (401(k)).

Subject to the terms of their respective policies and date of hire, employees are eligible for the following time off benefits:
• Vacation –120 hours per calendar year
• Sick time - 40 hours per calendar year; for employees who reside in the State of Colorado –48 hours per calendar year; for employees who reside in the State of Washington –56 hours per calendar year
• Holiday pay, including Floating Holidays –13 days per calendar year
• Work, Personal and Family Time - up to 40 hours per calendar year
• Parental Leave – 480 hours within one year of the birth/adoption/foster care of a child
• Bereavement Leave – 240 hours for an immediate family member: 40 hours for an extended family member per calendar year
• Caregiver Leave – 80 hours in a 52-week rolling period10 days
• Volunteer Leave – 32 hours per calendar year
• Military Spouse Time-Off – 80 hours per calendar year

For additional general information on Company benefits, please go to: - https://www.careers.jnj.com/employee-benefits
Resume ExampleCover Letter Example

Explore more