Johnson & Johnson’s MedTech Product Security team is recruiting for an experienced Product Security Senior Manager role to be based in Milpitas or Irvine, CA. Remote work options may be considered on a case-by-case basis and if approved by the Company. This may require up to 10% travel.
At Johnson & Johnson, we believe health is everything. Our strength in healthcare innovation empowers us to build a world where complex diseases are prevented, treated, and cured, where treatments are smarter and less invasive, and solutions are personal. Through our expertise in Innovative Medicine and MedTech, we are uniquely positioned to innovate across the full spectrum of healthcare solutions today to deliver the breakthroughs of tomorrow, and profoundly impact health for humanity. Learn more at https://www.jnj.com/.
For more than 130 years, diversity, equity & inclusion (DEI) has been a part of our cultural fabric at Johnson & Johnson and woven into how we do business every day. Rooted in Our Credo, the values of DEI fuel our pursuit to create a healthier, more equitable world. Our diverse workforce and culture of belonging accelerate innovation to solve the world’s most pressing healthcare challenges.
We know that the success of our business – and our ability to deliver meaningful solutions – depends on how well we understand and meet the diverse needs of the communities we serve. Which is why we foster a culture of inclusion and belonging where all perspectives, abilities and experiences are valued and our people can reach their potential.
At Johnson & Johnson, we all belong.
The Product Security Senior Manager will be responsible for implementation of J&J’s enterprise Product Security strategy and framework throughout Johnson & Johnson Surgical Vision (JJSV) medical device portfolio. This includes identifying key strategy and goals, collaborating with internal organizations on existing process and policy enhancements, creating and communicating metrics to senior management, identifying communications plans and raising overall awareness of the capability. Specific responsibilities include supporting JJSV throughout a new product’s development phases, review product security requirements and recommend security design solutions, help complete Quality documentation, threat modelling, penetration testing, software architecture review and design recommendations, code analysis and other security testing or work as needed.
Additionally, post market responsibilities for JJSV marketed devices include monitoring for new vulnerabilities, assisting with patching and remediation plans, as well as responding to all customer security questionnaires and reviewing security language within contractual agreements.
- Drive adherence to J&J Product Security’s overarching framework:
- Champion Product Security strategy and objectives within JJSV
- Partner with internal organizations to enhance existing processes and policies
- Create and present Product Security metrics to management
- Responsible and accountable to implement and enforce Product Security governance model for JJSV pre and post market medical devices.
- Perform automated code scanning and coordinate formal security testing.
- Respond to customer cybersecurity questionnaires and contractual language for all post-market medical devices.
- Other MedTech cybersecurity related duties as needed