Principal Product Security Cloud Engineer

Johnson & Johnson

Not Interested
Bookmark
Report This Job

profile Job Location:

Cherry Hill, NJ - USA

profile Monthly Salary: $ 102000 - 177100
Posted on: 9 hours ago
Vacancies: 1 Vacancy

Job Summary

At Johnson & Johnsonwe believe health is everything. Our strength in healthcare innovation empowers us to build aworld where complex diseases are prevented treated and curedwhere treatments are smarter and less invasive andsolutions are our expertise in Innovative Medicine and MedTech we are uniquely positioned to innovate across the full spectrum of healthcare solutions today to deliver the breakthroughs of tomorrow and profoundly impact health for more at

As guided by Our Credo Johnson & Johnson is responsible to our employees who work with us throughout the world. We provide an inclusive work environment where each person is considered as an individual. At Johnson & Johnson we respect the diversity and dignity of our employees and recognize their merit.

Job Function:

Technology Enterprise Strategy & Security

Job Sub Function:

Security & Controls

Job Category:

Scientific/Technology

All Job Posting Locations:

Alabama (Any City) Alabama (Any City) Alaska (Any City) Arizona (Any City) Arkansas (Any City) California (Any City) Colorado (Any City) Connecticut (Any City) Danvers Massachusetts United States of America Delaware (Any City) Florida (Any City) Georgia (Any City) Hawaii (Any City) Idaho (Any City) Illinois (Any City) Indiana (Any City) Iowa (Any City) Kansas (Any City) Kentucky (Any City) Louisiana (Any City) Maine (Any City) Maryland (Any City) Massachusetts (Any City) Michigan (Any City) Minnesota (Any City) 27 more

Job Description:

We are seeking the best talent for a Principal Product Security Cloud Engineer specializing in MS Azure to join our MedTech Product Security team. The role can be Remote-based or located onsite in Danvers MA or Raritan NJ. The role must work US East Coast hours and will require up to 10-15% travel.

As the worlds most comprehensive MedTech business J&J MedTech Companies are building on a century of experience merging science and technology to shape the future of health and benefit even more people around the world. With our unparalleled breadth depth and reach across heart recovery surgery orthopedics and interventional solutions were working to profoundly change the way care is delivered. We are in this for life. For more information visit Johnson & Johnson we all belong.

Are you passionate about security and interested in joining a community of collaborative colleagues working in a Patient First! culture If thats you we have an immediate opportunity for a Sr. Manager Medical Devices Product Security to join the Product Cybersecurity team to help ensure security is implemented by design for this top-performing medical device company. This is an exciting opportunity to impact development initiatives that will shape future product development and industry standards. You will own the Product Security process for the products that you will support throughout the product development lifecycle which includes both pre-market and post-market processes engineering teams. If you are eager to leverage your security risk and compliance skills to make a difference and directly impact patient lives this could be perfect for you.

Purpose: The Principal Product Security Cloud Engineer should have MS Azure experience and will be responsible for implementation of J&Js enterprise Product Security strategy and framework for the Heart Recovery cloud and supporting platforms. This role will join Abiomed part of Johnson & Johnson MedTech to provide MS Azuree Cloud technical expertise and strategic leadership in securing Impella heart pump cloud technologies next-generation cardiac support systems and connected medical devices to the MS Azure cloud. This role is responsible for delivering MS Azure cloud security architecture cryptographic controls and Public Key Infrastructure (PKI) cloud security protections/controls and threat mitigation techniques to ensure robust regulatory-compliant security across the product lifecycle.

Specific responsibilities include supporting heart recovery throughout a new products development phases define product security requirements and recommend security design solutions complete Quality documentation that includes development of the following: product security plan security requirements definition threat modeling cybersecurity architecture views per FDA pre-Market Guidance for Medical Devices cybersecurity risk assessment leveraging STRIDE and CVSS Software Bill of Materials (SBOM) Software Composition Analysis (SCA) against the SBOM SAST (Static Application Security Testing) DAST (Dynamic Application Security Testing) additional security testing including coordinating internal and external Pen Testing and development of the cybersecurity risk management report code analysis and other security testing work as needed.

Additionally this position will have post-market MS Azure Cloud responsibilities for Heart Recovery marketed devices delivered monthly that include monitoring for new vulnerabilities (CVEs) developing the monthly cybersecurity documentation with approvals assisting with patching and remediation plans. The role may also include supporting and responding to customer security questionnaires and reviewing security language within contractual agreements as needed.

  • Experience with MS Azure cloud security architecture and design

  • Experience with connected medical devices or IOTs connected to the cloud supporting secure data transmission and connectivity

  • Drive alignment of the Cloud security controls and adherence to the J&J Product Securitys overarching framework.

  • Experience creating a Cybersecurity Threat Model and Risk Assessment using STRIDE per element and CVSS frameworks for the Cloud environment.

  • Experience implementing PKI and cryptographic controls.

  • Understanding of FDA Pre-Market Guidance for Medical Device Appendix 1 and how to apply it to Cloud environments to achieve 524B compliance.

  • Define the security requirements required for USA 510k EU MDR and Japan PDMA compliance for Cloud solutions

  • Support the Product Security strategy and objectives within Heart Recovery

  • Define and enforce cryptographic protocols for data-at-rest and data-in-transit ensuring compliance with FDA cybersecurity requirements NIST 800-175 FIPS 140-3 and IEC 62443.

  • Define and implement key management infrastructure (PKI cloud-based HSMs)) for device identity authentication and software signing.

  • Implementing managed identities across MS Azure services and security VMs and APIs within the Cloud Solution.

  • Implement Zero Trust security for device-to-cloud connectivity integrating mTLS and continuous authentication models into clinical applications.

  • Oversee secure OTA (over-the-air) update mechanisms ensuring software and firmware rollbacks code signing and supply chain integrity validation.

Primary Duties and Responsibilities

  • Partner with engineering teams (cloud console) to drive successful adherence to the product security policies processes framework and program objectives.
  • Create update and improve product security processes for the cloud infrastructure and application.
  • Act as an SME on cybersecurity matters and provide guidance to engineering and cross-functional teams.
  • Advocate for proactive inclusion of cybersecurity controls and processes into all phases of the product life cycle process improvements strategic product road map planning.
  • Deliver monthly documentation for pre-market product development activities including security plans threat models security requirements SBOM and risk management documentation.
  • Drive and monitor post-market vulnerability management activities with adherence to monthly strict timelines.
  • Perform threat modeling and cybersecurity risk assessment on Cloud infrastructure and applications.
  • Collaborate with the development team to integrate security measures into the CI/CD pipeline and the DevSecOps processes.
  • Continuous improvement of Wiz and MS Defender Scores and monthly reports.
  • Support compliance certification activities such as SOC2 FedRAMP ISO 27001 etc.
  • Identify research evaluate and integrate new compliance requirements industry standards and best practices into the product security programs.
  • Maintain relationships with Abiomeds Information Sharing and Analysis Organizations.
  • Guide teams to make decisions that balance business needs with medical device security objectives within the MS Azure cloud.
  • Work across organizational boundaries and exhibit empathy with customers both internal and external.
  • Perform other related duties and responsibilities as assigned.

Qualifications

Required:

  • Bachelors degree or equivalent
  • 8-10 years industry experience in CyberSecurity.
  • 8 years industry experience within MS Azure cloud
  • Experience working in a Cloud Scrum/Agile Azure DevOps environment.
  • Familiarity with some or all of these tools: Snyk Veracode Wiz JIRA Confluence.
  • Experience with Containerization technologies such as Docker and Kubernetes.
  • Working knowledge of regulatory standards and compliance frameworks (e.g. NIST Cybersecurity Framework ISO27001 SOC2 HIPAA GDPR).
  • Experience with security risk management techniques.
  • Dmonstrated organizational skills attention to detail the ability to handle multiple assignments simultaneously in a timely manner and be able to meet assigned deadlines.
  • Committed to working with a sense of urgency and embracing new challenges.
  • Strong communication and interpersonal skills.

Preferred:

  • Experience working in an FDA-regulated environment.
  • Experience working with medical devices connected to the MS Azure Cloud
  • CISM or CISSP certification

Johnson & Johnson is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race color religion sex sexual orientation gender identity age national origin disability protected veteran status or other characteristics protected by federal state or local law. We actively seek qualified candidates who are protected veterans and individuals with disabilities as defined under VEVRAA and Section 503 of the Rehabilitation Act.

Johnson & Johnson is committed to providing an interview process that is inclusive of our applicants needs. If you are an individual with a disability and would like to request an accommodation external applicants please contact us via internal employees contact AskGS to be directed to your accommodation resource.

#JNJTECH

#LI-HYBRID

#LI-REMOTE

Required Skills:

Cloud Security Cybersecurity Risk Assessment Threat Modeling

Preferred Skills:

The anticipated base pay range for this position is :

$102000.00 - $177100.00

Additional Description for Pay Transparency:

Subject to the terms of their respective plans employees are eligible to participate in the Companys consolidated retirement plan (pension) and savings plan (401(k)).

Subject to the terms of their respective policies and date of hire employees are eligible for the following time off benefits:
Vacation 120 hours per calendar year
Sick time - 40 hours per calendar year; for employees who reside in the State of Colorado 48 hours per calendar year; for employees who reside in the State of Washington 56 hours per calendar year
Holiday pay including Floating Holidays 13 days per calendar year
Work Personal and Family Time - up to 40 hours per calendar year
Parental Leave 480 hours within one year of the birth/adoption/foster care of a child
Bereavement Leave 240 hours for an immediate family member: 40 hours for an extended family member per calendar year
Caregiver Leave 80 hours in a 52-week rolling period10 days
Volunteer Leave 32 hours per calendar year
Military Spouse Time-Off 80 hours per calendar year

For additional general information on Company benefits please go to: - Experience:

Staff IC

At Johnson & Johnsonwe believe health is everything. Our strength in healthcare innovation empowers us to build aworld where complex diseases are prevented treated and curedwhere treatments are smarter and less invasive andsolutions are our expertise in Innovative Medicine and MedTech we are unique...
View more view more

About Company

Company Logo

About Johnson & Johnson A t Johnson & Johnson, we believe good health is the foundation of vibrant lives, thriving communities and forward progress. That’s why for more than 130 years, we have aimed to keep people well at every age and every stage of life. Today, as the world’s larges ... View more

View Profile View Profile