1

Product Security Code Review Engineer Jobs in Michigan

Driving cross-functional alignment across Engineering, Architecture, and Security * Ensuring ... Oversee execution of threat modeling and design security reviews for high-risk applications and ...

... across Engineering, Architecture, and Security • Ensuring consistent application of security ... reviews for high-risk applications and APIs • Promote adoption of secure design patterns and ...

Product Security Manager

Ann Arbor, MI · On-site

$114K - $194K/yr

Champion a data-driven approach to improving product security by establishing processes that ... Ability to interpret code written in various programming languages * Ability to multi-task, adapt ...

Champion a data-driven approach to improving product security by establishing processes that ... Ability to interpret code written in various programming languages * Ability to multi-task, adapt ...

Product Security Architect

Troy, MI · On-site

$61.50 - $79.50/hr

Work and collaborate with customer, product, engineering, and operations teams to ensure high ... Salary ranges are determined through interviews and a review of the education, experience ...

Champion a data-driven approach to improving product security by establishing processes that ... Ability to interpret code written in various programming languages * Ability to multi-task, adapt ...

Champion a data-driven approach to improving product security by establishing processes that ... Ability to interpret code written in various programming languages * Ability to multi-task, adapt ...

Product Security Architect

Troy, MI · On-site

$61.50 - $79.50/hr

Work and collaborate with customer, product, engineering, and operations teams to ensure high ... Salary ranges are determined through interviews and a review of the education, experience ...

next page

Showing results 1-20

Product Security Code Review Engineer information

What are the key skills and qualifications needed to thrive as a Product Security Code Review Engineer, and why are they important?

To thrive as a Product Security Code Review Engineer, you need a deep understanding of secure coding practices, software development lifecycles, and vulnerability assessment, typically backed by a degree in computer science or a related field. Familiarity with static and dynamic analysis tools, code review platforms, and certifications like CISSP or OSCP is highly valuable. Strong analytical thinking, attention to detail, and effective communication are crucial soft skills for explaining security findings and collaborating with development teams. These skills and qualities are vital to identify, communicate, and mitigate security risks in code, ensuring the overall resilience of software products.

What are some typical challenges faced by Product Security Code Review Engineers when coordinating with development teams?

Product Security Code Review Engineers often encounter challenges in balancing security priorities with project timelines and developer workflows. Effective communication is essential, as engineers must clearly explain vulnerabilities and remediation steps to developers who may have varying levels of security expertise. Additionally, they need to ensure that security recommendations are practical and align with the product's architecture, all while fostering a collaborative environment rather than creating bottlenecks. Building strong relationships with development teams and understanding their processes helps streamline secure code adoption and continuous improvement.

What is the difference between Product Security Code Review Engineer vs Software Security Engineer?

AspectProduct Security Code Review EngineerSoftware Security Engineer
Primary FocusReviewing and analyzing source code for security vulnerabilities in productsDesigning and implementing security measures across software systems
Skills & CertificationsSecure coding, code review, security standards (e.g., OWASP), certifications like CSSLPSecurity architecture, threat modeling, secure coding, certifications like CISSP
Work EnvironmentCollaborates with development teams during product developmentWorks on system-wide security strategies and architecture
Industry UsageCommon in product-based companies, especially in tech and cybersecurityFound in organizations focusing on overall security infrastructure

While both roles focus on security, the Product Security Code Review Engineer primarily reviews source code for vulnerabilities in specific products, whereas the Software Security Engineer develops and implements security strategies across software systems. The roles often overlap but differ in scope and focus.

What is a Product Security Code Review Engineer?

A Product Security Code Review Engineer is a cybersecurity professional responsible for analyzing and reviewing application source code to identify and mitigate security vulnerabilities. They work closely with development teams to ensure secure coding practices, review code for compliance with security standards, and recommend fixes for potential security issues. Their goal is to prevent security breaches by catching vulnerabilities early in the software development lifecycle.
What are popular job titles related to Product Security Code Review Engineer jobs in Michigan? For Product Security Code Review Engineer jobs in Michigan, the most frequently searched job titles are:
What job categories do people searching Product Security Code Review Engineer jobs in Michigan look for? The top searched job categories for Product Security Code Review Engineer jobs in Michigan are:
What cities in Michigan are hiring for Product Security Code Review Engineer jobs? Cities in Michigan with the most Product Security Code Review Engineer job openings:

Principal Product Security Engineer

Johnson & Johnson

Berrien Springs, MI • On-site, Remote

Full-time

Medical, Dental, Vision, Life, Retirement, PTO

Posted yesterday


Johnson & Johnson rating

8.0

Company rating: 8.0 out of 10

Based on 100 frontline employees who took The Breakroom Quiz

35th of 71 rated pharmaceutical


Job description

At Johnson & Johnson, we believe health is everything. Our strength in healthcare innovation empowers us to build a world where complex diseases are prevented, treated, and cured, where treatments are smarter and less invasive, and solutions are personal. Through our expertise in Innovative Medicine and MedTech, we are uniquely positioned to innovate across the full spectrum of healthcare solutions today to deliver the breakthroughs of tomorrow, and profoundly impact health for humanity. Learn more at https://www.jnj.com

Job Function:

Technology Enterprise Strategy & Security

Job Sub Function:

Solution Architecture

Job Category:

Scientific/Technology

All Job Posting Locations:

Albuquerque, New Mexico, United States of America, Albuquerque, New Mexico, United States of America, Alexandria, Virginia, United States, Atlanta, Georgia, United States, Austin, Texas, United States, Baltimore, Maryland, United States, Billings, Montana, United States, Birmingham, Alabama, United States, Bismarck, North Dakota, United States, Bloomington, Illinois, United States, Boise, Idaho, United States, Boulder, Colorado, United States, Bridgeport, Connecticut, United States, Burlington, Vermont, United States, Charleston, South Carolina, United States, Charleston, West Virginia, United States, Charlotte, North Carolina, United States, Chattanooga, Tennessee, United States, Cleveland, Ohio, United States, Concord, New Hampshire, United States, Danvers, Massachusetts, United States of America, Detroit, Michigan, United States, Dover, Delaware, United States, Flagstaff, Arizona, United States, Indianapolis, Indiana, United States {+ 23 more}

Job Description:

We are searching for the best talent for a Principal Product Security Engineer to be located in Danvers, MA or Raritan, NJ. Remote work options may be considered on a case-by-case basis and if approved by the Company.

Are you passionate about security and interested in joining a community of collaborative colleagues working in a Patient First! culture? If that’s you, we have an immediate opportunity for a Principal Product Security Engineer to join the newly formed Product Security team to help ensure security is implemented by design for this top-performing medical device company. This is an exciting opportunity to impact development initiatives that will shape future product development and industry standards. You will own the Product Security process that includes both pre-market and post-market processes engineering teams leverage throughout the product development lifecycle. If you are eager to leverage your security risk and compliance skills to make a difference and directly impact patient lives, this could be perfect for you.

Primary Duties and Responsibilities

  • Being at the office in Danvers MA for a minimum of 3 days per week (for candidates within commutable distance to site).
  • Partner with engineering teams (cloud, console, pump, etc.) to drive successful adherence to Abiomed’s product security policies, processes, program objectives.
  • Create, update, and improve product security processes.
  • Act as a SME on cyber security matters and provide guidance to development teams.
  • Advocate for proactive inclusion of cyber security input into all phases of the product life cycle, process improvements, CAPAs, strategic product road map planning.
  • Deliver documentation for pre-market product development activities including security plans, architecture diagrams, data flow diagrams, threat models, security requirements, Design for Security, SBOM, and risk management documentation.
  • Drive and monitor and post-market vulnerability management activities, with adherence to strict timelines.
  • Support compliance certification activities, such as SOC2, FedRAMP, ISO 27001, etc.
  • Identify, research, evaluate, and integrate new compliance requirements, industry standards, and best practices into the product security programs.
  • Maintain relationships with Abiomed’s Information Sharing and Analysis Organizations.
  • Guide teams to make decisions that balance business needs with medical device security objectives.
  • Work across organizational boundaries and exhibit empathy with customers, both internal and external.
  • Perform other related duties and responsibilities, as assigned.

Qualifications

Required:

  • Bachelor’s degree
  • 5+ years industry experience in Information Security.
  • Working knowledge of regulatory standards and compliance frameworks (e.g., NIST Cybersecurity Framework, ISO27001, SOC2, HIPAA, GDPR).
  • Experience with security risk management techniques.
  • Demonstrated organizational skills, attention to detail, the ability to handle multiple assignments simultaneously in a timely manner and be able to meet assigned deadlines.
  • Committed to working with a sense of urgency and embracing new challenges.
  • Strong communication and interpersonal skills.

Preferred:

  • Experience working in a regulated environment, FDA-regulated

Johnson & Johnson is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, age, national origin, disability, protected veteran status or other characteristics protected by federal, state or local law. We actively seek qualified candidates who are protected veterans and individuals with disabilities as defined under VEVRAA and Section 503 of the Rehabilitation Act.

Johnson and Johnson is committed to providing an interview process that is inclusive of our applicants’ needs. If you are an individual with a disability and would like to request an accommodation, please email the Employee Health Support Center (ra-employeehealthsup@its.jnj.com) or contact AskGS to be directed to your accommodation resource.

#JNJTech

#LIHybrid

#LIRemote

The anticipated base pay range for this position is :

$100,000 - $172,500.

Additional Description for Pay Transparency:

The Company maintains highly competitive, performance-based compensation programs. Under current guidelines, this position is eligible for an annual performance bonus in accordance with the terms of the applicable plan. The annual performance bonus is a cash bonus intended to provide an incentive to achieve annual targeted results by rewarding for individual and the corporation’s performance over a calendar/performance year. Bonuses are awarded at the Company’s discretion on an individual basis. Employees and/or eligible dependents may be eligible to participate in the following Company sponsored employee benefit programs: medical, dental, vision, life insurance, short- and long-term disability, business accident insurance, and group legal insurance. Employees may be eligible to participate in the Company’s consolidated retirement plan (pension) and savings plan (401(k)). Employees are eligible for the following time off benefits: Vacation – up to 120 hours per calendar year Sick time - up to 40 hours per calendar year; for employees who reside in the State of Washington – up to 56 hours per calendar year Holiday pay, including Floating Holidays – up to 13 days per calendar year of Work, Personal and Family Time - up to 40 hours per calendar year Additional information can be found through the link below. http://www.careers.jnj.com/employee-benefits The compensation and benefits information set forth in this posting applies to candidates hired in the United States. Candidates hired outside the United States will be eligible for compensation and benefits in accordance with their local market.


What Johnson & Johnson employees say

Pay

Benefits

Hours and flexibility

Workplace

Get the full story on Breakroom