2

Remote Medical Device Cybersecurity Security Jobs

... cybersecurity team is recruiting for an experienced Principal Product Security Engineer ... The role can be remote-based or located onsite in Danvers, MA or Raritan, NJ. This role will ...

... cybersecurity team is recruiting for an experienced Principal Product Security Engineer ... The role can be remote-based or located onsite in Danvers, MA or Raritan, NJ. This role will ...

Be Seen First

Remote (must live within territory - northern California, Oregon, or Washington) Hire Type ... Proven B2B sales experience (medical device experience preferred but not required) * Experience ...

QA/RA Consultant

Boston, MA · On-site +1

$130K - $150K/yr

Deep understanding of medical device cybersecurity. * Experience as quality management representative in regulated environments. * Experience with regulatory and Notified Body submission requirements.

Remote Medical Coder

$19.25 - $24.25/hr

... Medical Coder to join our healthcare consulting practice. The role is fully remote within the US ... Ability to secure a DOD security clearance, must not have been unfavorably removed from a ...

Director - Product Security

Dallas, TX · On-site +1

$230K - $241K/yr

This executive will lead a dedicated team to manage the cybersecurity posture of our medical device ... Houston, TX is the ideal location for this role, but this is open to Remote opportunities for well ...

Director - Product Security

Charlotte, NC · On-site +1

$227K - $238K/yr

This executive will lead a dedicated team to manage the cybersecurity posture of our medical device ... Houston, TX is the ideal location for this role, but this is open to Remote opportunities for well ...

Director - Product Security

Chicago, IL · On-site +1

$240K - $251K/yr

This executive will lead a dedicated team to manage the cybersecurity posture of our medical device ... Houston, TX is the ideal location for this role, but this is open to Remote opportunities for well ...

Director - Product Security

Minneapolis, MN · On-site +1

$243K - $254K/yr

This executive will lead a dedicated team to manage the cybersecurity posture of our medical device ... Houston, TX is the ideal location for this role, but this is open to Remote opportunities for well ...

Director - Product Security

Orlando, FL · On-site +1

$217K - $227K/yr

This executive will lead a dedicated team to manage the cybersecurity posture of our medical device ... Houston, TX is the ideal location for this role, but this is open to Remote opportunities for well ...

Director - Product Security

Atlanta, GA · On-site +1

$224K - $234K/yr

This executive will lead a dedicated team to manage the cybersecurity posture of our medical device ... Houston, TX is the ideal location for this role, but this is open to Remote opportunities for well ...

Director - Product Security

Phoenix, AZ · On-site +1

$231K - $242K/yr

This executive will lead a dedicated team to manage the cybersecurity posture of our medical device ... Houston, TX is the ideal location for this role, but this is open to Remote opportunities for well ...

Director - Product Security

Houston, TX · On-site +1

$222K - $233K/yr

This executive will lead a dedicated team to manage the cybersecurity posture of our medical device ... Houston, TX is the ideal location for this role, but this is open to Remote opportunities for well ...

next page

Showing results 1-20

Remote Medical Device Cybersecurity Security information

See salary details

$40.5K

$122.9K

$180K

How much do remote medical device cybersecurity security jobs pay per year?

As of Jun 30, 2026, the average yearly pay for remote medical device cybersecurity security in the United States is $122,890.00, according to ZipRecruiter salary data. Most workers in this role earn between $102,000.00 and $142,000.00 per year, depending on experience, location, and employer.

What are the key skills and qualifications needed to thrive as a Remote Medical Device Cybersecurity Specialist, and why are they important?

To excel as a Remote Medical Device Cybersecurity Specialist, you need expertise in cybersecurity principles, risk assessment, and knowledge of medical device regulations, often supported by a degree in cybersecurity, computer science, or a related field. Familiarity with tools like vulnerability scanners, SIEM systems, and relevant certifications such as CISSP or CompTIA Security+ is typically required. Strong analytical thinking, attention to detail, and effective communication are crucial soft skills for collaborating with cross-functional teams and explaining complex risks to stakeholders. These competencies are vital to protect sensitive patient data, ensure device integrity, and maintain compliance in a highly regulated healthcare environment.

Can I work fully remote in cyber security?

Remote medical device cybersecurity roles, such as those involving security analysis, vulnerability assessment, and compliance, are often available as fully remote positions. These jobs typically require strong technical skills, certifications like CISSP or CISA, and familiarity with remote collaboration tools, making remote work feasible for qualified professionals.

Can you make $500,000 a year in cyber security?

Remote Medical Device Cybersecurity professionals can potentially earn $500,000 annually with extensive experience, advanced certifications, and leadership roles such as security managers or directors. High salaries are often associated with specialized skills, industry demand, and working in organizations with large or critical medical device portfolios.

What is a Remote Medical Device Cybersecurity Specialist?

A Remote Medical Device Cybersecurity Specialist is a professional who works remotely to protect medical devices and related systems from cyber threats. They assess risks, develop security protocols, and ensure compliance with regulations to safeguard patient data and ensure device functionality. These specialists collaborate with healthcare providers, manufacturers, and IT teams to identify vulnerabilities and implement effective security measures. Their work helps prevent unauthorized access, data breaches, and cyberattacks on medical devices connected to hospital networks or used in patient care.

What are some common challenges faced by professionals in remote medical device cybersecurity roles, and how can they be addressed?

One of the main challenges in remote medical device cybersecurity roles is ensuring secure communication and data protection when working outside of a centralized office. Professionals must stay vigilant against cyber threats targeting confidential medical data and device functionality. Effective collaboration with cross-functional teams, such as IT, regulatory, and clinical engineering, is essential to address vulnerabilities and implement security protocols. Staying updated on evolving regulations and emerging threats is also crucial for success in this dynamic field.

What is the 80 20 rule in cyber security?

In cybersecurity, the 80/20 rule suggests that approximately 80% of security issues stem from 20% of vulnerabilities or threats. For a remote medical device cybersecurity specialist, focusing on the most critical vulnerabilities can improve security efficiency and effectiveness, often using risk assessment tools and prioritization strategies.

Can I make $200 a year in cyber security?

A remote medical device cybersecurity specialist typically earns significantly more than $200 annually, with entry-level salaries often starting around $60,000 per year and increasing with experience and certifications. Earning $200 per year would be highly unlikely in this field, as it is a professional role requiring specialized skills in security protocols, risk assessment, and compliance. Most cybersecurity jobs, including those focused on medical devices, offer full-time salaries rather than minimal income levels.

What is the difference between Remote Medical Device Cybersecurity Security vs Remote Medical Device Quality Assurance?

AspectRemote Medical Device Cybersecurity SecurityRemote Medical Device Quality Assurance
Primary FocusProtecting medical devices from cyber threats and vulnerabilitiesEnsuring medical devices meet quality standards and regulatory compliance
Required CertificationsCybersecurity certifications (e.g., CISSP, CISA), medical device security trainingQuality assurance certifications (e.g., CQE, ISO 13485 auditor)
Work EnvironmentRemote, often collaborating with IT and security teamsRemote or on-site, working with engineering and regulatory teams
Industry UsageUsed across healthcare, medical device manufacturing, and cybersecurity sectorsPrimarily in medical device manufacturing and regulatory compliance

Remote Medical Device Cybersecurity Security focuses on safeguarding medical devices from cyber threats, while Remote Medical Device Quality Assurance ensures devices meet safety and quality standards. Both roles are essential in the medical device industry but differ in their core responsibilities and certifications.

More about Remote Medical Device Cybersecurity Security jobs
What cities are hiring for Remote Medical Device Cybersecurity Security jobs? Cities with the most Remote Medical Device Cybersecurity Security job openings:
What are the most commonly searched types of Medical Device Cybersecurity Security jobs? The most popular types of Medical Device Cybersecurity Security jobs are:
What states have the most Remote Medical Device Cybersecurity Security jobs? States with the most job openings for Remote Medical Device Cybersecurity Security jobs include:
Infographic showing various Remote Medical Device Cybersecurity Security job openings in the United States as of June 2026, with employment types broken down into 74% Full Time, 3% Part Time, and 23% Contract. Highlights an 37% Physical, 3% Hybrid, and 60% Remote job distribution, with an average salary of $122,890 per year, or $59.1 per hour.

Principal Med Device Security Engineer

Johnson & Johnson

Danvers, MA • On-site, Remote

Full-time

Retirement, PTO

Posted 28 days ago


Key responsibilities

  • Implement product security strategy and framework across the Heart Recovery portfolio of medical devices and supporting platforms.

  • Deliver security architecture, cryptographic controls, embedded system protections, and threat mitigation techniques throughout the product lifecycle.

  • Monitor for new vulnerabilities, assist with patching and remediation plans, and respond to customer security questionnaires and contractual security language for marketed devices.


Johnson & Johnson rating

8.2

Company rating: 8.2 out of 10

Based on 108 frontline employees who took The Breakroom Quiz

29th of 73 rated pharmaceutical


Job description

At Johnson & Johnson,we believe health is everything. Our strength in healthcare innovation empowers us to build aworld where complex diseases are prevented, treated, and cured,where treatments are smarter and less invasive, andsolutions are personal.Through our expertise in Innovative Medicine and MedTech, we are uniquely positioned to innovate across the full spectrum of healthcare solutions today to deliver the breakthroughs of tomorrow, and profoundly impact health for humanity.Learn more at jnj.com

As guided by Our Credo, Johnson & Johnson is responsible to our employees who work with us throughout the world. We provide an inclusive work environment where each person is considered as an individual. At Johnson & Johnson, we respect the diversity and dignity of our employees and recognize their merit.

Job Function:

Technology Enterprise Strategy & Security

Job Sub Function:

Security & Controls

Job Category:

Scientific/Technology

All Job Posting Locations:

Alabama (Any City), Alabama (Any City), Alaska (Any City), Arizona (Any City), Arkansas (Any City), California (Any City), Colorado (Any City), Connecticut (Any City), Danvers, Massachusetts, United States of America, Delaware (Any City), Florida (Any City), Georgia (Any City), Hawaii (Any City), Idaho (Any City), Illinois (Any City), Indiana (Any City), Iowa (Any City), Kansas (Any City), Kentucky (Any City), Louisiana (Any City), Maine (Any City), Maryland (Any City), Massachusetts (Any City), Michigan (Any City), Minnesota (Any City) {+ 27 more}

Job Description:

Johnson & Johnson's MedTech cybersecurity team is recruiting for an experienced Principal Product Security Engineer. The role can be remote-based or located onsite in Danvers, MA or Raritan, NJ. This role will require up to 10% travel.

Are you passionate about security and interested in joining a community of collaborative colleagues working in a Patient First! culture? If that's you, we have an immediate opportunity for a Principal Product Security Engineer to join the Product Cybersecurity team to help ensure security is implemented by design for this top-performing medical device company. This is an exciting opportunity to impact development initiatives that will shape future product development and industry standards. You will own the Product Security process for the products that you will support throughout the product development lifecycle which includes both pre-market and post-market processes engineering teams. If you are eager to leverage your security risk and compliance skills to make a difference and directly impact patient lives, this could be perfect for you.

Purpose:

The Principal Product Security Engineer will be responsible for implementation of J&J's enterprise Product Security strategy and framework throughout the Heart Recovery portfolio of medical devices and supporting platforms. This role will join Abiomed, part of Johnson & Johnson MedTech, to provide technical expertise and strategic leadership in securing Impella heart pump technologies, next-generation cardiac support systems, and connected medical devices. This role is responsible for delivering security architecture, cryptographic controls, embedded system protections/controls, and threat mitigation techniques to ensure robust, regulatory-compliant security across the product lifecycle.

Specific responsibilities include supporting heart recovery throughout a new product's development phases, review product security requirements and recommend security design solutions, complete Quality documentation, threat modelling, coordinate third-party penetration testing, software architecture review and design recommendations, code analysis and other security testing work as needed.

Additionally, this position will have post market responsibilities for Heart Recovery marketed devices include monitoring for new vulnerabilities, assisting with patching and remediation plans, as well as responding to customer security questionnaires and reviewing security language within contractual agreements as needed.

  • Drive alignment to J&J Product Security's overarching framework.
  • Support the Product Security strategy and objectives within Heart Recovery
  • Define and implement secure boot, firmware integrity validation, and anti-tamper mechanisms to protect Heart Recovery Device firmware against unauthorized modification.
  • Enforce cryptographic protocols for data-at-rest and data-in-transit, ensuring compliance with FDA cybersecurity requirements, NIST 800-175, FIPS 140-3, and IEC 62443.
  • Define and implement key management infrastructure (PKI, HSMs, TPMs, and secure enclave integration) for device identity, authentication, and software signing.
  • Develop real-time vulnerability assessment techniques for detecting security flaws in wireless communications (Bluetooth LE, NFC, Wi-Fi, 5G, proprietary RF) used in Heart Recovery's medical devices.
  • Implement Zero Trust security for device-to-cloud connectivity, integrating mTLS and continuous authentication models into clinical applications.
  • Oversee secure OTA (over-the-air) update mechanisms, ensuring firmware rollbacks, code signing, and supply chain integrity validation.
  • Embedded Security & Secure Development Lifecycle:
  • Lead Secure Development Lifecycle practices, integrating threat modeling, static/dynamic analysis, fuzz testing, and formal verification into the development process.
  • Work with R&D Engineering to define hardware security architecture, including trust zones, hardware root of trust (HRoT), and secure microcontroller protections
  • Implement memory safety strategies to mitigate buffer overflows, side-channel attacks, and execution vulnerabilities in real-time operating systems (RTOS) and bare-metal firmware.
  • Respond to customer cybersecurity questionnaires and contractual language for post-market medical devices under your responsibility as necessary.

Qualifications

Required:

  • 8+ years industry experience in Information Security
  • 5+ years experience with embedded system, IOT, or medical device cybersecurity
  • Bachelor's degree or equivalent
  • Experience generating Threat models without the use of threat modeling tools
  • Experience performing risk assessments utilizing CVSS 3.1 or higher, with STRIDE per element
  • Ability to write technical security requirements for embedded systems and web platforms based on the latest regulations
  • Understanding and execution of third-party penetration testing, vulnerability scanning, CVSS and/or other general security testing principles
  • Experience supporting regulatory security submissions, ensuring compliance with FDA Cybersecurity Guidance (2025), EU MDR, NIST 800-53, IMDRF, and AAMI TIR57.
  • Knowledge of real-time operating systems hardening techniques
  • Knowledge of cloud security principles
  • Ability to generate SBOMs from Software source code and Binaries, Firmware, and Operating Systems
  • Ability to generate pre-market risk assessments against the threat model leveraging STRIDE and post-market risk assessments via SCA SBOM scans.
  • Ability to generate the security architecture views for medical devices that could include: Global System View, Multi-Patient Harm View, Updateability/Patchability view and, detailing system boundaries, data flows, and external interactions to show risk mitigation, ensuring transparency, and supporting post-market management
  • Ability to translate technical security requirements into solutions
  • Ability to provide secure coding recommendations and execute reviews
  • Data privacy experience, including HIPAA and GDPR
  • Understanding of industry standards and certifications such as HITRUST & ISO 27001
  • Ability to work autonomously and proactively seek out product security opportunities within heart recovery
  • Ability to lead large projects and proven ability to track to project plan timelines from a security perspective
  • Ability to create and deliver cybersecurity awareness campaigns and other communications
  • Creative problem-solving skills
  • Customer focus (internal & external)
  • Excellent communication and collaboration skills, able to network, interface and influence at all levels of the organization, cross sector, cross-functionally and globally
  • Strong leadership skills

Preferred:

  • Experience leading or participating in formal security audits
  • Experience with Operating Systems such as QNX QOS, Yocto, Linux Ubuntu. Alpine
  • Familiarity with FDA and/or other global regulatory cybersecurity guidance requirements and submission process
  • Experience with web applications and server hardening (i.e. AWS, Azure) including knowledge of OWASP Top 10 and blue teaming techniques
  • Experience in cybersecurity pre-sales
  • Software development experience
  • CISSP, CISM, or other security certification
  • MS and/or advanced degree

Johnson & Johnson is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, age, national origin, disability, protected veteran status or other characteristics protected by federal, state or local law. We actively seek qualified candidates who are protected veterans and individuals with disabilities as defined under VEVRAA and Section 503 of the Rehabilitation Act.

Johnson & Johnson is committed to providing an interview process that is inclusive of our applicants' needs. If you are an individual with a disability and would like to request an accommodation, please contact us via https://www.jnj.com/contact-us/careers or contact AskGS to be directed to your accommodation resource.

#JNJTECH

Required Skills:

Product Security

Preferred Skills:

The anticipated base pay range for this position is :

$102,000.00 - $177,100.00

Additional Description for Pay Transparency:

Subject to the terms of their respective plans, employees are eligible to participate in the Company's consolidated retirement plan (pension) and savings plan (401(k)).
Subject to the terms of their respective policies and date of hire, employees are eligible for the following time off benefits:
Vacation -120 hours per calendar year
Sick time - 40 hours per calendar year; for employees who reside in the State of Colorado -48 hours per calendar year; for employees who reside in the State of Washington -56 hours per calendar year
Holiday pay, including Floating Holidays -13 days per calendar year
Work, Personal and Family Time - up to 40 hours per calendar year
Parental Leave - 480 hours within one year of the birth/adoption/foster care of a child
Bereavement Leave - 240 hours for an immediate family member: 40 hours for an extended family member per calendar year
Caregiver Leave - 80 hours in a 52-week rolling period10 days
Volunteer Leave - 32 hours per calendar year
Military Spouse Time-Off - 80 hours per calendar year
For additional general information on Company benefits, please go to: - https://www.careers.jnj.com/employee-benefits

What Johnson & Johnson employees say

Pay

Benefits

Hours and flexibility

Workplace

Get the full story on Breakroom