Johnson & Johnson New

60 Johnson Johnson Senior Security Engineer Jobs Hiring Near You

Senior Salesforce Engineer

Raritan, NJ · Hybrid

$128K - $157K/yr

At Johnson & Johnson,we believe health is everything. Our strength in healthcare innovation ... Raritan, New Jersey, United States of America We are looking for a Senior Salesforce Engineer who ...

Senior Manufacturing Engineer

Irving, TX · On-site

$87K - $119K/yr

At Johnson & Johnson,we believe health is everything. Our strength in healthcare innovation ... for a Senior Manufacturing Engineer, to join the team. The location for this position is Irving ...

next page

Showing results 1-20

Johnson & Johnson New Jobs Information

Do workers at Johnson & Johnson get paid breaks?

Yes. Most people get paid breaks.
77% of people say they get paid breaks.
Based on data from 62 people who took the Breakroom Quiz between December 2024 and August 2026.

Does Johnson & Johnson pay people when they’re sick?

Yes. Most people get paid when they’re sick.
77% of people say they would get paid if they were sick but scheduled to work.
Based on data from 39 people who took the Breakroom Quiz between August 2025 and August 2026.

At Johnson & Johnson, are sick days and vacation days separate paid time off?

Sick days and vacation days are separate paid time off.
68% of people say they don’t have to use vacation days when they’re out sick.
Based on data from 34 people who took the Breakroom Quiz between August 2025 and August 2026.

Is the health insurance from Johnson & Johnson affordable enough for their workers?

Most people say the health insurance costs are okay.
95% of people say the health insurance costs are okay
Based on data from 63 people who took the Breakroom Quiz between March 2025 and August 2026.

Do people get paid time off at Johnson & Johnson?

Most people get paid time off work.
90% of people say they get paid time off.
Based on data from 41 people who took the Breakroom Quiz between August 2025 and August 2026.

How far ahead of time do people find out their work schedule?

Most people find out their schedule less than four weeks ahead of time.
  • 79% of people with changing schedules find out their shifts one week or less ahead of time.
  • 11% of people with changing schedules find out their shifts two weeks ahead of time.
  • 0% of people with changing schedules find out their shifts three weeks ahead of time.
  • 11% of people with changing schedules find out their shifts four weeks or more ahead of time.

Based on data from 19 people who took the Breakroom Quiz between December 2024 and April 2026.

Do workers at Johnson & Johnson worry about hours?

Most people don’t worry about getting enough hours.
91% of people report they don’t worry about getting enough hours.
Based on data from 55 people who took the Breakroom Quiz between December 2024 and June 2026.

Do Johnson & Johnson workers get to choose the shifts they work?

Most people don’t get to choose which shifts they work.
69% report that they don’t have enough control over which shifts they work.
Based on data from 51 people who took the Breakroom Quiz between December 2024 and June 2026.

How easy is it for Johnson & Johnson workers to change shifts?

Some people find it hard to change shifts.
41% of people report that it’s hard to change shifts if they need to.
Based on data from 32 people who took the Breakroom Quiz between December 2024 and April 2026.

How easy is it to get time off at Johnson & Johnson?

Most people find it easy to get time off.
94% of people report it’s easy to get time off.
Based on data from 33 people who took the Breakroom Quiz between August 2025 and August 2026.

Do Johnson & Johnson managers change schedules at the last minute?

Most managers don’t change people’s schedules at the last minute.
83% of people say their manager doesn’t change their shift schedule at the last minute.
Based on data from 30 people who took the Breakroom Quiz between June 2025 and June 2026.

Do jobs at Johnson & Johnson spill into time workers aren’t paid for?

Rarely. The job doesn't usually spill into unpaid time.
18% of people report that their job takes up time that they don’t get paid for.
Based on data from 60 people who took the Breakroom Quiz between December 2024 and June 2026.

How easy is it to take sick days at Johnson & Johnson?

Most people find it easy to take sick days.
82% of people report that it’s easy to take time off if they are sick.
Based on data from 39 people who took the Breakroom Quiz between August 2025 and August 2026.

Is a Johnson & Johnson job good for students?

Most students say this is a good place to work if you’re studying.
100% of students report this is a good place to work if you’re studying.
Based on data from 15 people who took the Breakroom Quiz between January 2025 and June 2026.

Is working at Johnson & Johnson good if you’re a parent or caregiver?

Most parents and caregivers say this is a good place to work.
72% of people who care for a child or other relative report this is a good place to work.
Based on data from 32 people who took the Breakroom Quiz between December 2024 and July 2026.

Do people at Johnson & Johnson feel treated with respect by their managers?

Most people feel treated with respect by their managers.
95% of people say they’re treated with respect by their managers.
Based on data from 37 people who took the Breakroom Quiz between August 2025 and August 2026.

Do people at Johnson & Johnson get to take their breaks without interruption?

Most people get breaks without interruption.
97% of people report that they get to take their breaks without interruption.
Based on data from 31 people who took the Breakroom Quiz between August 2025 and August 2026.

Is it stressful to work at Johnson & Johnson?

Most people feel stressed here.
73% of people say they often feel stressed at work.
Based on data from 40 people who took the Breakroom Quiz between August 2025 and August 2026.

Do people at Johnson & Johnson enjoy their jobs?

Most people enjoy their job.
72% of people report they enjoy their job.
Based on data from 36 people who took the Breakroom Quiz between August 2025 and August 2026.

Do people at Johnson & Johnson recommend working with their team?

Only some people recommend working with their team.
41% of people report that they wouldn’t recommend working with their immediate team to a friend.
Based on data from 41 people who took the Breakroom Quiz between August 2025 and August 2026.

Do people get enough training when they start at Johnson & Johnson?

Most people got enough training when they started.
79% of people report they got enough training when they started working here.
Based on data from 39 people who took the Breakroom Quiz between August 2025 and August 2026.

Do people get support to advance at Johnson & Johnson?

Only some people are given support to advance their career here.
In the last year, 39% of people report not being given support to advance their career here.
Based on data from 33 people who took the Breakroom Quiz between August 2025 and August 2026.

Do people think Johnson & Johnson’s headquarters understands what’s happening where they work?

Some people think headquarters doesn’t understand what’s happening where they work.
67% of people think that this employer’s headquarters or owners don’t have a good understanding of what’s really happening where they work.
Based on data from 36 people who took the Breakroom Quiz between August 2025 and August 2026.

Do workers feel well informed about how Johnson & Johnson is doing?

Only some people feel well informed about how the company is doing.
35% of people feel that they aren’t kept well informed about how the company is doing as a whole.
Based on data from 37 people who took the Breakroom Quiz between August 2025 and August 2026.
Infographic showing various Senior Security Engineer job openings at Johnson Johnson in the United States as of August 2026, with employment types broken down into 100% Full Time. Highlights an 89% Physical, 3% Hybrid, and 8% Remote job distribution.

Principal Product Security Engineer

Johnson & Johnson

Santa Clara, CA

Full-time

Retirement, PTO

Posted 6 days ago


Johnson & Johnson rating

8.3

Company rating: 8.3 out of 10

Based on 112 frontline employees who took The Breakroom Quiz

25th of 86 rated pharmaceutical


Job description

At Johnson & Johnson,we believe health is everything. Our strength in healthcare innovation empowers us to build aworld where complex diseases are prevented, treated, and cured,where treatments are smarter and less invasive, andsolutions are personal.Through our expertise in Innovative Medicine and MedTech, we are uniquely positioned to innovate across the full spectrum of healthcare solutions today to deliver the breakthroughs of tomorrow, and profoundly impact health for humanity.Learn more at jnj.com

As guided by Our Credo, Johnson & Johnson is responsible to our employees who work with us throughout the world. We provide an inclusive work environment where each person is considered as an individual. At Johnson & Johnson, we respect the diversity and dignity of our employees and recognize their merit.

Job Function:

Technology Enterprise Strategy & Security

Job Sub Function:

Security & Controls

Job Category:

People Leader

All Job Posting Locations:

Santa Clara, California, United States of America

Job Description:

Johnson & Johnson's MedTech cybersecurity team is recruiting for an experienced Principal Product Security Engineer to be based in Santa Clara, CA. This may require up to 10% travel.

Relocation to the San Francisco Bay area will be considered on a case-by-case basis.

About MedTech

Fueled by innovation at the intersection of biology and technology, we're developing the next generation of smarter, less invasive, more personalized treatments.

Your unique talents will help patients on their journey to wellness. Learn more at https://www.jnj.com/medtech.

Position Summary


The Principal Product Security Engineer is a senior technical cybersecurity expert responsible for securing connected medical devices, robotic systems, embedded platforms, cloud services, and supporting digital health ecosystems throughout the product lifecycle.

This role provides hands-on technical leadership across multiple product teams by identifying cybersecurity risks, developing security requirements, performing security assessments, guiding remediation, and verifying that security controls are appropriately implemented within regulated medical device products.

Primary Responsibilities

Technical Product Security Leadership

  • Serve as the cybersecurity technical lead for complex medical device and digital health product development programs.
  • Provide technical direction on security design, implementation, verification, vulnerability remediation, and risk treatment activities.
  • Drive security-by-design practices throughout the product development lifecycle.
  • Influence engineering tradeoffs by balancing cybersecurity risk, patient safety, clinical workflow, usability, and product constraints.
  • Mentor software, systems, cloud, and embedded engineering teams on secure development practices.

Security Engineering

  • Develop, review, and maintain cybersecurity requirements for embedded systems, software applications, cloud services, and connected medical devices.
  • Perform detailed security design reviews, implementation assessments, configuration reviews, and attack surface analysis.
  • Evaluate authentication, authorization, cryptography, secure boot, key management, access control, logging, monitoring, update mechanisms, and operating system hardening implementations.
  • Provide practical secure coding and design recommendations to engineering teams.
  • Identify design weaknesses early and partner with teams to implement technically feasible mitigations.

Threat Modeling and Cybersecurity Risk Assessment

  • Lead threat modeling activities for products, platforms, system features, and supporting services.
  • Analyze threats, vulnerabilities, abuse cases, misuse cases, and chained attack paths.
  • Perform cybersecurity risk assessments and evaluate risk control effectiveness.
  • Assess potential impact to patient safety, clinical operations, confidentiality, integrity, availability, and product performance.
  • Develop risk-based mitigation strategies and support the objective evidence needed to demonstrate control effectiveness.

Security Testing and Validation

  • Perform or coordinate security testing activities including static analysis, software composition analysis, vulnerability scanning, fuzz testing, penetration testing, secure configuration reviews, and architecture assessments.
  • Analyze test results and translate findings into clear, actionable remediation plans.
  • Support independent security assessments and third-party penetration testing activities.
  • Verify the effectiveness of implemented security controls and compensating controls.
  • Ensure security testing outputs are traceable to product risks, requirements, and release decisions.

Vulnerability Management and Post-Market Security

  • Analyze vulnerabilities affecting commercial, open-source, cloud, infrastructure, and internally developed software components.
  • Evaluate exploitability and product impact using CVSS and product-specific cybersecurity risk assessment methods.
  • Lead technical investigations, root cause analysis, remediation planning, and compensating control evaluation.
  • Support patching strategies, remediation roadmaps, coordinated vulnerability disclosure, and post-market surveillance activities.
  • Partner with product support and customer-facing teams to provide technically accurate cybersecurity responses.

Regulatory, Quality, and Customer Support

  • Provide cybersecurity technical input for product releases, design reviews, quality documentation, and regulatory submissions.
  • Support cybersecurity deliverables such as product security plans, threat models, SBOM-related assessments, vulnerability assessments, penetration test summaries, security architecture documentation, and customer-facing security materials.
  • Participate in audits, assessments, and regulatory inspections as a product cybersecurity technical expert.
  • Review customer security questionnaires and cybersecurity contractual language for technical accuracy.
  • Communicate complex security topics clearly to technical and non-technical stakeholders.
Qualifications

Required:

  • Bachelor's degree in Computer Science, Cybersecurity, Software Engineering, Computer Engineering, or equivalent practical experience.
  • 8+ years of experience in cybersecurity, product security, cloud security, or related technical disciplines.
  • Demonstrated expertise in threat modeling, secure software development, vulnerability management, penetration testing, security design review, and cybersecurity risk assessment.
  • Experience securing embedded systems, connected medical devices, IoT products, robotics platforms, cloud-connected systems, or other cyber-physical products.
  • Strong technical understanding of authentication, authorization, cryptography, secure boot, key management, operating system hardening, network security, logging, monitoring, and secure update mechanisms.
  • Experience writing, reviewing, and validating technical cybersecurity requirements.
  • Ability to translate complex cybersecurity risks into practical engineering recommendations and risk-based product decisions.
  • Experience using vulnerability scoring and assessment methodologies such as CVSS.
  • Ability to independently lead technically complex security initiatives across multiple cross-functional teams.
  • Excellent written and verbal communication skills, including the ability to influence engineering and program stakeholders without direct authority.

Preferred:

  • Experience with medical devices, healthcare technology, surgical robotics, regulated software, or connected health platforms.
  • Familiarity with FDA medical device cybersecurity expectations and global medical device cybersecurity regulatory requirements.
  • Working knowledge of standards and frameworks such as ISO 14971, AAMI TIR57, IEC 62304, IEC 81001-5-1, HIPAA, GDPR, HITRUST, ISO 27001, OWASP Top 10, SOC 2, or FedRAMP.
  • Experience with AWS, Azure, cloud security, web application security, and secure infrastructure design.
  • Software development experience in C, C++, C#, Java, Python, or similar languages.
  • CISSP, CSSLP, GIAC, GICSP, or similar security certification.
  • Master's degree in Cybersecurity, Computer Science, Engineering, or related discipline.
  • Experience supporting formal security audits, regulatory submissions, or product security customer engagements.

Characteristics of Success

  • Solves complex product security problems across multiple product lines without relying on direct people management authority.
  • Identifies cybersecurity concerns early enough to influence design and implementation decisions.
  • Improves security posture through hands-on technical analysis, practical remediation guidance, and verification of control effectiveness.
  • Builds credibility with engineering teams by providing technically sound, feasible, and risk-informed recommendations.
  • Maintains strong traceability between cybersecurity risks, requirements, controls, verification activities, and release decisions.
  • Communicates cybersecurity risk in a way that supports patient safety, regulatory defensibility, and business decision-making.

Johnson & Johnson is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, age, national origin, disability, protected veteran status or other characteristics protected by federal, state or local law. We actively seek qualified candidates who are protected veterans and individuals with disabilities as defined under VEVRAA and Section 503 of the Rehabilitation Act.

Johnson & Johnson is committed to providing an interview process that is inclusive of our applicants' needs. If you are an individual with a disability and would like to request an accommodation, external applicants please contact us via https://www.jnj.com/contact-us/careers , internal employees contact AskGS to be directed to your accommodation resource.

#JNJTECH

Required Skills:

Preferred Skills:

The anticipated base pay range for this position is :

$118,000.00 - $203,550.00

Additional Description for Pay Transparency:

Subject to the terms of their respective plans, employees are eligible to participate in the Company's consolidated retirement plan (pension) and savings plan (401(k)).
Subject to the terms of their respective policies and date of hire, employees are eligible for the following time off benefits:
Vacation -120 hours per calendar year
Sick time - 40 hours per calendar year; for employees who reside in the State of Colorado -48 hours per calendar year; for employees who reside in the State of Washington -56 hours per calendar year
Holiday pay, including Floating Holidays -13 days per calendar year
Work, Personal and Family Time - up to 40 hours per calendar year
Parental Leave - 480 hours within one year of the birth/adoption/foster care of a child
Bereavement Leave - 240 hours for an immediate family member: 40 hours for an extended family member per calendar year
Caregiver Leave - 80 hours in a 52-week rolling period10 days
Volunteer Leave - 32 hours per calendar year
Military Spouse Time-Off - 80 hours per calendar year
For additional general information on Company benefits, please go to: - https://www.careers.jnj.com/employee-benefits

What Johnson & Johnson employees say

Pay

Benefits

Hours and flexibility

Workplace

Get the full story on Breakroom