Apply

Ready to go for it?

AI Apply speeds things up—apply directly if you prefer.

FREE ACCESS
5,000–10,000 jobs/day
Scoutfield Logo

See all jobs on Scoutfield

Search thousands of fresh jobs every day.

Discover
  • Fresh listings
  • Fast filters
  • No subscription required
Create a free account and start exploring right away.
Johnson & Johnson

Experienced Security Engineer, Product Analyst

Johnson & Johnson

. Integrate security requirements and controls into the design and development of digital and connected products .

Posted 9/22/2026full-timeUnited StatesJuniorMid-Level💰 $79,000 - $142,000 per yearWebsite

Core Competencies

Role fit
Core Competencies

Use this summary to align your resume positioning with the role.

Demonstrates expertise in integrating security requirements into product design and development, conducting security risk assessments, and collaborating with cross-functional teams. Proficient in secure development lifecycle practices and familiar with regulatory standards relevant to medical devices.

Highest-signal resume keywords
Security Risk AssessmentThreat ModelingVulnerability AnalysisSecure Development Lifecycle (SDLC)ISO, NIST, OWASP Standards

ATS Keywords

Tailor your resume
Applicant Tracking System Keywords

Tip: use these terms in your resume and cover letter to boost ATS matches.

Hard Skills
Security TestingStatic AnalysisDynamic AnalysisPenetration TestingVulnerability ValidationDocumentation ManagementCybersecurity Threat MonitoringRegulatory ComplianceSecurity Standards DevelopmentGovernance Processes
Soft Skills
Analytical SkillsCommunication SkillsCollaboration Skills
Tools & Technologies
SASTDASTDependency ScanningCloud SecurityEmbedded Device SecurityConnected Device Security
Certifications & Qualifications
CISSPCSSLPGSEC
Industry Keywords
Medical DevicesHealthcareLife SciencesCybersecurityProduct Security

Tech Stack

Tools & technologies
CloudCyber SecuritySDLC

About the role

Key responsibilities & impact
  • Integrate security requirements and controls into the design and development of digital and connected products
  • Perform product security risk assessments, threat modeling, and vulnerability analysis across the product lifecycle
  • Partner with product development, quality, and regulatory teams on secure design reviews and remediation activities
  • Support security testing, including static and dynamic analysis, penetration testing coordination, and vulnerability validation
  • Track, document, and manage product security findings to closure under internal governance processes
  • Contribute to product security standards, procedures, and best practices
  • Monitor emerging cybersecurity threats, vulnerabilities, and regulatory guidance relevant to medical devices and digital health
  • Support audits, assessments, and regulatory inquiries related to product cybersecurity
  • Partner with engineering, quality, regulatory, and IT teams to protect DePuy Synthes digital products and connected medical technologies

Requirements

What you’ll need
  • Bachelor’s degree in Computer Science, Engineering, Information Security, or a related technical field required
  • 2–4 years of relevant professional experience in cybersecurity, product security, or secure software development
  • Working knowledge of secure development lifecycle (SDLC) practices and security-by-design principles
  • Experience conducting security risk assessments, threat modeling, or vulnerability analysis
  • Familiarity with common security standards and frameworks, including ISO, NIST, and OWASP
  • Ability to collaborate with cross-functional technical and non-technical teams
  • Strong analytical, documentation, and communication skills
  • English proficiency required
  • Up to 10% domestic travel
  • Preferred: Master’s degree in Cybersecurity, Computer Engineering, or a related discipline
  • Preferred: Experience in a regulated industry such as medical devices, healthcare, or life sciences
  • Preferred: Exposure to SAST, DAST, and dependency scanning
  • Preferred: Knowledge of cloud, embedded, or connected device security concepts
  • Preferred: Understanding of FDA premarket/postmarket guidance
  • Preferred: Experience contributing to internal security policies, standards, or governance processes
  • Preferred certifications: CISSP, CSSLP, GSEC, or equivalent security certification

Benefits

Comp & perks
  • Consolidated retirement plan (pension)
  • Savings plan (401(k))
  • Vacation – 120 hours per calendar year
  • Sick time – 40 hours per calendar year; 48 hours for employees residing in Colorado; 56 hours for employees residing in Washington
  • Holiday pay, including Floating Holidays – 13 days per calendar year
  • Work, Personal and Family Time – up to 40 hours per calendar year
  • Parental Leave – 480 hours within one year of the birth/adoption/foster care of a child
  • Bereavement Leave – 240 hours for an immediate family member; 40 hours for an extended family member per calendar year
  • Caregiver Leave – 80 hours in a 52-week rolling period
  • Volunteer Leave – 32 hours per calendar year
  • Military Spouse Time-Off – 80 hours per calendar year