Apply

Ready to go for it?

AI Apply speeds things up—apply directly if you prefer.

FREE ACCESS
5,000–10,000 jobs/day
Scoutfield Logo

See all jobs on Scoutfield

Search thousands of fresh jobs every day.

Discover
  • Fresh listings
  • Fast filters
  • No subscription required
Create a free account and start exploring right away.
Johnson & Johnson

Professional, Program Lead, PenTesting Services

Johnson & Johnson

. Own the end-to-end penetration testing services program for products and connected platforms .

Posted 9/22/2026full-timeUnited StatesSenior💰 $94,000 - $170,000 per yearWebsite

Core Competencies

Role fit
Core Competencies

Use this summary to align your resume positioning with the role.

Demonstrates expertise in managing penetration testing programs, including methodology development, vendor oversight, and embedding security testing within the product development lifecycle. Proficient in conducting assessments across various platforms and delivering technical training to engineering teams.

Highest-signal resume keywords
Penetration Testing Program ManagementWeb Application Penetration TestingScripting Proficiency in PythonOSCP CertificationThreat Modeling and Attack Surface Analysis

ATS Keywords

Tailor your resume
Applicant Tracking System Keywords

Tip: use these terms in your resume and cover letter to boost ATS matches.

Hard Skills
Penetration TestingOffensive SecurityApplication Security AssessmentSecurity Testing MethodologyExploitability AssessmentRemediation ManagementTechnical Risk AnalysisSecurity Testing GatesEmbedded Firmware TestingCloud Infrastructure Testing
Soft Skills
Strong Written CommunicationStrong Verbal Communication
Tools & Technologies
Burp SuiteMetasploitNmapWiresharkGhidraIDAKali
Certifications & Qualifications
OSCPOSCEGPENGWAPTGXPN
Industry Keywords
FDA Premarket SubmissionsEU MDR Technical FilesMedical Device SecurityPatient SafetyClinical Impact

Tech Stack

Tools & technologies
CloudCyber SecurityPythonSDLC

About the role

Key responsibilities & impact
  • Own the end-to-end penetration testing services program for products and connected platforms
  • Develop the annual testing roadmap, prioritization model, and capacity plan
  • Define and maintain penetration testing methodology, scoping standards, rules of engagement, and reporting templates
  • Embed security testing gates into the product development lifecycle
  • Execute and oversee assessments across medical devices, embedded firmware, wireless protocols, mobile and web applications, APIs, and cloud infrastructure
  • Manage third-party penetration testing vendors, including scopes, statements of work, deliverable quality, and SLA performance
  • Triage and validate findings, assess exploitability, and evaluate patient safety and clinical impact
  • Drive remediation with R&D and engineering teams through retest and verified closure
  • Conduct threat modeling and attack surface analysis
  • Produce testing evidence for FDA premarket submissions, EU MDR technical files, and hospital security assessments
  • Contribute testing results and residual risk analysis to product security risk files
  • Build and report program metrics to leadership and product stakeholders
  • Research emerging attack techniques, medical device vulnerabilities, and tooling; develop custom tooling and exploits as needed
  • Assess testing implications of platform migrations, supplier changes, and separation/carve-out activity
  • Deliver technical enablement and secure development training to engineering teams

Requirements

What you’ll need
  • Bachelor's degree in Computer Science, Cybersecurity, Software/Electrical/Biomedical Engineering, Information Systems, or a related technical discipline
  • Minimum 6 years of progressive experience in penetration testing, offensive security, red teaming, or application security assessment
  • Experience leading or managing a penetration testing program, including methodology definition, scoping standards, and vendor oversight
  • Hands-on proficiency across web application, API, mobile, network, wireless, and cloud penetration testing
  • Working knowledge of Burp Suite, Metasploit, Nmap, Wireshark, Ghidra/IDA, and Kali
  • Scripting proficiency in Python, Bash, and PowerShell
  • Understanding of OWASP Top 10, CWE, and CVSS
  • Experience embedding security testing into an SDLC and driving remediation through verified closure
  • Strong written and verbal communication skills and ability to translate technical exploitation detail into business and patient safety risk
  • English proficiency required
  • OSCP, OSCE, GPEN, GWAPT, or GXPN certification required or in progress

Benefits

Comp & perks
  • Retirement plan (pension)
  • Savings plan (401(k))
  • Vacation – 120 hours per calendar year
  • Sick time – 40 hours per calendar year; for Colorado residents – 48 hours; for Washington residents – 56 hours
  • Holiday pay, including Floating Holidays – 13 days per calendar year
  • Work, Personal and Family Time – up to 40 hours per calendar year
  • Parental Leave – 480 hours within one year of the birth/adoption/foster care of a child
  • Bereavement Leave – 240 hours for an immediate family member; 40 hours for an extended family member per calendar year
  • Caregiver Leave – 80 hours in a 52-week rolling period
  • Volunteer Leave – 32 hours per calendar year
  • Military Spouse Time-Off – 80 hours per calendar year
  • Hybrid work
  • Up to 10% domestic and international travel