FREE ACCESS
5,000–10,000 jobs/day
See all jobs on Scoutfield
Search thousands of fresh jobs every day.
Discover
- Fresh listings
- Fast filters
- No subscription required
Create a free account and start exploring right away.

Professional, Program Lead, PenTesting Services
Johnson & Johnson. Own the end-to-end penetration testing services program for products and connected platforms .
Core Competencies
Role fitCore Competencies
Use this summary to align your resume positioning with the role.
Demonstrates expertise in managing penetration testing programs, including methodology development, vendor oversight, and security testing integration into the product development lifecycle. Proficient in translating technical findings into business and patient safety risks while ensuring compliance with industry standards.
Highest-signal resume keywords
Penetration Testing Program ManagementWeb Application Penetration TestingScripting Proficiency in PythonOSCP CertificationExperience with Medical Devices
ATS Keywords
Tailor your resumeApplicant Tracking System Keywords
Tip: use these terms in your resume and cover letter to boost ATS matches.
Hard Skills
Penetration TestingOffensive SecurityRed TeamingAPI Security AssessmentCloud Penetration TestingThreat ModelingAttack Surface AnalysisSecurity Testing MethodologyExploitability AssessmentRemediation Management
Soft Skills
Communication SkillsCollaborationProblem-Solving
Tools & Technologies
Burp SuiteMetasploitNmapWiresharkGhidraKaliAWSAzure
Certifications & Qualifications
OSCPOSCEGPENGWAPTGXPN
Industry Keywords
FDA Cybersecurity GuidanceEU MDRIEC 62304ISO 14971AAMI TIR57Embedded SystemsFirmwareWireless ProtocolsDevSecOpsCI/CD
Tech Stack
Tools & technologiesAWSAzureCloudCyber SecurityPythonSDLC
About the role
Key responsibilities & impact- Own the end-to-end penetration testing services program for products and connected platforms
- Develop the annual testing roadmap, prioritization model, and capacity planning
- Define and maintain penetration testing methodology, scoping standards, rules of engagement, and reporting templates
- Embed security testing gates into the product development lifecycle
- Execute and oversee assessments across medical devices, firmware, wireless protocols, mobile applications, web applications, APIs, and cloud infrastructure
- Manage third-party penetration testing vendors, including scopes, statements of work, deliverable quality, and SLA performance
- Triage and validate findings, assess exploitability, and evaluate patient safety and clinical impact
- Drive remediation with R&D and engineering teams through retest and verified closure
- Conduct threat modeling and attack surface analysis
- Produce testing evidence for FDA submissions, EU MDR technical files, and hospital security assessments
- Contribute results and residual risk analysis to product security risk files
- Build and report program metrics to leadership and product stakeholders
- Research emerging attack techniques and develop custom tooling and exploits as needed
- Assess testing implications of migrations, supplier changes, and separation/carve-out activity
- Deliver technical enablement and secure development training to engineering teams
Requirements
What you’ll need- Bachelor's degree in Computer Science, Cybersecurity, Software/Electrical/Biomedical Engineering, Information Systems, or a related technical discipline
- Minimum 6 years of progressive experience in penetration testing, offensive security, red teaming, or application security assessment
- Experience leading or managing a penetration testing program, including methodology definition, scoping standards, and vendor oversight
- Hands-on proficiency in web application, API, mobile, network, wireless, and cloud penetration testing
- Working knowledge of Burp Suite, Metasploit, Nmap, Wireshark, Ghidra/IDA, and Kali
- Scripting proficiency in Python, Bash, and PowerShell
- Understanding of OWASP Top 10, CWE, and CVSS
- Experience embedding security testing into an SDLC and driving remediation through verified closure
- Ability to translate technical exploitation details into business and patient safety risk for non-technical audiences
- English proficiency required
- OSCP, OSCE, GPEN, GWAPT, or GXPN required or in progress
- Up to 10% domestic and international travel expected
- Advanced degree or specialized cybersecurity education preferred
- Preferred experience with MedTech or medical devices, FDA cybersecurity guidance, EU MDR, IEC 62304, ISO 14971, AAMI TIR57, embedded systems, firmware, wireless/IoMT protocols, AWS/Azure, vulnerability disclosure, Generative AI/LLM tooling, and DevSecOps/CI/CD
Benefits
Comp & perks- Consolidated retirement plan (pension)
- Savings plan (401(k))
- Vacation – 120 hours per calendar year
- Sick time – 40 hours per calendar year; Colorado employees – 48 hours per calendar year; Washington employees – 56 hours per calendar year
- Holiday pay, including Floating Holidays – 13 days per calendar year
- Work, Personal and Family Time – up to 40 hours per calendar year
- Parental Leave – 480 hours within one year of the birth/adoption/foster care of a child
- Bereavement Leave – 240 hours for an immediate family member; 40 hours for an extended family member per calendar year
- Caregiver Leave – 80 hours in a 52-week rolling period
- Volunteer Leave – 32 hours per calendar year
- Military Spouse Time-Off – 80 hours per calendar year
- Hybrid work arrangement