Apply

Ready to go for it?

AI Apply speeds things up—apply directly if you prefer.

FREE ACCESS
5,000–10,000 jobs/day
Scoutfield Logo

See all jobs on Scoutfield

Search thousands of fresh jobs every day.

Discover
  • Fresh listings
  • Fast filters
  • No subscription required
Create a free account and start exploring right away.
Johnson & Johnson

Security Engineer, Product Analyst

Johnson & Johnson

. Integrate security requirements and controls into the design and development of digital and connected products .

Posted 9/22/2026full-timeUnited StatesJuniorMid-Level💰 $79,000 - $142,000 per yearWebsite

Core Competencies

Role fit
Core Competencies

Use this summary to align your resume positioning with the role.

Demonstrates expertise in integrating security requirements into product design and development, conducting security risk assessments, and collaborating with cross-functional teams to ensure compliance with cybersecurity standards in regulated industries. Proficient in security testing methodologies and maintaining product security governance.

Highest-signal resume keywords
Security Risk AssessmentThreat ModelingSecure Development Lifecycle (SDLC)ISO, NIST, OWASP StandardsCISSP, CSSLP, GSEC Certifications

ATS Keywords

Tailor your resume
Applicant Tracking System Keywords

Tip: use these terms in your resume and cover letter to boost ATS matches.

Hard Skills
Vulnerability AnalysisStatic AnalysisDynamic AnalysisPenetration TestingSecurity TestingDocumentationAnalytical Skills
Soft Skills
CollaborationCommunicationCross-Functional Teamwork
Tools & Technologies
SASTDASTDependency ScanningCloud SecurityEmbedded Device Security
Certifications & Qualifications
CISSPCSSLPGSEC
Industry Keywords
Medical DevicesHealthcareLife SciencesCybersecurityRegulatory Compliance

Tech Stack

Tools & technologies
CloudCyber SecuritySDLC

About the role

Key responsibilities & impact
  • Integrate security requirements and controls into the design and development of digital and connected products
  • Perform product security risk assessments, threat modeling, and vulnerability analysis across the product lifecycle
  • Partner with product development, quality, and regulatory teams on secure design reviews and remediation activities
  • Support security testing, including static and dynamic analysis, penetration testing coordination, and vulnerability validation
  • Track, document, and manage product security findings to closure in alignment with internal governance processes
  • Contribute to product security standards, procedures, and best practices
  • Monitor emerging cybersecurity threats, vulnerabilities, and regulatory guidance relevant to medical devices and digital health
  • Support audits, assessments, and regulatory inquiries related to product cybersecurity
  • Report into the DePuy Synthes Technology organization
  • Collaborate with engineering, quality, regulatory, and IT teams to protect digital products and connected medical technologies

Requirements

What you’ll need
  • Bachelor’s degree in Computer Science, Engineering, Information Security, or a related technical field
  • 2–4 years of relevant professional experience in cybersecurity, product security, or secure software development
  • Working knowledge of secure development lifecycle (SDLC) practices and security-by-design principles
  • Experience conducting security risk assessments, threat modeling, or vulnerability analysis
  • Familiarity with common security standards and frameworks, including ISO, NIST, or OWASP
  • Ability to collaborate effectively with cross-functional technical and non-technical teams
  • Strong analytical, documentation, and communication skills
  • English proficiency required
  • Up to 10% domestic travel
  • Preferred: experience in a regulated industry such as medical devices, healthcare, or life sciences
  • Preferred: hands-on exposure to SAST, DAST, and dependency scanning
  • Preferred: knowledge of cloud, embedded, or connected device security concepts
  • Preferred: understanding of FDA premarket/postmarket cybersecurity guidance
  • Preferred: experience contributing to internal security policies, standards, or governance processes
  • Preferred certifications: CISSP, CSSLP, GSEC, or equivalent security certification
  • Master’s degree in Cybersecurity, Computer Engineering, or a related discipline preferred

Benefits

Comp & perks
  • Consolidated retirement plan (pension)
  • Savings plan (401(k))
  • Vacation – 120 hours per calendar year
  • Sick time – 40 hours per calendar year; 48 hours per calendar year for employees residing in Colorado; 56 hours per calendar year for employees residing in Washington
  • Holiday pay, including Floating Holidays – 13 days per calendar year
  • Work, Personal and Family Time – up to 40 hours per calendar year
  • Parental Leave – 480 hours within one year of the birth/adoption/foster care of a child
  • Bereavement Leave – 240 hours for an immediate family member; 40 hours for an extended family member per calendar year
  • Caregiver Leave – 80 hours in a 52-week rolling period
  • Volunteer Leave – 32 hours per calendar year
  • Military Spouse Time-Off – 80 hours per calendar year
  • Inclusive interview process and disability accommodations