Job Closed

This listing is no longer active.

Director, Product Security

Security EngineerSecurity EngineerFull TimeRemoteLeadTeam 10,001+H1B SponsorCompany SiteLinkedIn

Location

California + 4 moreAll locations: California | Maine | Nevada | Pennsylvania | South Carolina

Posted

18 days ago

Salary

$150K - $258.8K / year

Seniority

Lead

Bachelor Degree15 yrs expEnglishCloudCyber SecuritySDLC

Job Description

Director, Product Security

Johnson & Johnson

• Define and execute the Business Units product security strategy aligned with FDA/MDR/524B expectations, and QMS requirements. • Lead and grow a global product security team, fostering collaboration that balances technical rigor with business needs. • Oversee security integration across medical devices, software, mobile applications, embedded devices, and cloud environments • Partner with Regulatory, Quality, Legal, Privacy, and Commercial teams to ensure cybersecurity requirements are built into Class I, II, and III devices, supporting PMA and 510(k) submissions. • Champion secure SDLC, DevSecOps, SBOM generation/validation, and vulnerability management across device and software platforms. • Lead emerging technologies (AI and Quantum Cryptography) for medical devices and that will be impacted by cybersecurity. • Make internal and external policy recommendations to mitigate threats and vulnerabilities. • Lead post-market security activities including vulnerability disclosures, CAPAs, routine cyber patching, and incident response. • Operationalize implementation of J&J's enterprise level Product Security Quality Standards and framework throughout the MedTech portfolio of medical devices and supporting platforms • Act as senior product security SME with customers, hospital IT/IS staff, and clinicians, translating technical requirements into clear business and clinical impact. • Represent product security in FDA and international regulatory inspections, reinforcing trust in our devices. • Advance Product Security J&J enterprise Governance and Quality efforts, including J&J Quality Standards for Product Security and ISRM Product Security Framework. • Lead product security Quality and Regulatory cyber efforts within J&J and through key industry forums (e.g., MDIC, AdvaMed, Health-ISAC) to drive alignment and industry collaboration. • Oversee centralized Product Security penetration testing function serving business unit product security teams to provide real-word risk identification and remediation across MedTech product portfolios. • Scaling centralized DevSecOps function serving business unit product security teams that integrate security tooling, secure development controls, and vulnerability management processes into CI/CD pipelines and engineering workflows.

Job Requirements

  • Bachelor’s degree in STEM, Engineering, Computer Science, Cybersecurity or related field, or equivalent work experience.
  • Strong R&D, Regulatory or Quality experience in medical devices is highly preferred
  • 15+ years of MedTech experience in Quality, R&D, engineering, product development, medical devices, or product security, with 5+ years in leadership.
  • Experience with Class I, Class II, and Class III medical devices, including 510(k) and PMA submissions.
  • Experience with medical devices, and/or connected product solutions.
  • Knowledge of hardware and software security, including secure screws, tamper seals, physical port blocking, enclosure access detection, secure boot and system integrity, trusted hardware, secure coding, identity and access management, PKI, integrating security into the development lifecycle (DevSecOps) and manufacturing lifecycle
  • Experience with medical device cybersecurity regulatory expectations and risk management framework, including FDA cybersecurity guidance, section 524B of the FD&C Act for cyber devices, ISO/IEC 81001-5-1, NIST CSF, NIST 800-175, FIPS 140-3, and IEC 62443 and global frameworks.
  • Demonstrated success bridging Engineering, Quality, Regulatory, Legal, Privacy, and Commercial functions.
  • Certifications (nice to have): CISSP, CSSLP, CISM, CISA, or equivalent.

Benefits

  • Subject to the terms of their respective plans, employees are eligible to participate in the Company’s consolidated retirement plan (pension) and savings plan (401(k)).
  • This position is eligible to participate in the Company’s long-term incentive program.
  • Subject to the terms of their respective policies and date of hire, employees are eligible for the following time off benefits:
  • Vacation –120 hours per calendar year
  • Sick time - 40 hours per calendar year; for employees who reside in the State of Colorado –48 hours per calendar year; for employees who reside in the State of Washington –56 hours per calendar year
  • Holiday pay, including Floating Holidays –13 days per calendar year
  • Work, Personal and Family Time - up to 40 hours per calendar year
  • Parental Leave – 480 hours within one year of the birth/adoption/foster care of a child
  • Bereavement Leave – 240 hours for an immediate family member: 40 hours for an extended family member per calendar year
  • Caregiver Leave – 80 hours in a 52-week rolling period
  • Volunteer Leave – 32 hours per calendar year
  • Military Spouse Time-Off – 80 hours per calendar year

Related Categories

Related Job Pages

More Security Engineer Jobs

Full TimeRemoteTeam 5,001-10,000H1B No Sponsor

• Apoiar testes de segurança em aplicações baseadas em LLMs, incluindo cenários de prompt injection, jailbreak, e manipulação de contexto. • Executar casos de teste em agentes internos e user-facing. • Contribuir para a evolução de suítes de testes usando ferramentas como Promptfoo. • Realizar validações funcionais e testes de regressão em serviços de AI Security. • Documentar achados técnicos, evidências, FAQs e boas práticas de forma clara e acionável.

Brazil
Dragonfli Group logo

Senior Cloud Security Architect

Dragonfli Group

CyberSecurity as a Solution: Enabling Secure Business.

Full TimeRemoteTeam 11-50H1B No Sponsor

• Lead the design of a global Zero Trust architecture, ensuring robust identity governance (IAM), network micro-segmentation, and data encryption across AWS, Azure, and/or GCP • Architect specialized security frameworks for AI/ML pipelines, focusing on data privacy for training sets, model integrity, and securing LLM-integrated applications against emerging attack vectors • Develop and enforce enterprise-wide security policies using Infrastructure-as-Code tools (e.g., Terraform), ensuring non-compliant infrastructure is automatically remediated or blocked from deployment • Design and oversee integration of CNAPP and CSPM tools to provide real-time visibility into misconfigurations, vulnerabilities, and excessive permissions • Conduct deep-dive threat modeling for complex cloud-native systems, simulating advanced persistent threats (APTs) and blast-radius scenarios to strengthen system resilience • Drive the organization's transition to a Zero Standing Privilege model for all production environments • Achieve automated auditing for core compliance frameworks, including NIST and CIS Benchmarks • Leverage AI-driven monitoring to minimize Mean Time to Detect (MTTD) anomalous cloud activity • Act as lead security advisor for the Cloud Architecture team, bridging DevOps agility with rigorous regulatory compliance (SOC 2, FedRAMP) • Communicate security risks, architecture decisions, and roadmap recommendations clearly to C-suite and executive stakeholders • Embed automated security testing (SAST/DAST/SCA) directly into CI/CD pipelines as part of a mature DevSecOps practice

District Of Columbia
TransUnion logo

Senior Privacy Compliance Advisor

TransUnion

TransUnion is a global information and insights company that makes trust possible by ensuring that each consumer is reliably and safely represented in the marketplace. We do this by having an accurate and comprehensive picture of each person. This picture is grounded in our legacy as a credit reporting agency which enables us to tap into both credit and public record data; our data fusion methodology that helps us link, match and tap into the awesome combined power of that data; and our knowledgeable and passionate team, who stewards the information with expertise, and in accordance with local legislation around the world. Because of our work, organizations can better understand consumers in order to make more informed decisions, and earn their trust through great, personalized experiences, and the proactive extension of the right opportunities, tools and offers. In turn, consumers can be confident that their data identities will result in the opportunities they deserve. We make trust possible, so businesses and consumers can transact with confidence and achieve great things. We call this Information for Good®—it’s our purpose, and what drives us every day.

Full TimeHybridTeam 10,001+Since 1968H1B Sponsor

Title: Senior Privacy Compliance Advisor- AdTech & Marketing Solutions Location: - 555 West Adams St, Chicago, IL - Reston, Virginia - Crum Lynne, Pennsylvania - GreenWood Village, Colorado - Boca Raton, Florida Hybrid Full time Job Description: Team Overview The Senior Privacy Compliance Advisor serves as a trusted compliance and privacy advisor to the Marketing Solutions business, with a strong emphasis on AdTech, digital advertising, and identity/audience products. You will provide guidance on U.S. and global privacy laws as they apply to advertising technology, supports product development and enhancements and lead regulatory impact assessments. In this role, you will report to the Senior Director, Compliance Advisory. This is a hybrid position and involves regular performance of job responsibilities virtually as well as in-person at an assigned TU office location for a minimum of two days a week. Role Overview and Core Responsibilities - Responsible for advising Marketing Solutions and US Markets on compliance with U.S. privacy laws and regulatory obligations - Serve as the Risk and Compliance lead for the Marketing Solutions Cross Functional Leadership Team; assist in driving their global strategy, supported by stakeholders across the global Legal, Risk and Compliance team - Follow Regulatory Change Management procedures by the business in assessing the impact of new laws and developing and executing on action plans implementing those new laws - Follow Issue Management procedures, by supporting internal business clients to self-identify control breaks that could bring harm to our customers and consumers, investigate the root cause of those issues, and identify and track corrective action to remediate any potential harm - Serve as subject matter expert for relevant compliance policies and training - Support regulatory exams and enforcement activity - Execute team initiatives, including supporting Risk and Compliance Councils, and periodic Mergers and Acquisition activities - Collaborate with Legal, Risk, and Audit teams to ensure alignment across the enterprise. - Mentor junior team members and contribute to a culture of compliance excellence. Required Knowledge and Experiences - Bachelor’s degree required; advanced degree or certification (e.g., IAPP, CIPP) preferred. - 8+ years of AdTech experience related to the digital ecosystem; experience in compliance providing compliance advice to business partners on product development with marketing products - In-depth knowledge of U.S. privacy laws and regulatory frameworks for the AdTech industry - Issue and regulatory change management experience We’re also looking for the preferred skills below. Whether you are proficient or could use some brushing up, we’re happy to support your career development and growth in: - Experience working at large digital platforms or AdTech companies (e.g., advertising, identity, or marketing technology providers) - IAPP certification (e.g., CIPP‑US, CIPP‑E) strongly preferred - Advanced degree or additional privacy/compliance certifications - Experience supporting regulatory exams or enforcement actions - Familiarity with global privacy frameworks beyond the U.S. (e.g., GDPR and similar regulations) Benefits that support every part of your life: At TransUnion, we design benefits to help you feel well, do well, and plan well—from day one. For Your Health: Enjoy day-one eligibility for medical, dental, and vision coverage, plus supplemental plan options. Spousal, domestic partner, and other eligible dependent coverage is available on select plans. Choose tax‑advantaged HSA and FSA accounts to make everyday care more affordable. For Your Protection: We’ve got your back with company‑paid basic life and AD&D, optional voluntary life and AD&D for you and your family, and short‑ and long‑term disability. You can also opt into a legal plan, pet insurance, and travel accident coverage. For Your Family: From adoption assistance and fertility planning coverage to caregiver support, we’re here for every chapter. Access Dependent Care FSA for possibility of an employer match, a complimentary Care@Work membership, and up to 12 weeks of paid parental leave with eligibility for a thoughtful, gradual return. For Your Future: Build toward what’s next with our 401(k) with employer match and Employee Stock Purchase Plan (ESPP). Tap financial wellness resources, career coaching, and optional long‑term care insurance to plan confidently. For You: Grow and recharge with tuition reimbursement, flexible time off for exempt employees or paid time off for nonexempt employees, up to 12 paid holidays per year, commuter benefits, employee discounts, charitable gift matching, and paid volunteer time off, plus corporate volunteer events that make it easy to give back. For Your Wellness: Access 24/7 support including professional therapy, coaching, and emotional well‑being programs alongside guided meditation and resources that support physical, mental, social, and financial wellness. We are committed to being a place where diversity is not only present, it is embraced. As an equal opportunity employer, all qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, age, disability status, veteran status, genetic information, marital status, citizenship status, sexual orientation, gender identity or any other characteristic protected by law. Additionally, in accordance with Section 503 of the Rehabilitation Act of 1973 and the Vietnam Era Veterans’ Readjustment Assistance Act of 1974, TransUnion takes affirmative action to employ and advance in employment qualified individuals with a disability and protected veterans in all levels of employment and develops annual affirmative action plans. Components of TransUnion’s Affirmative Action Program for individuals with disabilities and protected veterans are available for review to any associate or applicant for employment upon request by contacting ERCoE@transunion.com. Qualified applicants with arrest or conviction records will be considered for employment in accordance with applicable law, including the Los Angeles County Fair Chance Ordinance for Employers, the San Francisco Fair Chance Ordinance, Fair Chance Initiative for Hiring Ordinance, and the California Fair Chance Act. TransUnion complies with all applicable immigration laws and regulations. The Company does not presently provide employer support or sponsorship for an immigration-related employment benefit for this position. Applicants must be authorized to work in the United States on a full-time basis without the need for employer support or sponsorship now or in the future. Adherence to Company policies, sound judgment and trustworthiness, working safely, communicating respectfully, and safeguarding business operations, confidential and proprietary information, and the Company’s reputation are also essential expectations of this position. Pay Scale Information: The U.S. base salary range for this position is $142,500.00 - $237,500 annually. *The salary range for this position reflects a reasonable estimate of the range of compensation for this job. At TransUnion, actual compensation is based on careful consideration of additional factors such as (but not limited to) an individual’s education, training, work experience, job-related skill set, location, and industry knowledge, as well as the scope and responsibilities of the position and market considerations. Regular, fulltime non-sales positions may be eligible to participate in TransUnion’s annual bonus plan. Certain positions may be also eligible for long-term incentives and other payments based on applicable company guidance and plan documents. TransUnion Overview: At TransUnion, we encourage and are committed to creating a real, positive impact and shared sense of purpose within our Workforce for Good, which empowers our people to grow, innovate and contribute to a better future for our communities and customers. We strive to build an environment where our associates are in the driver’s seat of their professional development— while having access to help along the way. We recognize that success comes when our associates thrive both professionally and personally; that’s why we prioritize work/life flexibility and offer resources for our teams across the globe to collaborate and drive excellence. Be a part of our Workforce for Good – you’ll work with great people, pioneering products and cutting-edge technology. TransUnion's Internal Job Title: Sr Advisor, Compliance Advisory Company: TransUnion LLC

Illinois + 4 moreAll locations: Illinois | Virginia | Pennsylvania | Colorado | Florida
$142.5K - $237.5K / year

• Planning, procurement, installation, daily on-site maintenance, upgrades, replacements, and preventive maintenance on all systems. • Inventory capture of all electronic security equipment and updating as needed. • Providing technical assistance to team members and acting as the tech expert to the customer. • Electrical troubleshooting, device testing, and installation of electronic components. • Following or referring to layout sheets, building plans, and technical guidance. • Documenting, scheduling, and closing work orders with detailed descriptions.

Texas
$33 - $35 / hour