> Markdown version of [/jobs/ext/1274982-principal-product-security-engineer](https://www.wearedevelopers.com/jobs/ext/1274982-principal-product-security-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Principal Product Security Engineer - **Company:** Johnson & Johnson - **Location:** Raritan, NJ, United States (Remote available) - **Experience:** Expert - **Salary:** $100,000.0 - $172,500.0 - **Contract:** Permanent contract - **Skills:** Cyber Security, Software Vulnerability Management, Software Security - **Published:** July 15, 2026 - **Apply:** https://www.careerjet.com/job/usf2aa331a53d931306ab15188fefef2dd/eaa ## About the Role * Bachelor's degree * 5+ years industry experience in Information Security. * Working knowledge of regulatory standards and compliance frameworks (e.g., NIST Cybersecurity Framework, ISO27001, SOC2, HIPAA, GDPR). * Experience with security risk management techniques. * Demonstrated organizational skills, attention to detail, the ability to handle multiple assignments simultaneously in a timely manner and be able to meet assigned deadlines. * Committed to working with a sense of urgency and embracing new challenges . * Strong communication and interpersonal skills. Preferred: * Experience working in a regulated environment, FDA-regulated ## Description We are searching for the best talent for a Principal Product Security Engineer to be located in Danvers, MA or Raritan, NJ. Remote work options may be considered on a case-by-case basis and if approved by the Company. Are you passionate about security and interested in joining a community of collaborative colleagues working in a Patient First! culture? If that's you, we have an immediate opportunity for a Principal Product Security Engineer to join the newly formed Product Security team to help ensure security is implemented by design for this top-performing medical device company. This is an exciting opportunity to impact development initiatives that will shape future product development and industry standards. You will own the Product Security process that includes both pre-market and post-market processes engineering teams leverage throughout the product development lifecycle. If you are eager to leverage your security risk and compliance skills to make a difference and directly impact patient lives, this could be perfect for you., * Being at the office in Danvers MA for a minimum of 3 days per week (for candidates within commutable distance to site). * Partner with engineering teams (cloud, console, pump, etc.) to drive successful adherence to Abiomed's product security policies, processes, program objectives. * Create, update, and improve product security processes. * Act as a SME on cyber security matters and provide guidance to development teams. * Advocate for proactive inclusion of cyber security input into all phases of the product life cycle, process improvements, CAPAs, strategic product road map planning. * Deliver documentation for pre-market product development activities including security plans, architecture diagrams, data flow diagrams, threat models, security requirements, Design for Security, SBOM, and risk management documentation. * Drive and monitor and post-market vulnerability management activities, with adherence to strict timelines. * Support compliance certification activities, such as SOC2, FedRAMP, ISO 27001, etc. * Identify, research, evaluate, and integrate new compliance requirements, industry standards, and best practices into the product security programs. * Maintain relationships with Abiomed's Information Sharing and Analysis Organizations. * Guide teams to make decisions that balance business needs with medical device security objectives. * Work across organizational boundaries and exhibit empathy with customers, both internal and external. * Perform other related duties and responsibilities, as assigned. ## Related Videos - [Software Security 101: Secure Coding Basics](https://www.wearedevelopers.com/videos/220-software-security-101-secure-coding-basics) - [Reporting Active Exploits in 24 Hours: Are You Ready for the CRA?](https://www.wearedevelopers.com/videos/100248-reporting-active-exploits-in-24-hours-are-you-ready-for-the-cra) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [What is the real price of one successful line of code?](https://www.wearedevelopers.com/videos/1921-what-is-the-real-price-of-one-successful-line-of-code) - [One Pipeline, Three Regulator - SBOM Compliance for the Developer](https://www.wearedevelopers.com/videos/100169-one-pipeline-three-regulator-sbom-compliance-for-the-developer) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Fully Remote Software Engineer Jobs](https://www.wearedevelopers.com/magazine/447-fully-remote-software-engineer-jobs) - [Where to Find Entry-Level Software Engineering Jobs](https://www.wearedevelopers.com/magazine/397-where-to-find-entry-level-software-engineering-jobs) - [What’s the Difference between a Junior, Mid, and Senior Developer?](https://www.wearedevelopers.com/magazine/238-what-s-the-difference-between-a-junior-mid-and-senior-developer) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Now is the time for industrialized software development](https://www.wearedevelopers.com/magazine/601-now-is-the-time-for-industrialized-software-development)