> Markdown version of [/jobs/ext/2150646-principal-product-security-engineer](https://www.wearedevelopers.com/jobs/ext/2150646-principal-product-security-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Principal Product Security Engineer - **Company:** Johnson & Johnson - **Location:** Santa Clara, CA, United States - **Experience:** Expert - **Salary:** $118,000.0 - $203,550.0 - **Contract:** Permanent contract - **Skills:** C (Programming Language), Java (Programming Language), Amazon Web Services, Software Applications, Software System Penetration Testing, Microsoft Azure, C Sharp (Programming Language), C++ (Programming Language), Cloud Computing, Cloud Computing Security, Static Program Analysis, Cyber Security, Computer Engineering, Fuzz Testing, Python (Programming Language), Key Management, Network Security, Open Source Technology, Open Web Application Security, Cloud Services, Robotic Automation Software, Secure Coding, Web Application Security, Software Engineering, Software Vulnerability Management, Data Logging, Software Security, Information Technology, U-Boot, Vulnerability Analysis - **Published:** August 20, 2026 - **Apply:** https://dejobs.org/x/x/83E9E794C5C3407183069DBF186B5340/job/ ## About the Role * Bachelor's degree in Computer Science, Cybersecurity, Software Engineering, Computer Engineering, or equivalent practical experience. * 8+ years of experience in cybersecurity, product security, cloud security, or related technical disciplines. * Demonstrated expertise in threat modeling, secure software development, vulnerability management, penetration testing, security design review, and cybersecurity risk assessment. * Experience securing embedded systems, connected medical devices, IoT products, robotics platforms, cloud-connected systems, or other cyber-physical products. * Strong technical understanding of authentication, authorization, cryptography, secure boot, key management, operating system hardening, network security, logging, monitoring, and secure update mechanisms. * Experience writing, reviewing, and validating technical cybersecurity requirements. * Ability to translate complex cybersecurity risks into practical engineering recommendations and risk-based product decisions. * Experience using vulnerability scoring and assessment methodologies such as CVSS. * Ability to independently lead technically complex security initiatives across multiple cross-functional teams. * Excellent written and verbal communication skills, including the ability to influence engineering and program stakeholders without direct authority. Preferred: * Experience with medical devices, healthcare technology, surgical robotics, regulated software, or connected health platforms. * Familiarity with FDA medical device cybersecurity expectations and global medical device cybersecurity regulatory requirements. * Working knowledge of standards and frameworks such as ISO 14971, AAMI TIR57, IEC 62304, IEC 81001-5-1, HIPAA, GDPR, HITRUST, ISO 27001, OWASP Top 10, SOC 2, or FedRAMP. * Experience with AWS, Azure, cloud security, web application security, and secure infrastructure design. * Software development experience in C, C++, C#, Java, Python, or similar languages. * CISSP, CSSLP, GIAC, GICSP, or similar security certification. * Master's degree in Cybersecurity, Computer Science, Engineering, or related discipline. * Experience supporting formal security audits, regulatory submissions, or product security customer engagements. Characteristics of Success * Solves complex product security problems across multiple product lines without relying on direct people management authority. * Identifies cybersecurity concerns early enough to influence design and implementation decisions. * Improves security posture through hands-on technical analysis, practical remediation guidance, and verification of control effectiveness. * Builds credibility with engineering teams by providing technically sound, feasible, and risk-informed recommendations. * Maintains strong traceability between cybersecurity risks, requirements, controls, verification activities, and release decisions. * Communicates cybersecurity risk in a way that supports patient safety, regulatory defensibility, and business decision-making. ## Description The Principal Product Security Engineer is a senior technical cybersecurity expert responsible for securing connected medical devices, robotic systems, embedded platforms, cloud services, and supporting digital health ecosystems throughout the product lifecycle. This role provides hands-on technical leadership across multiple product teams by identifying cybersecurity risks, developing security requirements, performing security assessments, guiding remediation, and verifying that security controls are appropriately implemented within regulated medical device products. Primary Responsibilities Technical Product Security Leadership * Serve as the cybersecurity technical lead for complex medical device and digital health product development programs. * Provide technical direction on security design, implementation, verification, vulnerability remediation, and risk treatment activities. * Drive security-by-design practices throughout the product development lifecycle. * Influence engineering tradeoffs by balancing cybersecurity risk, patient safety, clinical workflow, usability, and product constraints. * Mentor software, systems, cloud, and embedded engineering teams on secure development practices. Security Engineering * Develop, review, and maintain cybersecurity requirements for embedded systems, software applications, cloud services, and connected medical devices. * Perform detailed security design reviews, implementation assessments, configuration reviews, and attack surface analysis. * Evaluate authentication, authorization, cryptography, secure boot, key management, access control, logging, monitoring, update mechanisms, and operating system hardening implementations. * Provide practical secure coding and design recommendations to engineering teams. * Identify design weaknesses early and partner with teams to implement technically feasible mitigations. Threat Modeling and Cybersecurity Risk Assessment * Lead threat modeling activities for products, platforms, system features, and supporting services. * Analyze threats, vulnerabilities, abuse cases, misuse cases, and chained attack paths. * Perform cybersecurity risk assessments and evaluate risk control effectiveness. * Assess potential impact to patient safety, clinical operations, confidentiality, integrity, availability, and product performance. * Develop risk-based mitigation strategies and support the objective evidence needed to demonstrate control effectiveness. Security Testing and Validation * Perform or coordinate security testing activities including static analysis, software composition analysis, vulnerability scanning, fuzz testing, penetration testing, secure configuration reviews, and architecture assessments. * Analyze test results and translate findings into clear, actionable remediation plans. * Support independent security assessments and third-party penetration testing activities. * Verify the effectiveness of implemented security controls and compensating controls. * Ensure security testing outputs are traceable to product risks, requirements, and release decisions. Vulnerability Management and Post-Market Security * Analyze vulnerabilities affecting commercial, open-source, cloud, infrastructure, and internally developed software components. * Evaluate exploitability and product impact using CVSS and product-specific cybersecurity risk assessment methods. * Lead technical investigations, root cause analysis, remediation planning, and compensating control evaluation. * Support patching strategies, remediation roadmaps, coordinated vulnerability disclosure, and post-market surveillance activities. * Partner with product support and customer-facing teams to provide technically accurate cybersecurity responses. Regulatory, Quality, and Customer Support * Provide cybersecurity technical input for product releases, design reviews, quality documentation, and regulatory submissions. * Support cybersecurity deliverables such as product security plans, threat models, SBOM-related assessments, vulnerability assessments, penetration test summaries, security architecture documentation, and customer-facing security materials. * Participate in audits, assessments, and regulatory inspections as a product cybersecurity technical expert. * Review customer security questionnaires and cybersecurity contractual language for technical accuracy. * Communicate complex security topics clearly to technical and non-technical stakeholders. ## Related Videos - [Crypto-secure Data Management with In-Database Blockchain](https://www.wearedevelopers.com/videos/632-crypto-secure-data-management-with-in-database-blockchain) - [How will artificial intelligence change the future of software testing?](https://www.wearedevelopers.com/videos/85-how-will-artificial-intelligence-change-the-future-of-software-testing) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Build Delightful Mobile Experiences with Kotlin, Realm, and Atlas Device Sync](https://www.wearedevelopers.com/videos/694-build-delightful-mobile-experiences-with-kotlin-realm-and-atlas-device-sync) - [Automated Security for the Entire SDLC](https://www.wearedevelopers.com/videos/100323-automated-security-for-the-entire-sdlc) - [Mutation Testing and Fuzzing in C#](https://www.wearedevelopers.com/videos/703-mutation-testing-and-fuzzing-in-c) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again](https://www.wearedevelopers.com/magazine/751-how-we-built-a-worry-free-system-that-runs-for-10-years-and-what-we-d-do-again) - [What is Software Engineering?](https://www.wearedevelopers.com/magazine/289-what-is-software-engineering) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [What’s the Difference between a Junior, Mid, and Senior Developer?](https://www.wearedevelopers.com/magazine/238-what-s-the-difference-between-a-junior-mid-and-senior-developer) - [Top Characteristics of a Software Engineer](https://www.wearedevelopers.com/magazine/166-top-characteristics-of-a-software-engineer)