Director Software Quality Engineering & Cybersecurity

Johnson & Johnson
Santa Clara, CA, United States
3 days ago
Apply on www.techcareers.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
7 years minimum
Compensation
$172,000.0 - $297,850.0
Working hours
Regular working hours

Tech stack

Agile Methodology Artificial Intelligence Application Lifecycle Management Software System Penetration Testing Systems Engineering Configuration Management Software Quality Cyber Security Data Systems DevOps Digital Technology EHealth
+10 more
Embedded Software Software Product Management Software Tools Software Engineering Software Requirements Analysis Software Vulnerability Management Information Technology Mdsap GXP Vulnerability Analysis

Job description

The Director leads the quality engineering strategy and execution for software-enabled medical technologies across the OTTAVA robotic surgical platform. This leader oversees software quality engineering activities supporting software in medical device including AI/ML components, Software as a Medical Device (SaMD), Medical Device Data Systems (MDDS), embedded software, connected digital systems, non-product software validation, and cybersecurity compliance. This role partners closely with R&D, Regulatory Affairs, Medical Safety, Systems Engineering, Clinical, and enterprise cybersecurity teams to ensure software products and supporting systems meet global regulatory requirements, cybersecurity expectations, and company quality standards throughout the product lifecycle. The Director establishes scalable quality systems, drive software development and validation excellence, supports regulatory submissions and inspections, and enable safe and compliant product commercialization., * Lead the Software Quality Engineering function supporting the OTTAVA robotic surgical platform and associated digital technologies.

  • Establish and execute software quality strategies aligned with FDA, ISO 13485, IEC 62304, ISO 14971, FDA cybersecurity guidance, and applicable global regulations.
  • Provide oversight of software design controls, software lifecycle processes, software risk management, anomaly management, configuration management, and release readiness activities.
  • Ensure robust traceability between software requirements, hazards, mitigations, verification, validation, and cybersecurity controls.
  • Lead quality and compliance activities for Software as a Medical Device (SaMD) and Medical Device Data Systems (MDDS).
  • Partner with Regulatory Affairs to support regulatory submissions, FDA interactions, technical documentation, and cybersecurity deliverables.
  • Ensure software classification, intended use, and regulatory positioning are appropriately documented and maintained.
  • Lead quality oversight for product cybersecurity activities across the software development lifecycle.
  • Partner with enterprise cybersecurity and product security teams to ensure implementation of Secure Product Development Framework (SPDF) practices.
  • Oversee cybersecurity risk management, vulnerability management, penetration testing assessments, SBOM governance, threat modeling, and post-market cybersecurity processes.
  • Ensure cybersecurity activities are integrated into CAPA, complaint handling, supplier controls, and change management systems.
  • Support regulatory responses related to cybersecurity and software assurance.
  • Establish and maintain compliant validation programs for non-product software used in development, testing, manufacturing, quality systems, and operations.
  • Ensure validation approaches are risk-based, scalable, and inspection-ready.
  • Oversee governance for software tools supporting regulated activities, including lifecycle management and change control.
  • Partner with R&D and Systems Engineering to support new product development, sustaining engineering, design changes, and software releases.
  • Participate in risk management activities, design reviews, verification/validation reviews, and failure investigations.
  • Ensure software quality considerations are integrated into design transfer and launch readiness activities.
  • Develop and maintain procedures, standards, and governance models supporting software quality and cybersecurity compliance.
  • Ensure inspection readiness for FDA, notified body, and internal audits.
  • Lead software quality metrics, trend analysis, and continuous improvement initiatives.
  • Support investigations, CAPAs, complaints, and field actions involving software or cybersecurity-related issues
  • Build and develop a high-performing Software QE organization.
  • Provide coaching, mentorship, and career development for managers and engineers.
  • Foster a culture of accountability, technical excellence, collaboration, and proactive risk management.
  • Drive clarity of ownership and effective cross-functional decision-making
  • Leads with technical credibility and executive presence, inspiring confidence across engineering, operations, and executive teams.
  • Comprehensive understanding of Design Controls, Design Verification and Validation, and Design Transfer processes for medical devices.
  • Proficiency with 21 CFR Part 820, ISO 13485, ISO 14971, IEC 62304, and EU MDR compliance frameworks.
  • Proven success supporting FDA inspections, ISO certification audits, and MDSAP assessments with strong command of global regulatory requirements.

Requirements

  • Bachelor’s degree in engineering, Computer Science, Software Engineering, Biomedical engineering, or related technical field is required. Advanced degree is preferred.
  • A minimum of 12 years of experience in medical devices, software-regulated, or highly regulated industries.
  • A minimum of 7 years of leadership experience managing software quality or software engineering teams.
  • Strong knowledge of IEC 62304, ISO 14971, ISO 13485, FDA QSR/QMSR, and FDA cybersecurity guidance.
  • Hands-on experience with AI/ML-enabled device development, software lifecycle management, and digital health quality integration.
  • Experience with software risk management, cybersecurity governance, and software development lifecycle processes.
  • In depth knowledge of SPDF, threat modeling, SBOM management, and vulnerability assessment processes.
  • Experience with Agile software development environments and DevOps methodologies.
  • Experience supporting FDA submissions, inspections, and regulatory audits.
  • On-site attendance at Johnson and Johnson robotic campus in Santa Clara, CA facility is required for at least 3 days a week., Business Planning, Change Management, Coaching, Cybersecurity, Design Controls, Fact-Based Decision Making, FDA Submissions, Give Feedback, IEC 62304, Inclusive Leadership, Leadership, Process Improvements, Risk Management Software, Science, Technology, Engineering, and Math (STEM) Application, Technical Software

Benefits & conditions

Subject to the terms of their respective plans, employees are eligible to participate in the Company’s consolidated retirement plan (pension) and savings plan (401(k)).

This position is eligible to participate in the Company’s long-term incentive program.

Subject to the terms of their respective policies and date of hire, employees are eligible for the following time off benefits:

Vacation -120 hours per calendar year

Sick time - 40 hours per calendar year; for employees who reside in the State of Colorado -48 hours per calendar year; for employees who reside in the State of Washington -56 hours per calendar year

Holiday pay, including Floating Holidays -13 days per calendar year

Work, Personal and Family Time - up to 40 hours per calendar year

Parental Leave - 480 hours within one year of the birth/adoption/foster care of a child

Bereavement Leave - 240 hours for an immediate family member: 40 hours for an extended family member per calendar year

Caregiver Leave - 80 hours in a 52-week rolling period10 days

Volunteer Leave - 32 hours per calendar year

Military Spouse Time-Off - 80 hours per calendar year

About the company

At Johnson & Johnson, we believe health is everything. Our strength in healthcare innovation empowers us to build a world where complex diseases are prevented, treated, and cured, where treatments are smarter and less invasive, and solutions are personal. Through our expertise in Innovative Medicine and MedTech, we are uniquely positioned to innovate across the full spectrum of healthcare solutions today to deliver the breakthroughs of tomorrow, and profoundly impact health for humanity. Learn more at jnj.com

As guided by Our Credo, Johnson & Johnson is responsible to our employees who work with us throughout the world. We provide an inclusive work environment where each person is considered as an individual. At Johnson & Johnson, we respect the diversity and dignity of our employees and recognize their merit.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.techcareers.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

3:13 min

Core components of the internal Optimize ecosystem

Dominik Schneider Dominik Schneider · World Congress 2025

2:17 min

Mapping the maturity roadmap for scaled devops adoption

Dominik Krichbaum Dominik Krichbaum · World Congress 2026 Europe

3:10 min

Navigating medical device certification and clinical trials

Alexandre Guenoun Alexandre Guenoun +3 · World Congress 2026 Europe

3:30 min

Scaling agile frameworks and data interoperability in healthcare

Leo Lindhorst · World Congress 2022

3:18 min

Scaling global network engineering through DevOps culture

Stuart Clark · LIVE

2:30 min

Establishing shared definitions for devops and cloud architectures

Bruno Amaro Almeida · World Congress 2022

Videos

See all

Related articles

See all