> Markdown version of [/jobs/ext/2569678-principal-security-architect](https://www.wearedevelopers.com/jobs/ext/2569678-principal-security-architect). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Principal, Security Architect - **Company:** Johnson & Johnson - **Location:** New Brunswick, NJ, United States - **Experience:** Expert - **Salary:** $102,000.0 - $204,000.0 - **Contract:** Permanent contract - **Skills:** Artificial Intelligence, Amazon Web Services, Microsoft Azure, Cloud Computing, Cloud Computing Security, Cyber Security, Data Security, Information Systems Security Architecture Professional, Network Security, Network Planning and Design, Network Segmentation, Systems Development Life Cycle, Role-Based Access Control, Zero Trust Network Access, Sherwood Applied Business Security Architecture, Secure Coding, Systems Integration, EndPointSecurity, Generative AI, Firewalls (Computer Science), Information Technology, Operational Systems, CIS Benchmarks, Meditech, Devsecops, Security Orchestration, Automation & Response - **Published:** August 26, 2026 - **Apply:** https://www.juju.com/job/00000000gp71ke ## About the Role + Required:Bachelor's degree in Computer Science, Information Security, Engineering, ora relatedtechnical field. + Preferred: Master's degree in Cybersecurity, Information Security, ora relateddiscipline. _Experience and Skills:_ Required: + 8+ years of experience in information security, withdemonstrateddepth in security architecture and controls. + Hands-on experience with vulnerability and exposure management, including assessment and remediation. + Strong knowledge of network security and segmentation, firewalls, and zero-trust architecture. + Experience designing endpoint protection and device security controls (e.g., EDR/XDR, device hardening). + Experience withcloud security across one or more major platforms (AWS, Azure, or GCP), including secure configuration and workload protection. + Working knowledge of application and data security principles, including secure SDLC and data protection. + Familiarity with industry frameworks and standards (e.g., NIST CSF, ISO 27001, CIS Controls). Preferred: + Experience securing Operational Technology (OT) and connected/IoT device environments. + Experience defining security controls for AI, data, and Generative AI solutions. + Experience in a regulated industry (MedTech, Pharmaceutical, or Healthcare) with familiarity in associated compliance requirements. + Experience with security automation, SOAR, and security tooling integration. + Experience supporting large-scale transformation or separation programs. Other: + Travel: Up to 25% + Language: Englishproficiencyrequired. + Certifications: Relevant security certifications (e.g., CISSP, CISSP-ISSAP, CCSP, SABSA, or cloud security certifications) preferred. ## Description DePuy Synthes is recruiting for a Principal, Security Architect, located in the United States. The Security Architect designs, evaluates, and strengthens the security architecture that protects DePuy Synthes' technology assets, data, and operational environments. Sitting within the Technology Enterprise Strategy & Security organization, this role serves as a technical authority on security controls-assessing system and network configurations, identifying vulnerabilities and exposures, performing root-cause analysis, and contributing to the design, development, and implementation of countermeasures and security tooling across the enterprise. This role is responsible for advancing the organization's Zero Trust, Secure by Design, and Resilient by Design strategy, ensuring security and resilience are embedded into every technology platform, architecture decision, and transformation initiative. Key Responsibilities + Lead the development of Secure by Design, Resilient by Design, and Zero Trustarchitecturesacross cloud, network, endpoint, identity, application, data, and OT environments. + Conduct security architecture reviews, threat modeling, and risk assessments for new and existing solutions. + Drive the enterprise Zero Trust strategy, including identity, segmentation, least privilege, and continuous verification capabilities. + Design network segmentation and micro-segmentation architectures to protect critical assets and reduce lateral movement. + Define vulnerability and exposure management strategies, including risk-based prioritization and remediation. + Develop resilient security architectures that strengthen containment, recovery, and business continuity capabilities. + Design endpoint security controls, hardening standards, device compliance frameworks, and EDR/XDR integrations. + Establish secure architectures for cloud, AI, data, and application environments, including secure development,DevSecOps, and AI governance practices. + Develop OT security architectures that protect manufacturing,laboratory, and connected device environments. + Partner with Enterprise and Solution Architects to embed security, resilience, and compliance requirements across transformation initiatives. + Evaluatearchitecturesand configurations against frameworks including NIST, NIST Zero Trust, CIS, ISO 27001, and applicable regulatory requirements. + Drive security automation, tooling integrations, and engineering improvements that enhance enterprise defenses. + Perform root-cause analysis of security findings and incidents, recommending strategic and sustainable improvements. + Produce architecture standards, reference designs, technical documentation, and executive-level roadmaps. + Mentor and coach security architects and engineers while fostering a culture of engineering excellence and continuous improvement., Johnson & Johnson announced plans to separate our Orthopaedics business to establish a standalone orthopaedics company, operating as DePuy Synthes. The process of the planned separation is anticipated to be completed within 18 to 24 months, subject to legal requirements, including consultation with works councils and other employee representative bodies, as may be required, regulatory approvals and other customary conditions and approvals. Should you accept this position, it is anticipated that, following conclusion of the transaction, you would be an employee of DePuy Synthes and your employment would be governed by DePuy Synthes employment processes, programs, policies, and benefit plans. In that case, details of any planned changes would be provided to you by DePuy Synthes at an appropriate time and subject to any necessary consultation processes. ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [DevSecOps: Injecting Security into Mobile CI/CD Pipelines](https://www.wearedevelopers.com/videos/273-devsecops-injecting-security-into-mobile-ci-cd-pipelines) - [How to Cause (or Prevent) a Massive Data Breach- Secure Coding and IDOR](https://www.wearedevelopers.com/videos/39-how-to-cause-or-prevent-a-massive-data-breach-secure-coding-and-idor) - [The New AI Security Stack: Observe, Detect, Protect](https://www.wearedevelopers.com/videos/100302-the-new-ai-security-stack-observe-detect-protect) - [You can’t hack what you can’t see](https://www.wearedevelopers.com/videos/41-you-can-t-hack-what-you-can-t-see) - [DevSecOps culture](https://www.wearedevelopers.com/videos/783-devsecops-culture) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Best Paying Jobs in Technology](https://www.wearedevelopers.com/magazine/256-best-paying-jobs-in-technology) - [What’s the Difference between a Junior, Mid, and Senior Developer?](https://www.wearedevelopers.com/magazine/238-what-s-the-difference-between-a-junior-mid-and-senior-developer) - [Why Upskilling And Reskilling is Important For Developers](https://www.wearedevelopers.com/magazine/428-why-upskilling-and-reskilling-is-important-for-developers) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking)