> Markdown version of [/jobs/ext/3052524-exp-analyst-security-engineer-product](https://www.wearedevelopers.com/jobs/ext/3052524-exp-analyst-security-engineer-product). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Exp, Analyst, Security Engineer Product - **Company:** Johnson & Johnson - **Location:** New Brunswick, NJ, United States - **Experience:** Experienced - **Salary:** $79,000.0 - $142,000.0 - **Contract:** Permanent contract - **Skills:** Software System Penetration Testing, Cloud Computing, Cyber Security, Computer Engineering, Human-Computer Interaction, Open Web Application Security, Program Analysis, Secure Coding, Software Engineering, Software Security, Information Technology, Static Application Security Testing, Vulnerability Analysis, Dynamic Application Security Testing - **Published:** September 24, 2026 - **Apply:** https://www.techcareers.com/job.asp?id=3402950441&tx=JP10801LFU&pt=1&aff=0B19D771-A501-4A5E-8338-2A822B784D54&utm_source=Job%20Feed&utm_medium=textkernel&utm_campaign=DE&utm_term=0B19D771-A501-4A5E-8338-2A822B784D54 ## About the Role * Required: Bachelor's degree in Computer Science, Engineering, Information Security, or a related technical field. * Preferred: Master's degree in Cybersecurity, Computer Engineering, or a related discipline., * 2-4 years of relevant professional experience in cybersecurity, product security, or secure software development. * Working knowledge of secure development lifecycle (SDLC) practices and security-by-design principles. * Experience conducting security risk assessments, threat modeling, or vulnerability analysis. * Familiarity with common security standards and frameworks (e.g., ISO, NIST, OWASP). * Ability to collaborate effectively with cross-functional technical and non-technical teams. * Strong analytical, documentation, and communication skills., * Experience supporting cybersecurity activities in a regulated industry (medical devices, healthcare, or life sciences). * Hands-on exposure to security testing tools and techniques (e.g., SAST, DAST, dependency scanning). * Knowledge of cloud, embedded, or connected device security concepts. * Understanding of regulatory cybersecurity expectations (e.g., FDA premarket/postmarket guidance). * Experience contributing to internal security policies, standards, or governance processes., * Language: English proficiencyrequired. * Travel: Up to 10% domestic travel. * Certifications (Preferred): CISSP, CSSLP, GSEC, or equivalent security certification., Analytical Reasoning, Coaching, Communication, Cross-Functional Collaboration, Demand Forecasting, Human-Computer Interaction (HCI), Persistence and Tenacity, Product Costing, Product Development, Product Strategies, Quality Assurance (QA), Research and Development, Researching, Software Development Management, Technical Credibility, Technologically Savvy ## Description DePuy Synthes is recruiting for a(n) Exp, Analyst, Security Engineer Product located in New Brunswick, NJ or West Chester, PA or Palm Beach Gardens, FL or Warsaw, IN or Raynham, MA., This role supports the protection of DePuy Synthes digital products and connected medical technologies by embedding security practices throughout the product lifecycle. The Exp, Analyst, Security Engineer Product partners closely with engineering, quality, regulatory, and IT teams to identify risks early, design secure solutions, and ensure products meet cybersecurity and regulatory expectations. This is an exciting opportunity to directly impact patient safety and product trust while working in a highly regulated, innovation-driven environment and reports into the DePuy Synthes Technology organization., * Integrate security requirements and controls into the design and development of digital and connected products. * Perform product security risk assessments, threat modeling, and vulnerability analysis across the product lifecycle. * Partner with product development, quality, and regulatory teams to support secure design reviews and remediation activities. * Support security testing activities, including static and dynamic analysis, penetration testing coordination, and vulnerability validation. * Track, document, and manage product security findings to closure in alignment with internal governance processes. * Contribute to the development and maintenance of product security standards, procedures, and best practices. * Monitor emerging cybersecurity threats, vulnerabilities, and regulatory guidance relevant to medical devices and digital health. * Support audits, assessments, and regulatory inquiries related to product cybersecurity., Johnson & Johnson announced plans to separate our Orthopaedics business to establish a standalone orthopaedics company, operating as DePuy Synthes. The process of the planned separation is anticipated to be completed within 18 to 24 months, subject to legal requirements, including consultation with works councils and other employee representative bodies, as may be required, regulatory approvals and other customary conditions and approvals. Should you accept this position, it is anticipated that, following conclusion of the transaction, you would be an employee of DePuy Synthes and your employment would be governed by DePuy Synthes employment processes, programs, policies, and benefit plans. In that case, details of any planned changes would be provided to you by DePuy Synthes at an appropriate time and subject to any necessary consultation processes. ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Green Cloud Computing](https://www.wearedevelopers.com/videos/592-green-cloud-computing) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [How to Cause (or Prevent) a Massive Data Breach- Secure Coding and IDOR](https://www.wearedevelopers.com/videos/39-how-to-cause-or-prevent-a-massive-data-breach-secure-coding-and-idor) - [Reporting Active Exploits in 24 Hours: Are You Ready for the CRA?](https://www.wearedevelopers.com/videos/100248-reporting-active-exploits-in-24-hours-are-you-ready-for-the-cra) - [Cyber Security: Small, and Large!](https://www.wearedevelopers.com/videos/259-cyber-security-small-and-large) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [The Most Popular IT Jobs on the Market](https://www.wearedevelopers.com/magazine/376-the-most-popular-it-jobs-on-the-market) - [What’s the Difference between a Junior, Mid, and Senior Developer?](https://www.wearedevelopers.com/magazine/238-what-s-the-difference-between-a-junior-mid-and-senior-developer) - [Best Paying Jobs in Technology](https://www.wearedevelopers.com/magazine/256-best-paying-jobs-in-technology) - [The 12 Best Jobs for Software Engineers](https://www.wearedevelopers.com/magazine/401-the-12-best-jobs-for-software-engineers) - [Why Upskilling And Reskilling is Important For Developers](https://www.wearedevelopers.com/magazine/428-why-upskilling-and-reskilling-is-important-for-developers)