Product Security Vulnerability Management Lead

4 weeks ago


Salt Lake, Utah, United States J&J Family of Companies Full time
Job Summary

We are seeking a highly skilled Product Security Vulnerability Management Specialist to join our team at Johnson & Johnson. The successful candidate will play a key role in implementing the ISRM Product Security Vulnerability Management Process, supporting identified key strategies and goals, and collaborating with internal organizations on existing process and policy enhancements.

This role will be responsible for creating and communicating metrics to MedTech management, supporting communications plans, and raising overall awareness of the capability. The Product Security Vulnerability Management Specialist will also support MedTech Business Units throughout the post-market phase, review product vulnerabilities, and recommend security design solutions.

Key Responsibilities:

  • Support the integration of vulnerability management and provide inputs to initiatives that bolster the cybersecurity resiliency throughout the MedTech business.
  • Ensure cybersecurity-enabled products or other compensating security control technologies reduce identified risk to an acceptable level.
  • Perform cyber defense trend analysis and reporting.
  • Map event correlation using information gathered from a variety of sources within the enterprise to gain situational awareness and determine the effectiveness of an observed attack.
  • Participate in security reviews and identify security gaps in security architecture resulting in recommendations for inclusion in the risk mitigation strategy using threat modeling.
  • Conduct research, analysis, and correlation across a wide variety of all-source data sets (indications and warnings).
  • Collaborate with other ISRM capabilities to ensure risk analysis (e.g., threat, vulnerability, and probability of occurrence) whenever high exploit vulnerabilities occur.
  • Provide input to the Risk Management Framework process activities and related documentation (e.g., system life-cycle support plans, concept of operations, operational procedures, and maintenance training materials).
  • Support the creation of plans of action and milestones or remediation plans are in place for vulnerabilities identified during risk assessments.
  • Contributes with the Coordinated Vulnerability Disclosure process through the generation of vulnerability memos.

Requirements:

  • Bachelor's degree or equivalent in Computer Science or similar engineering discipline.
  • Minimum 8 years relevant experience, or equivalent combination of education/experience.
  • Must be experienced in Vulnerability Management, including scanning, remediation, stakeholder engagement, system administration, and engineering.
  • Experience with SBOM creation/scanning automation.

Preferred Skills:

  • Experienced in the following domains: APIs Security, Vulnerability Scan, compliance and threat detection, OWASP Top 10 API Security, Web App Security, AppSec, SAST, DAST, and SCA (Software composition analysis).
  • Experience or good understanding of the different enterprise components to publish and use APIs (e.g., API Gateways (Apigee), Microservices, Cloud Components, Load Balancers, WAFs).
  • Experience with API security testing, vulnerability scan, and compliance reporting.
  • Experience with OWASP Top 10 for Web App & APIs.
  • Experience with Postman Collections, Swagger, OpenAPI, and other common formats for organizing and functionally testing REST APIs.
  • Excellent analytical, written, and verbal communication skills – capable of explaining complex requirements in simple words.
  • Any programming or integration experience in the past will be highly beneficial.
  • Healthcare medical equipment network integration management experience.
  • Cybersecurity management experience, preferably with medical devices.

Location:

This position can be located anywhere in the United States and may require up to 10% travel.

Johnson & Johnson is an Affirmative Action and Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, age, national origin, or protected veteran status and will not be discriminated against on the basis of disability.

The anticipated base pay range for this position is $99,000 to $170,200. The Company maintains highly competitive, performance-based compensation programs. Under current guidelines, this position is eligible for an annual performance bonus in accordance with the terms of the applicable plan.

Employees and/or eligible dependents may be eligible to participate in the following Company-sponsored employee benefit programs: medical, dental, vision, life insurance, short- and long-term disability, business accident insurance, and group legal insurance.

Employees may be eligible to participate in the Company's consolidated retirement plan (pension) and savings plan (401(k)).

Employees are eligible for the following time off benefits:

  • Vacation – up to 120 hours per calendar year.
  • Sick time - up to 40 hours per calendar year; for employees who reside in the State of Washington – up to 56 hours per calendar year.
  • Holiday pay, including Floating Holidays – up to 13 days per calendar year of Work, Personal and Family Time - up to 40 hours per calendar year.


  • Salt Lake, Utah, United States L3 Technologies Full time

    Job Title:Lead Information Security Systems EngineerJob Overview:This Subject Matter Expert will apply current systems security engineering methods, practices and technologies to the architecture, design, development, evaluation and integration of systems and networks to maintain system security and execute system CONOPS.Key Responsibilities:Works with...


  • Salt Lake, Utah, United States Confluent Full time

    About ConfluentWe are a company that helps organizations harness the power of data to innovate and win in the modern digital world. Our purpose is to create an entirely new category within data infrastructure - data streaming. This technology will allow every organization to create experiences and use the power of data in ways that profoundly impact the way...


  • Salt Lake, Utah, United States Motorola Full time

    Company OverviewMotorola Solutions is a leading provider of mission-critical communications and public safety solutions. Our goal is to help people be their best in the moments that matter.We achieve this by building innovative technologies that solve for safer across every part of our safety and security ecosystem.This includes mission-critical...


  • Salt Lake, Utah, United States Motorola Full time

    At Motorola Solutions, we're committed to creating a safer world through innovative technologies. As a Cloud Security Architect, you'll play a critical role in ensuring the security and compliance of our cloud platform and products.The Cloud Platform Engineering department builds, operates, and manages the platform for the Public Safety Application Software...


  • Salt Lake, Utah, United States Motorola Full time

    At Motorola Solutions, we're driven by a shared purpose - to help people be their best in the moments that matter. Our Cloud Platform Engineering department builds, operates, and manages the platform for the Public Safety Application Software as a Service (SaaS) from Motorola Solutions Inc.You will work with a top-notch team that employs cutting-edge tools...


  • Salt Lake, Utah, United States Apothecarie Full time

    We are Apothecarie, a team of entrepreneurs, innovators, and self-starters building cutting-edge MarTech solutions from the ground up. To support our growth, we are seeking a seasoned Cybersecurity Engineer - Infrastructure Security to lead our cyber security efforts. This role is ideal for a problem solver and collaborator who thrives in a fast-paced...


  • Salt Lake, Utah, United States Lucid Software Full time

    About the Role:Lucid Software is a leader in visual collaboration, helping teams see and build the future from idea to reality. As a Senior Security Assurance Analyst, you will leverage your cybersecurity knowledge and expertise to protect corporate information assets, demonstrate compliance with industry frameworks, and promote confidence in Lucid's...


  • Salt Lake, Utah, United States Lucid Software Full time

    About the Role:Lucid Software is a leader in visual collaboration, helping teams see and build the future from idea to reality. As a Senior Security Assurance Analyst, you will leverage your cybersecurity knowledge and expertise to protect corporate information assets, demonstrate compliance with industry frameworks, and promote confidence in Lucid's...

  • Security Professional

    4 weeks ago


    Salt Lake, Utah, United States All Pro Security Full time

    Job Title: Security Officer - Unarmed/Armed GuardAbout All Pro Security:All Pro Security has earned a reputation as one of Utah's leading security companies, recognized as Best of State for Security Services and listed on the Inc 5000 as one of the fastest-growing companies in the U.S. Our mission is to protect our clients and their property while offering...


  • Salt Lake, Utah, United States Sorenson Communications Full time

    Senior Information Security OfficerWe are seeking an experienced Senior Information Security Officer to join our team at Sorenson Communications. This is a critical role that will lead the development and implementation of our information security strategy, ensuring the confidentiality, integrity, and availability of our information assets. The ideal...


  • Salt Lake, Utah, United States L3Harris Full time

    Job Title: Senior Cybersecurity Systems EngineerJob Overview:This Senior Cybersecurity Systems Engineer will apply current systems security engineering methods, practices, and technologies to the architecture, design, development, evaluation, and integration of systems and networks to maintain system security and execute system CONOPS.The Lead will work...


  • Salt Lake, Utah, United States Sorenson Communications Full time

    Job SummaryThe Senior Information Security Officer will be responsible for assisting the CISO in developing and implementing the overall information security strategy. This includes providing leadership and direction to the information security team, ensuring alignment with organizational goals, and collaborating with other departments to integrate security...


  • Salt Lake, Utah, United States L3Harris Technologies Full time

    Job Title: Senior Cybersecurity Systems EngineerJob Location: RemoteJob Code: 15721Job Schedule: Flexible Position Overview:L3Harris Technologies is seeking a highly skilled Senior Cybersecurity Systems Engineer to join our team. As a Senior Cybersecurity Systems Engineer, you will apply current systems security engineering methods, practices, and...


  • Salt Lake, Utah, United States MasterCard Full time

    About the Role:The Account Opening and Identity team at Mastercard is seeking a highly motivated and analytical Specialist, Product Management to drive our customer experience strategy forward by consistently innovating and problem-solving.The ideal candidate is passionate about the customer experience journey, highly motivated, intellectually curious, and...


  • Salt Lake, Utah, United States MasterCard Full time

    About the RoleThe Account Opening and Identity team at Mastercard is seeking a highly motivated and analytical Specialist, Product Management to drive our customer experience strategy forward by consistently innovating and problem-solving. The ideal candidate is passionate about the customer experience journey, intellectually curious, and possesses an...

  • Production Manager

    3 weeks ago


    Salt Lake, Utah, United States CRH Full time

    Production Manager Job SummaryCRH is seeking a Production Manager to lead our manufacturing team. As a key member of our operations team, you will be responsible for ensuring the efficient production of high-quality products while maintaining a safe and healthy work environment.Key Responsibilities:Plan and direct production activities to meet customer...


  • Salt Lake, Utah, United States VLCM Full time

    Job SummaryWe are seeking a highly skilled Network Security Specialist to join our team at VLCM. As a Network Security Specialist, you will be responsible for designing, implementing, and managing firewall solutions to protect our clients' networks.Key Responsibilities:Design and implement firewall solutions that align with our clients' security policies and...


  • Salt Lake, Utah, United States VLCM Full time

    Job OverviewVLCM is seeking a skilled Firewall Engineer to join our team. As a key member of our IT security team, you will be responsible for designing, implementing, and managing firewall solutions to protect our clients' networks.Key Responsibilities:Design and implement firewall solutions that align with our clients' security policies and regulatory...

  • Production Manager

    3 weeks ago


    Salt Lake, Utah, United States Curaleaf Full time

    Job DescriptionWe are seeking a highly skilled Production Manager to oversee and manage personnel in our production department. The ideal candidate will have a strong background in manufacturing operations and a proven track record of ensuring high-quality products.Key Responsibilities:Oversee production operations to ensure timely and efficient delivery of...

  • Security Officer

    4 weeks ago


    Salt Lake, Utah, United States All Pro Security Full time

    About the RoleAs a Security Officer with All Pro Security, you will be responsible for providing exceptional customer service and maintaining professionalism in all interactions. You will serve a variety of clients, ranging from managing access at office buildings to patrolling residential communities and protecting construction sites and businesses from...