Product Security Vulnerability Management Lead

1 day ago


Salt Lake, Utah, United States J&J Family of Companies Full time
Job Summary

We are seeking a highly skilled Product Security Vulnerability Management Specialist to join our team at Johnson & Johnson. The successful candidate will play a key role in implementing the ISRM Product Security Vulnerability Management Process, supporting identified key strategies and goals, and collaborating with internal organizations on existing process and policy enhancements.

This role will be responsible for creating and communicating metrics to MedTech management, supporting communications plans, and raising overall awareness of the capability. The Product Security Vulnerability Management Specialist will also support MedTech Business Units throughout the post-market phase, review product vulnerabilities, and recommend security design solutions.

Key Responsibilities:

  • Support the integration of vulnerability management and provide inputs to initiatives that bolster the cybersecurity resiliency throughout the MedTech business.
  • Ensure cybersecurity-enabled products or other compensating security control technologies reduce identified risk to an acceptable level.
  • Perform cyber defense trend analysis and reporting.
  • Map event correlation using information gathered from a variety of sources within the enterprise to gain situational awareness and determine the effectiveness of an observed attack.
  • Participate in security reviews and identify security gaps in security architecture resulting in recommendations for inclusion in the risk mitigation strategy using threat modeling.
  • Conduct research, analysis, and correlation across a wide variety of all-source data sets (indications and warnings).
  • Collaborate with other ISRM capabilities to ensure risk analysis (e.g., threat, vulnerability, and probability of occurrence) whenever high exploit vulnerabilities occur.
  • Provide input to the Risk Management Framework process activities and related documentation (e.g., system life-cycle support plans, concept of operations, operational procedures, and maintenance training materials).
  • Support the creation of plans of action and milestones or remediation plans are in place for vulnerabilities identified during risk assessments.
  • Contributes with the Coordinated Vulnerability Disclosure process through the generation of vulnerability memos.

Requirements:

  • Bachelor's degree or equivalent in Computer Science or similar engineering discipline.
  • Minimum 8 years relevant experience, or equivalent combination of education/experience.
  • Must be experienced in Vulnerability Management, including scanning, remediation, stakeholder engagement, system administration, and engineering.
  • Experience with SBOM creation/scanning automation.

Preferred Skills:

  • Experienced in the following domains: APIs Security, Vulnerability Scan, compliance and threat detection, OWASP Top 10 API Security, Web App Security, AppSec, SAST, DAST, and SCA (Software composition analysis).
  • Experience or good understanding of the different enterprise components to publish and use APIs (e.g., API Gateways (Apigee), Microservices, Cloud Components, Load Balancers, WAFs).
  • Experience with API security testing, vulnerability scan, and compliance reporting.
  • Experience with OWASP Top 10 for Web App & APIs.
  • Experience with Postman Collections, Swagger, OpenAPI, and other common formats for organizing and functionally testing REST APIs.
  • Excellent analytical, written, and verbal communication skills – capable of explaining complex requirements in simple words.
  • Any programming or integration experience in the past will be highly beneficial.
  • Healthcare medical equipment network integration management experience.
  • Cybersecurity management experience, preferably with medical devices.

Location:

This position can be located anywhere in the United States and may require up to 10% travel.

Johnson & Johnson is an Affirmative Action and Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, age, national origin, or protected veteran status and will not be discriminated against on the basis of disability.

The anticipated base pay range for this position is $99,000 to $170,200. The Company maintains highly competitive, performance-based compensation programs. Under current guidelines, this position is eligible for an annual performance bonus in accordance with the terms of the applicable plan.

Employees and/or eligible dependents may be eligible to participate in the following Company-sponsored employee benefit programs: medical, dental, vision, life insurance, short- and long-term disability, business accident insurance, and group legal insurance.

Employees may be eligible to participate in the Company's consolidated retirement plan (pension) and savings plan (401(k)).

Employees are eligible for the following time off benefits:

  • Vacation – up to 120 hours per calendar year.
  • Sick time - up to 40 hours per calendar year; for employees who reside in the State of Washington – up to 56 hours per calendar year.
  • Holiday pay, including Floating Holidays – up to 13 days per calendar year of Work, Personal and Family Time - up to 40 hours per calendar year.


  • Salt Lake, Utah, United States L3Harris Technologies Full time

    Job Title: Lead Information Security Systems EngineerJob Location: Salt Lake City, UTJob Code: 16381Job Schedule: 9/80, every other Friday offJob Description:This Subject Matter Expert will apply current systems security engineering methods, practices, and technologies to the architecture, design, development, evaluation, and integration of systems and...


  • Salt Lake, Utah, United States Highmark Health Full time

    Job SummaryThis role provides Information Security and Risk Management services for the Organization. The successful candidate will work with peers within security, EnGen customers, and application teams to ensure alignment with current and future security needs. They will manage activities of various Information Security personnel, make decisions on...


  • Salt Lake, Utah, United States L3Harris Technologies Full time

    Job Title: Lead Cybersecurity Systems EngineerAt L3Harris Technologies, we are seeking a highly skilled Lead Cybersecurity Systems Engineer to join our team. As a key member of our cybersecurity team, you will be responsible for applying current systems security engineering methods, practices, and technologies to the architecture, design, development,...


  • Salt Lake, Utah, United States L3Harris Technologies Full time

    Job Title: Lead Cybersecurity Systems EngineerJob Location: Salt Lake City, UTJob Code: 15816Job Schedule: 9/80, every other Friday offJob Summary:This Subject Matter Expert will apply current systems security engineering methods, practices, and technologies to the architecture, design, development, evaluation, and integration of systems and networks to...


  • Salt Lake, Utah, United States Idaho Scientific Full time

    Job DescriptionIdaho Scientific is seeking a highly skilled Senior System Security Engineer to join our team. As a subject matter expert in anti-tamper, cyber security, and supply chain trust, you will be responsible for designing and deploying secure system solutions through novel CPU design, crypto cores, purpose-built system-on-a-chip architectures, and...


  • Salt Lake, Utah, United States Idaho Scientific Full time

    Job DescriptionIdaho Scientific is seeking a highly skilled Senior System Security Engineer to join our team. As a subject matter expert in anti-tamper, cyber security, and supply chain trust, you will be responsible for designing and deploying secure system solutions through novel CPU design, crypto cores, purpose-built system-on-a-chip architectures, and...


  • Salt Lake, Utah, United States Lucid Software Full time

    Job Title: Senior Security Assurance AnalystLucid Software is a leader in visual collaboration, helping teams see and build the future from idea to reality. We value innovation, passion, and excellence in every area, individual empowerment, initiative, and ownership, and teamwork over ego. Our company culture is respectful and inclusive for everyone.We...


  • Salt Lake, Utah, United States Lucid Software Full time

    About the Role:We are seeking a highly skilled Senior Security Assurance Analyst to join our team at Lucid Software. As a key member of our security team, you will be responsible for protecting corporate information assets, demonstrating compliance with industry frameworks, and promoting confidence in our security program both internally and...


  • Salt Lake, Utah, United States Department Of Homeland Security Full time

    About the JobAt the Department of Homeland Security, we are seeking a highly skilled Transportation Security Specialist- Explosives to join our team. As a key member of our security team, you will play a critical role in ensuring the safety and security of our transportation systems.Key ResponsibilitiesAssess threats and apply technical knowledge of...


  • Salt Lake, Utah, United States Patterned Learning AI Full time

    Job DescriptionPatterned Learning AI is seeking a skilled Application Security Specialist to join our team. As a champion for our digital security, you will conduct comprehensive assessments of our applications and software, proactively identifying and mitigating vulnerabilities to safeguard us from cyber threats.Key Responsibilities:Lead the application...


  • Salt Lake, Utah, United States Motorola Full time

    At Motorola Solutions, we're driven by a shared purpose - to help people be their best in the moments that matter. Our Cloud Platform Engineering department builds, operates, and manages the platform for the Public Safety Application Software as a Service (SaaS) from Motorola Solutions Inc.You will work with a top-notch team that employs cutting-edge tools...


  • Salt Lake, Utah, United States Legato Security Full time

    Job Title: Firewall EngineerLegato Security is seeking a skilled Firewall Engineer to join our team in Salt Lake City, UT. This exciting opportunity offers a chance to enhance your expertise and progress in the cybersecurity field.Job SummaryWe are looking for a highly motivated and analytical individual to design and implement new network solutions,...

  • Security Officer

    4 weeks ago


    Salt Lake, Utah, United States Inter-Con Security Full time

    Job DetailsJob LocationSalt Lake City, UTPosition TypeFull TimeSalary Range$19.45 HourlyJob ShiftSwingDescriptionAt Inter-Con Security, we pride ourselves on providing customized security solutions that meet the unique needs of our clients. As an Unarmed Security Officer, you will be part of a highly trained security team that supports critical facilities...


  • Salt Lake, Utah, United States Legato Security Full time

    Job Title: Firewall EngineerWe are seeking a highly skilled Firewall Engineer to join our team at Legato Security in Salt Lake City, UT. As a key member of our security operations team, you will be responsible for designing and implementing network solutions, configuring firewalls, and maximizing network performance.Key Responsibilities:Design and implement...


  • Salt Lake, Utah, United States All Pro Security Full time

    Job Title: Security Officer - Unarmed/Armed GuardAbout All Pro Security:All Pro Security has earned a reputation as one of Utah's leading security companies, recognized as Best of State for Security Services and listed on the Inc 5000 as one of the fastest-growing companies in the U.S. Our mission is to protect our clients and their property while offering...


  • Salt Lake, Utah, United States Wells Fargo Full time

    About this Role:Wells Fargo is seeking a seasoned Digital Product Manager to lead the development and execution of complex digital business plans, programs, and initiatives that drive business outcomes across the enterprise.The ideal candidate will have a strong background in digital product management, with experience in building strategies and requirements...

  • Senior Product Owner

    3 weeks ago


    Salt Lake, Utah, United States Marriott Full time

    Job SummaryMarriott International is seeking a highly skilled Senior Product Owner - Exchange/Email Security to join our team. As a key member of our IT organization, you will be responsible for designing, implementing, and maintaining the Exchange/Email Security infrastructure. You will work closely with IT teams, security professionals, and business...


  • Salt Lake, Utah, United States Public Consulting Group Full time

    Job Title: Information Security EngineerPublic Consulting Group LLC (PCG) is a leading public sector solutions implementation and operations improvement firm that partners with health, education, and human services agencies to improve lives.As a key member of our team, you will play a pivotal role in safeguarding PCG's information, brand, digital assets, and...


  • Salt Lake, Utah, United States Sunstates Security Full time

    Business Development ManagerSunstates Security, a leading provider of security services, is seeking a talented Business Development Manager to join our Utah region team. As a key member of our sales team, you will be responsible for generating leads, closing new business, and building market position.Key Responsibilities:Identify decision makers and analyze...


  • Salt Lake, Utah, United States Patterned Learning AI Full time

    Job Title: Junior Application Security AnalystJoin Patterned Learning AI as a Junior Application Security Analyst and play a vital role in safeguarding our company's digital assets. As a champion for our digital security, you will conduct comprehensive assessments of our applications and software, proactively identifying and mitigating vulnerabilities to...