US Jobs US Jobs     UK Jobs UK Jobs     EU Jobs EU Jobs


Professional, Prog Lead, PenTesting Svcs

At Johnson & Johnson,we believe health is everything.

Our strength in healthcare innovation empowers us to build aworld where complex diseases are prevented, treated, and cured,where treatments are smarter and less invasive, andsolutions are personal.Through our expertise in Innovative Medicine and MedTech, we are uniquely positioned to innovate across the full spectrum of healthcare solutions today to deliver the breakthroughs of tomorrow, and profoundly impact health for humanity.Learn more at jnj.com

As guided by Our Credo, Johnson & Johnson is responsible to our employees who work with us throughout the world.

We provide an inclusive work environment where each person is considered as an individual.

At Johnson & Johnson, we respect the diversity and dignity of our employees and recognize their merit.

Job Function:
Technology Enterprise Strategy & Security

Job Sub Function:
Solution Architecture

Job Category:
Scientific/Technology

All Job Posting Locations:
New Brunswick, New Jersey, United States of America, Palm Beach Gardens, Florida, United States of America, Raynham, Massachusetts, United States of America, Warsaw, Indiana, United States of America, West Chester, Pennsylvania, United States of America

Job Description:

DePuy Synthes is recruiting for a(n) Professional, Prog Lead, PenTesting Svcs located in New Brunswick, NJ or West Chester, PA or Palm Beach Gardens, FL or Warsaw, IN or Raynham, MA.

Job Overview

The Professional, Program Lead, Penetration Testing Services is a seasoned individual contributor within the Cybersecurity function, Product Security sub-function, accountable for building and running the penetration testing and offensive security services program for the DePuy Synthes product portfolio.

This role establishes the testing methodology , scoping standards, and engagement model that embed Secure by Design verification into the product development lifecycle - spanning medical devices, embedded firmware, mobile applications, APIs, and supporting cloud services.

The Program Lead manages internal testers and third-party assessment partners, translates technical findings into patient safety and business risk, and drives remediation to closure with R&D and engineering teams.

Applying advanced technical skills and industry-leading practices, this role serves as the authoritative voice on product security testing across the enterprise.

Key Responsibilities



* Own the end-to-end penetration testing services program for products and connected platforms, including the annual testing roadmap, prioritization model, and capacity planning across internal and external resources.



* Define and maintain the penetration testing methodology , scoping standards, rules of engagement, and reporting templates aligned to industry frameworks (OWASP, PTES, NIST SP 800-115, MITRE ATT&CK).



* Embed security testing gates into the product development lifecycle, ensuring Secure by Design verification occurs at defined desi...




Share Job