ForgeApply · Job listing
Senior Manager, Product Security - Shockwave Medical
Johnson & Johnson
Tailor your resume for this Johnson & Johnson job in about a minute.
ForgeApply tailors your resume and cover letter to this exact posting, then hands you a ready-to-submit application for Johnson & Johnson's site. Free trial, no card required.
About this role
At Johnson & Johnson, we believe health is everything. Our strength in healthcare innovation empowers us to build a world where complex diseases are prevented, treated, and cured, where treatments are smarter and less invasive, and solutions are personal. Through our expertise in Innovative Medicine and MedTech, we are uniquely positioned to innovate across the full spectrum of healthcare solutions today to deliver the breakthroughs of tomorrow, and profoundly impact health for humanity. Learn more at jnj.com
As guided by Our Credo, Johnson & Johnson is responsible to our employees who work with us throughout the world. We provide an inclusive work environment where each person is considered as an individual. At Johnson & Johnson, we respect the diversity and dignity of our employees and recognize their merit.
Job Function: Technology Enterprise Strategy & Security
Job Sub Function: Security & Controls
Job Category: People Leader
All Job Posting Locations: Santa Clara, California, United States of America
Job Description: Johnson & Johnson is hiring for a Sr. Manager, Product Security – Shockwave Medical to join our team located in Santa Clara, CA.
At Johnson & Johnson, we believe health is everything. Our strength in healthcare innovation empowers us to build a world where complex diseases are prevented, treated, and cured, where treatments are smarter and less invasive, and solutions are personal. Through our expertise in Innovative Medicine and MedTech, we are uniquely positioned to innovate across the full spectrum of healthcare solutions today to deliver the breakthroughs of tomorrow, and profoundly impact health for humanity. Learn more at https://www.jnj.com/ .
Fueled by innovation at the intersection of biology and technology, we’re developing the next generation of smarter, less invasive, more personalized treatments. Ready to join a team that’s pioneering the development and commercialization of Intravascular Lithotripsy (IVL) to treat complex calcified cardiovascular disease. Our Shockwave Medical portfolio aims to establish a new standard of care for medical device treatment of atherosclerotic cardiovascular disease through its differentiated and proprietary local delivery of sonic pressure waves for the treatment of calcified plaque.
Position Overview The Sr. Manager, Product Security provides technical leadership supporting product cybersecurity strategy and execution. This position is responsible for defining secure architecture patterns and controls for medical devices and guiding advanced security real-world testing approaches. The position partners closely with engineering, quality, PMO, and regulatory to translate global cybersecurity expectations into practical and scalable engineering solutions.
Essential Job Functions • serve as the functional owner of product security within the Business Unit, accountable for defining, governing, and ensuring execution of product security processes and tools in alignment with J&J Quality Standards. • Define and architect defense in depth security controls including hardware root of trust, secure boot, cryptographic services (PKI/TLS), identity and access management, secure update mechanisms, and trusted device to cloud communications. • Conduct medical devices threat modeling, secure design reviews, and cyber risk assessments for new and existing product platforms. • Support cybersecurity submission readiness by contributing technical direction, regulatory evidence, architecture rationale, and risk mitigation strategies. • Lead emerging cyber technologies (AI and Quantum Cryptography) for medical devices and that will be impacted by cybersecurity. Make internal and external policy recommendations to mitigate threats and vulnerabilities. • Provide technical leadership supporting cyber architecture, penetration testing approaches, advanced real-world security testing methodologies, and risk-based validation strategies. • Drive integration of security tooling and controls into Business Units CI/CD pipelines, including static analysis, software composition analysis, component/sub-systems security, and SBOM generation. • Define secure build, release, and patching architecture patterns aligned with regulatory expectations. Promote scalable shift-left security practices across each product release. • Act as a trusted cybersecurity architect advisor to R&D, engineering leaders, quality, regulatory, PMOS, and commercial teams • Partner with engineering and quality teams to prioritize and track mitigation of identified cybersecurity risks. • Support cybersecurity regulatory expectations (e.g., FDA guidance, global cybersecurity standards) into implementable engineering requirements and QMS procedures. • Drive Post Market cybersecurity monitoring, risk management, including threat monitoring, and formal risk dispositioning decisions. • Define and execute patching and mitigation strategies, supporting coordinated disclosure, regulatory reporting, and field actions in alignment with FDA expectations. • Other duties as needed.
Requirements • Bachelor’s degree in Engineering, Cybersecurity, STEM or related field, or equivalent work experience. • 12+ years of MedTech experience in R&D, engineering, product development, medical devices, or product security. • Strong technical understanding of software development languages, preferred with C, C++, Python, and Groovy to support secure architecture reviews, threat modeling, vulnerability analysis, and DevSecOps enablement across product teams. • Experience integrating DevSecOps capabilities into CI/CD pipelines using Jenkins and Bitbucket Cloud, including SAST/SCA tooling (Black Duck, Checkmarx, Snyk), SBOM generation, secure code review, artifact signing, and automated security validation. • Expertise in Class I, Class II, and Class III medical devices, including 510(k) and PMA submissions. Experience with medical devices, and/or connected product solutions. • Experience implementing
Tailor your resume for this Johnson & Johnson role before you apply.
Tailor my resume for this jobSimilar jobs
- Senior Security Engineering Manager, Product Security — Upstart · Remote
- Senior Engineering Manager, Product Security — Monarchmoney · Remote
- Sr. Clinical Quality Auditor - Shockwave Medical — Johnson & Johnson · Remote
- Sr. Clinical Quality Auditor - Shockwave Medical — Johnson & Johnson · Remote
- Principal Project Manager (US Commercial)- Shockwave Medical — Johnson & Johnson · Remote
- Staff NPI Engineer - Shockwave Medical — Johnson & Johnson · Santa Clara, California, United States
- Manager, Product Security Engineering — Dragos · Remote
- Sr Product Analyst, PLM - Shockwave Medical — Johnson & Johnson · Santa Clara, California, United States
More like this: More jobs at Johnson & Johnson · Browse all jobs
Free ATS checker · How to Tailor Your Resume to a Job Description (Step by Step)