Senior Manager, Product Security - Shockwave Medical

Johnson & Johnson Innovative MedicineSanta Clara, CA
$142,000 - $244,950Onsite

About The Position

Johnson & Johnson is hiring for a Sr. Manager, Product Security – Shockwave Medical to join our team located in Santa Clara, CA. At Johnson & Johnson, we believe health is everything. Our strength in healthcare innovation empowers us to build a world where complex diseases are prevented, treated, and cured, where treatments are smarter and less invasive, and solutions are personal. Through our expertise in Innovative Medicine and MedTech, we are uniquely positioned to innovate across the full spectrum of healthcare solutions today to deliver the breakthroughs of tomorrow, and profoundly impact health for humanity. Fueled by innovation at the intersection of biology and technology, we’re developing the next generation of smarter, less invasive, more personalized treatments. Ready to join a team that’s pioneering the development and commercialization of Intravascular Lithotripsy (IVL) to treat complex calcified cardiovascular disease. Our Shockwave Medical portfolio aims to establish a new standard of care for medical device treatment of atherosclerotic cardiovascular disease through its differentiated and proprietary local delivery of sonic pressure waves for the treatment of calcified plaque.

Requirements

  • Bachelor’s degree in Engineering, Cybersecurity, STEM or related field, or equivalent work experience.
  • 12+ years of MedTech experience in R&D, engineering, product development, medical devices, or product security.
  • Strong technical understanding of software development languages, preferred with C, C++, Python, and Groovy to support secure architecture reviews, threat modeling, vulnerability analysis, and DevSecOps enablement across product teams.
  • Experience integrating DevSecOps capabilities into CI/CD pipelines using Jenkins and Bitbucket Cloud, including SAST/SCA tooling (Black Duck, Checkmarx, Snyk), SBOM generation, secure code review, artifact signing, and automated security validation.
  • Expertise in Class I, Class II, and Class III medical devices, including 510(k) and PMA submissions. Experience with medical devices, and/or connected product solutions.
  • Experience implementing hardware and software security, including secure screws, tamper seals, physical port blocking, enclosure access detection, secure boot and system integrity, trusted hardware, secure coding, identity and access management, PKI, integrating security into the development lifecycle (DevSecOps) and manufacturing lifecycle.
  • Demonstrated expertise in secure architecture design and security testing of connected or embedded systems.
  • Experience integrating security controls into DevSecOps environments and software delivery pipelines as well in manufacturing environments.
  • Experience with medical device cybersecurity regulatory expectations and risk management framework, including FDA cybersecurity guidance, section 524B of the FD&C Act for cyber devices, ISO/IEC 81001-5-1, NIST CSF, NIST 800-175, FIPS 140-3, and IEC 62443 and global frameworks.
  • Demonstrated success bridging Engineering, Quality, Regulatory, Legal, Privacy, and Commercial functions. Strong ability to influence engineering teams and communicate complex technical concepts.

Nice To Haves

  • Preferred certifications: CISSP, CSSLP, CISM, CISA, or equivalent.

Responsibilities

  • Serve as the functional owner of product security within the Business Unit, accountable for defining, governing, and ensuring execution of product security processes and tools in alignment with J&J Quality Standards.
  • Define and architect defense in depth security controls including hardware root of trust, secure boot, cryptographic services (PKI/TLS), identity and access management, secure update mechanisms, and trusted device to cloud communications.
  • Conduct medical devices threat modeling, secure design reviews, and cyber risk assessments for new and existing product platforms.
  • Support cybersecurity submission readiness by contributing technical direction, regulatory evidence, architecture rationale, and risk mitigation strategies.
  • Lead emerging cyber technologies (AI and Quantum Cryptography) for medical devices and that will be impacted by cybersecurity. Make internal and external policy recommendations to mitigate threats and vulnerabilities.
  • Provide technical leadership supporting cyber architecture, penetration testing approaches, advanced real-world security testing methodologies, and risk-based validation strategies.
  • Drive integration of security tooling and controls into Business Units CI/CD pipelines, including static analysis, software composition analysis, component/sub-systems security, and SBOM generation.
  • Define secure build, release, and patching architecture patterns aligned with regulatory expectations. Promote scalable shift-left security practices across each product release.
  • Act as a trusted cybersecurity architect advisor to R&D, engineering leaders, quality, regulatory, PMOS, and commercial teams.
  • Partner with engineering and quality teams to prioritize and track mitigation of identified cybersecurity risks.
  • Support cybersecurity regulatory expectations (e.g., FDA guidance, global cybersecurity standards) into implementable engineering requirements and QMS procedures.
  • Drive Post Market cybersecurity monitoring, risk management, including threat monitoring, and formal risk dispositioning decisions.
  • Define and execute patching and mitigation strategies, supporting coordinated disclosure, regulatory reporting, and field actions in alignment with FDA expectations.
  • Other duties as needed.

Benefits

  • Consolidated retirement plan (pension)
  • Savings plan (401(k))
  • Long-term incentive program
  • Vacation –120 hours per calendar year
  • Sick time - 40 hours per calendar year (varies by state)
  • Holiday pay, including Floating Holidays –13 days per calendar year
  • Work, Personal and Family Time - up to 40 hours per calendar year
  • Parental Leave – 480 hours within one year of the birth/adoption/foster care of a child
  • Bereavement Leave – 240 hours for an immediate family member: 40 hours for an extended family member per calendar year
  • Caregiver Leave – 80 hours in a 52-week rolling period
  • Volunteer Leave – 32 hours per calendar year
  • Military Spouse Time-Off – 80 hours per calendar year
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service