← Back to search
Johnson & Johnson logo

Professional, Prog Lead, PenTesting Svcs

Johnson & Johnson · New Brunswick, NJ +4 more

RoleLantern checked
IT & SoftwareFull-timeCompany career page

The apply link worked recently (not employer-confirmed).

Role summary

Johnson & Johnson's DePuy Synthes division seeks a penetration testing program leader to design and manage offensive security services across medical devices, firmware, mobile applications, and cloud platforms. The role establishes testing methodology, embeds security gates into product development, manages internal and third-party testers, and translates technical findings into patient safety and business risk.

What they're looking for

  • Bachelor's degree in Computer Science, Cybersecurity, Engineering, or related technical discipline
  • Minimum 6 years progressive penetration testing, offensive security, or application security assessment experience
  • Demonstrated experience leading penetration testing program including methodology and vendor management
  • Hands-on proficiency in web, API, mobile, network, wireless, and cloud penetration testing
  • Proficiency with Burp Suite, Metasploit, Nmap, Wireshark, Ghidra/IDA, Kali and scripting languages
  • Strong knowledge of OWASP Top 10, CWE, CVSS, and industry frameworks including NIST and MITRE ATT&CK

What you'll be doing

  • Own end-to-end penetration testing program including annual roadmap, prioritization, and capacity planning
  • Define testing methodology, scoping standards, rules of engagement aligned to industry frameworks
  • Embed security testing gates into product development lifecycle at design and pre-release milestones
  • Manage third-party penetration testing vendors including scoping, SOW development, and performance oversight
  • Drive remediation with engineering teams, track findings through closure, and escalate overdue risks

Privacy & handoff

This role links to Johnson & Johnson's own application system. RoleLantern records your interest and checks the link, but the application happens on the employer's site and status updates may not come back to us. Clicking apply does not mark you as applied automatically.

What RoleLantern checked

This role is listed from an approved source. RoleLantern checks that the application link is live and how recently the role appeared — the employer has not confirmed it directly on RoleLantern.

RoleLantern checked active
RoleLantern checkedNeeds clarity
Date postedToday
Last source checkToday
Salary listedNeeds clarity
Location clearClear
Something look off? Let us know and we may ask the employer to verify it.

See how you match this role

Upload your CV to see which of this role's requirements your background supports, where there may be gaps, and what needs clarification. Private by default — we never sell your CV.

See my match

Similar roles

Johnson & Johnson logo
Exp, Analyst, Security Engineer Product
Johnson & Johnson · New Brunswick, NJ +4 more
AbbVie logo
Data Science Program Lead I - Neurology
AbbVie · Florham Park, NJ
Baxter logo
Principal Software Engineer – Android
Baxter · Skaneateles, NY
Ipsen logo
Global Digital & IT Transformation & Integration Lead
Ipsen · Cambridge
Johnson & Johnson logo
Senior Specialist, Source-to-Contract, IT NA
Johnson & Johnson · Distrito Capital, Colombia
Thermo Fisher Scientific logo
Sr Staff Architect, Software
Thermo Fisher Scientific · Karnātaka, India