Principal, Security Architect
Brunswick, ME - USA
Job Summary
At Johnson & Johnsonwe believe health is everything. Our strength in healthcare innovation empowers us to build aworld where complex diseases are prevented treated and curedwhere treatments are smarter and less invasive andsolutions are our expertise in Innovative Medicine and MedTech we are uniquely positioned to innovate across the full spectrum of healthcare solutions today to deliver the breakthroughs of tomorrow and profoundly impact health for more at
As guided by Our Credo Johnson & Johnson is responsible to our employees who work with us throughout the world. We provide an inclusive work environment where each person is considered as an individual. At Johnson & Johnson we respect the diversity and dignity of our employees and recognize their merit.
Job Function:
Technology Enterprise Strategy & SecurityJob Sub Function:
Security & ControlsJob Category:
Scientific/TechnologyAll Job Posting Locations:
New Brunswick New Jersey United States of America Palm Beach Gardens Florida United States of America Raritan New Jersey United States of America Raynham Massachusetts United States of America Warsaw Indiana United States of America West Chester Pennsylvania United States of AmericaJob Description:
DePuy Synthes is recruiting for a Principal Security Architect located in the United States.
The Security Architect designs evaluates and strengthens the security architecture that protects DePuy Synthes technology assets data and operational environments. Sitting within the Technology Enterprise Strategy & Security organization this role serves as a technical authority on securitycontrolsassessing system and network configurations identifying vulnerabilities and exposures performing root-cause analysis and contributing to the design development and implementation of countermeasures and security tooling across the enterprise.
This roleis responsible foradvancing the organizationsZero Trust Secure by Design and Resilient by Designstrategy ensuring security and resilience are embedded into every technology platform architecture decision and transformation initiative.
Key Responsibilities
Lead the development of Secure by Design Resilient by Design and Zero Trustarchitecturesacross cloud network endpoint identity application data and OT environments.
Conduct security architecture reviews threat modeling and risk assessments for new and existing solutions.
Drive the enterprise Zero Trust strategy including identity segmentation least privilege and continuous verification capabilities.
Design network segmentation and micro-segmentation architectures to protect critical assets and reduce lateral movement.
Define vulnerability and exposure management strategies including risk-based prioritization and remediation.
Develop resilient security architectures that strengthen containment recovery and business continuity capabilities.
Design endpoint security controls hardening standards device compliance frameworks and EDR/XDR integrations.
Establish secure architectures for cloud AI data and application environments including secure developmentDevSecOps and AI governance practices.
Develop OT security architectures that protect manufacturinglaboratory and connected device environments.
Partner with Enterprise and Solution Architects to embed security resilience and compliance requirements across transformation initiatives.
Evaluatearchitecturesand configurations against frameworks including NIST NIST Zero Trust CIS ISO 27001 and applicable regulatory requirements.
Drive security automation tooling integrations and engineering improvements that enhance enterprise defenses.
Perform root-cause analysis of security findings and incidents recommending strategic and sustainable improvements.
Produce architecture standards reference designs technical documentation and executive-level roadmaps.
Mentor and coach security architects and engineers while fostering a culture of engineering excellence and continuous improvement.
Qualifications
Education:
Required:Bachelors degree in Computer Science Information Security Engineering ora relatedtechnical field.
Preferred: Masters degree in Cybersecurity Information Security ora relateddiscipline.
Experience and Skills:
Required:
8 years of experience in information security withdemonstrateddepth in security architecture and controls.
Hands-on experience with vulnerability and exposure management including assessment and remediation.
Strong knowledge of network security and segmentation firewalls and zero-trust architecture.
Experience designing endpoint protection and device security controls (e.g. EDR/XDR device hardening).
Experience withcloud security across one or more major platforms (AWS Azure or GCP) including secure configuration and workload protection.
Working knowledge of application and data security principles including secure SDLC and data protection.
Familiarity with industry frameworks and standards (e.g. NIST CSF ISO 27001 CIS Controls).
Preferred:
Experience securing Operational Technology (OT) and connected/IoT device environments.
Experience defining security controls for AI data and Generative AI solutions.
Experience in a regulated industry (MedTech Pharmaceutical or Healthcare) with familiarity in associated compliance requirements.
Experience with security automation SOAR and security tooling integration.
Experience supporting large-scale transformation or separation programs.
Other:
Travel: Up to 25%
Language: Englishproficiency.
Certifications: Relevant security certifications (e.g. CISSP CISSP-ISSAP CCSP SABSA or cloud security certifications) preferred.
Required Skills:
Preferred Skills:
Business Process Design Crisis Management Critical Thinking Information Security Auditing Information Security Management System (ISMS) Information Technology (IT) Security Assessments Information Technology Strategies Mentorship Organizing Presentation Design Process Optimization Root Cause Analysis (RCA) Security Architecture Design Security Policies Technical Credibility Vulnerability ManagementThe anticipated base pay range for this position is :
102000.00 - 204000.00 USD AnnualAdditional Description for Pay Transparency:
Subject to the terms of their respective plans employees are eligible to participate in the Companys consolidated retirement plan (pension) and savings plan (401(k)). Subject to the terms of their respective policies and date of hire employees are eligible for the following time off benefits: Vacation 120 hours per calendar year Sick time - 40 hours per calendar year; for employees who reside in the State of Colorado 48 hours per calendar year; for employees who reside in the State of Washington 56 hours per calendar year Holiday pay including Floating Holidays 13 days per calendar year Work Personal and Family Time - up to 40 hours per calendar year Parental Leave 480 hours within one year of the birth/adoption/foster care of a child Bereavement Leave 240 hours for an immediate family member: 40 hours for an extended family member per calendar year Caregiver Leave 80 hours in a 52-week rolling period10 days Volunteer Leave 32 hours per calendar year Military Spouse Time-Off 80 hours per calendar year For additional general information on Company benefits please go to: - Experience:Staff IC
About Company
About Johnson & Johnson A t Johnson & Johnson, we believe good health is the foundation of vibrant lives, thriving communities and forward progress. That’s why for more than 130 years, we have aimed to keep people well at every age and every stage of life. Today, as the world’s larges ... View more