What are the responsibilities and job description for the Manager, Product Security DevSecOps position at Johnson & Johnson Services Inc?
The Manager, Product Security DevSecOps will be responsible for implementation of J&J’s enterprise Product Security tooling for MedTech. This includes identifying key strategy and goals, collaborating with internal organizations on existing process and policy enhancements, creating and communicating metrics to MedTech management, identifying communications plans and raising overall awareness of the capability. Specific responsibilities include supporting MedTech business units throughout a new product’s development phases, review product security requirements and recommend security design solutions, to ensure automation of security tooling inside of development pipelines.
Key Responsibilities:
Design solutions to enable global cloud provisioning and migration
Design and build software tools to enable self-service and no ops capabilities
Guide teams working with Azure PaaS and Atlassian Services
Guide team members working with Azure in problem solving and implementation
Be a subject matter expert on Azure IaaS and PaaS services for the MedTech platform engineering team
Work with tools such as Git, Azure DevOps, Artifactory, and other similar tooling
Build and consume REST APIs
Contribute to dev ops workflows through expert guidance and support for MedTech business unit security automation
Applies ISRM product security policies and standards when performing all duties
Anything a team member can do that contributes to enhanced systems reliability and availability is within scope.
Qualifications
Required:
Bachelor’s degree or equivalent work experience required
5 years of DevOps experience
2 years of DevSecOps Experience
2 years of software development experience
Understanding of DevOps pipeline and CI/CD tools and ability to mentor and teach others complex CI/CD and application concepts
Working knowledge of Waterfall, Agile, and primarily DevOps development methodologies
Working knowledge of tools such as Git, Azure DevOps, Artifactory, and other similar tooling
Experience with Agile methodologies
Preferred:
Experience with SBOM Automation Tooling
Familiarity with system and security design principles of medical device back-end software
In-depth understanding of cloud security principles and hands-on experience with cloud platforms such as AWS, Azure, or Google Cloud
Demonstrated mastery in IaC tools and technologies with a deep understanding of IaC principles and best practices
Strong understanding and experience with RESTful API’s
Advanced knowledge of one or more scripting languages, such as Python, Bash, or PowerShell
Experience with one or more programming languages, such as Type/JavaScript, JAVA, or PHP or Python
Proficiency in using SIEM for monitoring and analyzing security events
Extensive experience and expertise in leveraging tools for automating security processes within the development pipeline
Understanding of Quality Design Control processes and FDA submission processes.
Experience with web applications and server hardening (i.e. AWS, Azure) including knowledge of OWASP Top 10 and blue teaming techniques
Other:
Proficiency in English
Limited travel is required, up to 10%, including international travel.
The anticipated base pay range for this position in the United States is $100,000 to $172,500. California Bay Area - The anticipated base pay range for this position is $114,000 to $197,800.
The Company maintains highly competitive, performance-based compensation programs. Under current guidelines, this position is eligible for an annual performance bonus in accordance with the terms of the applicable plan. The annual performance bonus is a cash bonus intended to provide an incentive to achieve annual targeted results by rewarding for individual and the corporation’s performance over a calendar/performance year. Bonuses are awarded at the Company’s discretion on an individual basis.
Employees and/or eligible dependents may be eligible to participate in the following Company sponsored employee benefit programs: medical, dental, vision, life insurance, short- and long-term disability, business accident insurance, and group legal insurance.
Employees may be eligible to participate in the Company’s consolidated retirement plan (pension) and savings plan (401(k)).
Employees are eligible for the following time off benefits: - Vacation – up to 120 hours per calendar year
Sick time - up to 40 hours per calendar year; for employees who reside in the State of Washington – up to 56 hours per calendar year
Holiday pay, including Floating Holidays – up to 13 days per calendar year of Work, Personal and Family Time - up to 40 hours per calendar year
Salary : $100,000 - $198,000