채용
At Johnson & Johnson, we believe health is everything. Our strength in healthcare innovation empowers us to build a world where complex diseases are prevented, treated, and cured, where treatments are smarter and less invasive, and solutions are personal. Through our expertise in Innovative Medicine and Med Tech, we are uniquely positioned to innovate across the full spectrum of healthcare solutions today to deliver the breakthroughs of tomorrow, and profoundly impact health for humanity. Learn more at jnj.com.
As guided by Our Credo, Johnson & Johnson is responsible to our employees who work with us throughout the world. We provide an inclusive work environment where each person is considered as an individual. At Johnson & Johnson, we respect the diversity and dignity of our employees and recognize their merit.
Job Function:
Technology Enterprise Strategy & Security:
Job Sub Function:
Security & Controls:
Job Category:
Scientific/Technology
All Job Posting Locations:
São José dos Campos, São Paulo, Brazil, Warsaw, Masovian, Poland
Job Description:
Johnson & Johnson is currently recruiting for a Principal Attack Surface Management within the Information Security and Risk Management (ISRM) organization.
This position is based out of Warsaw, Poland or São José dos Campos, Brazil.
As a member of the Attack Surface Management (ASM) team, you will lead J&J’s Exposure Management. Continuously discover, quantify, and reduce internal and external attack surface. You will turn findings into prioritized action, lead adversarial validation, and collaborate across security and technology teams to deliver measurable risk reduction. Driving remediation across on‑prem and cloud environments - consistently and with measurable impact!
Key Responsibilities:
-
Support Exposure and Attack Surface Management platform configuration, scalability, upgrades, policy enforcement, and overall health.
-
Partner with ASM vendor to coordinate platform issues, upgrades, maintenance, roadmaps, and feature requests.
-
Drive detection and prioritization: tune and automate detection rules, enrichment, and correlation logic to reduce false positives and accelerate response.
-
Support ingestion and delivery of exposure and incident data into enterprise risk tools to support incident response, containment, and post‑incident review.
-
Ensure exposure management practices align with CIS, NIST, and applicable compliance requirements.
-
Produce actionable reporting and indicators (heat maps, MTTR, exploitable exposure reduction, observability coverage) to guide prioritization and executive decision-making.
-
Plan, authorize, and coordinate adversarial exposure programs (pen tests, Red Team, Purple Team), defining scope, rules of engagement, success criteria, and approvals.
-
Perform or coordinate authorized exploit validation and proof of concept development in isolated labs; operationalize findings into CTEM/ASM workflows to adjust scoring, tune detection, and trigger remediation/ticketing.
-
Collaborate multi-functionally with Technology teams, Cloud Security, Application Security, Identity, the Cyber Defense Center, and business owners to coordinate fixes and risk acceptance.
Experience and Skills:
Required:
-
8+ years in security engineering, exposure/attack surface management, vulnerability management, or similar roles.
-
Hands‑on experience with CTEM/ASM platforms and asset discovery tools and integrating them into enterprise tooling.
-
Strong scripting and automation skills (Python, PowerShell, or equivalent) for integrations, enrichment, and remediation orchestration via APIs.
-
Demonstrable experience conducting or coordinating authorized exploit validation, PoC testing, and working with Pen Test/Red Team/Purple Team engagements.
-
Solid knowledge of exposure and risk prioritization methodologies, threat intelligence ingestion, and exploitability scoring.
-
Demonstrated ability to build remediation playbooks, automate ticketing/workflows, and drive multi-functional remediation at scale.
-
Ability to translate technical vulnerabilities into business risk language for executive and business-owner reporting.
-
Proven track record of producing measurable outcomes (reduced exploitable exposures, improved MTTR, increased observability coverage).
Preferred:
-
Certifications: CISSP, GPEN, GWAPT, CRISC, OSCP/OSWE, or equivalent; cloud security certs (AWS/Azure/GCP) a plus.
-
Prior experience in large, hybrid enterprises or compliance-focused environments adhering to security frameworks such as CIS and NIST.
-
Vendor management experience including platform evaluation, roadmap alignment, and procurement support.
-
Strong data‑analytics approach: experience building dashboards, and executive‑level key risk metrics.
For more information on how we support the whole health of our employees throughout their wellness, career and life journey, please visit www.careers.jnj.com.]
Required Skills:
Preferred Skills:
Business Process Design, Crisis Management, Critical Thinking, Information Security Auditing, Information Security Management System (ISMS), Information Technology (IT) Security Assessments, Information Technology Strategies, Mentorship, Organizing, Presentation Design, Process Optimization, Root Cause Analysis (RCA), Security Architecture Design, Security Policies, Technical Credibility, Vulnerability Management
Total Views
0
Apply Clicks
0
Mock Applicants
0
Scraps
0
Similar Jobs
PN
Financial Advisor - PNC Wealth Management
PNC Financial · 2 Locations
TI
Head of Client Portfolio Management Operations - Brooklyn Investment Group
TIAA · 2 Locations
FA
SF Operational Risk - Risk Management - Principal
Fannie Mae · 2 Locations

Senior Projektmanager*in ACS/FACTS (m/w/d)
GE Vernova · 2 Locations

Praktikum Continuous Improvement & Lean Management in der Medizintechnik / Maschinenbau (6 Monate | Start Sept./Okt. 2026)
Stryker · 2 Locations
About Johnson & Johnson

Johnson & Johnson
PublicCaring for the world, one person at a time.
10000+
Employees
New Brunswick
Headquarters
Reviews
3.6
5 reviews
Work Life Balance
3.8
Compensation
2.5
Culture
3.0
Career
3.2
Management
2.8
45%
Recommend to a Friend
Pros
Good work-life balance
Strong R&D division
University talent engagement
Cons
Contract employee job security issues
Pay cuts during transitions
Product liability concerns
Salary Ranges
2,248 data points
Junior/L3
Senior/L5
Junior/L3 · Analyst
177 reports
$93,472
total / year
Base
$85,723
Stock
-
Bonus
$7,749
$59,968
$146,648
Interview Experience
7 interviews
Difficulty
3.0
/ 5
Duration
14-28 weeks
Experience
Positive 0%
Neutral 86%
Negative 14%
Interview Process
1
Application Review
2
HireVue Video Interview
3
Recruiter Screen
4
Technical/Hiring Manager Interview
5
Panel Interview
6
Offer
Common Questions
Behavioral/STAR
Technical Knowledge
Past Experience
Culture Fit
Case Study
News & Buzz
Is Johnson & Johnson (JNJ) The Most Profitable Healthcare Stock To Buy? - Finviz
Source: Finviz
News
·
5w ago
Is Johnson & Johnson (JNJ) The Most Profitable Healthcare Stock To Buy? - Insider Monkey
Source: Insider Monkey
News
·
5w ago
Johnson & Johnson Weighs Oncology Progress Against Easing Talc Legal Risks - simplywall.st
Source: simplywall.st
News
·
5w ago
New York State Common Retirement Fund Decreases Stock Position in Johnson & Johnson $JNJ - MarketBeat
Source: MarketBeat
News
·
5w ago