Johnson & Johnson Posted August 25, 2026

Principal, Security Architect

New Brunswick, United States Full time

Johnson & Johnson is the source of truth for this posting and owns the application process. We surface normalized context and market comparison you won't find on the original listing.

About this opportunity

At Johnson & Johnson, we believe health is everything. Our strength in healthcare innovation empowers us to build a world where complex diseases are prevented, treated, and cured, where treatments are smarter and less invasive, and solutions are personal. Through our expertise in Innovative Medicine and MedTech, we are uniquely positioned to innovate across the full spectrum of healthcare solutions today to deliver the breakthroughs of tomorrow, and profoundly impact health for humanity. Learn more at jnj.com

As guided by Our Credo, Johnson & Johnson is responsible to our employees who work with us throughout the world.  We provide an inclusive work environment where each person is considered as an individual.  At Johnson & Johnson, we respect the diversity and dignity of our employees and recognize their merit.

Job Function:

Technology Enterprise Strategy & Security

Job Sub Function:

Security & Controls

Job Category:

Scientific/Technology

All Job Posting Locations:

New Brunswick, New Jersey, United States of America, Palm Beach Gardens, Florida, United States of America, Raritan, New Jersey, United States of America, Raynham, Massachusetts, United States of America, Warsaw, Indiana, United States of America, West Chester, Pennsylvania, United States of America

Job Description:

DePuy Synthes is recruiting for a Principal, Security Architect, located in the United States.

The Security Architect designs, evaluates, and strengthens the security architecture that protects DePuy Synthes' technology assets, data, and operational environments. Sitting within the Technology Enterprise Strategy & Security organization, this role serves as a technical authority on security   controls, assessing system and network configurations, identifying vulnerabilities and exposures, performing root-cause analysis, and contributing to the design, development, and implementation of countermeasures and security tooling across the enterprise.

This role   is responsible for   advancing the organization' s   Zero Trust, Secure by Design, and Resilient by Design   strategy, ensuring security and resilience are embedded into every technology platform, architecture decision, and transformation initiative.

Key Responsibilities  

Lead the development of Secure by Design, Resilient by Design, and Zero Trust   architectures   across cloud, network, endpoint, identity, application, data, and OT environments.

Conduct security architecture reviews, threat modeling, and risk assessments for new and existing solutions.

Drive the enterprise Zero Trust strategy, including identity, segmentation, least privilege, and continuous verification capabilities.

Design network segmentation and micro-segmentation architectures to protect critical assets and reduce lateral movement.

Define vulnerability and exposure management strategies, including risk-based prioritization and remediation.

Develop resilient security architectures that strengthen containment, recovery, and business continuity capabilities.

Design endpoint security controls, hardening standards, device compliance frameworks, and EDR/XDR integrations.

Establish secure architectures for cloud, AI, data, and application environments, including secure development,   DevSecOps , and AI governance practices.

Develop OT security architectures that protect manufacturing,   laboratory , and connected device environments.

Partner with Enterprise and Solution Architects to embed security, resilience, and compliance requirements across transformation initiatives.

Evaluate   architectures   and configurations against frameworks including NIST, NIST Zero Trust, CIS, ISO 27001, and applicable regulatory requirements.

Drive security automation, tooling integrations, and engineering improvements that enhance enterprise defenses.

Perform root-cause analysis of security findings and incidents, recommending strategic and sustainable improvements.

Produce architecture standards, reference designs, technical documentation, and executive-level roadmaps.

Mentor and coach security architects and engineers while fostering a culture of engineering excellence and continuous improvement.

Qualifications  

Education:

Required:   Bachelor's degree in Computer Science , Information Security, Engineering, or   a related   technical field.

Preferred: Master's degree in Cybersecurity, Information Security, or   a related   discipline.

Experience and Skills:  

Required:

8+ years of experience in information security, with   demonstrated   depth in security architecture and controls.

Hands-on experience with vulnerability and exposure management, including assessment and remediation.

Strong knowledge of network security and segmentation, firewalls, and zero-trust architecture.

Experience designing endpoint protection and device security controls (e.g., EDR/XDR, device hardening).

Experience with   cloud security across one or more major platforms (AWS, Azure, or GCP), including secure configuration and workload protection.

Working knowledge of application and data security principles, including secure SDLC and data protection.

Familiarity with industry frameworks and standards (e.g., NIST CSF, ISO 27001, CIS Controls).

Preferred:

Experience securing Operational Technology (OT) and connected/IoT device environments.

Experience defining security controls for AI, data, and Generative AI solutions.

Experience in a regulated industry (MedTech, Pharmaceutical, or Healthcare) with familiarity in associated compliance requirements.

Experience with security automation, SOAR, and security tooling integration.

Experience supporting large-scale transformation or separation programs.

Other:

Travel: Up to 25%

Language: English   proficiency   required .

Certifications: Relevant security certifications (e.g., CISSP, CISSP-ISSAP, CCSP, SABSA, or cloud security certifications) preferred.

For more information on how we support the whole health of our employees throughout their wellness,   career   and life journey, please visit   www.careers.jnj.com .

Johnson & Johnson announced plans to separate our Orthopaedics business to establish a standalone orthopaedics company, operating as DePuy Synthes. The process of the planned separation is anticipated to be completed within 18 to 24 months, subject to legal requirements, including consultation with works councils and other employee representative bodies, as may be required, regulatory approvals and other customary conditions and approvals. Should you accept this position, it is anticipated that, following conclusion of the transaction, you would be an employee of DePuy Synthes and your employment would be governed by DePuy Synthes employment processes, programs, policies, and benefit plans. In that case, details of any planned changes would be provided to you by DePuy Synthes at an appropriate time and subject to any necessary consultation processes.

Johnson & Johnson is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, age, national origin, disability, protected veteran status or other characteristics protected by federal, state or local law. We actively seek qualified candidates who are protected veterans and individuals with disabilities as defined under VEVRAA and Section 503 of the Rehabilitation Act.

Johnson & Johnson is committed to providing an interview process that is inclusive of our applicants’ needs. If you are an individual with a disability and would like to request an accommodation, external applicants please contact us via https://www.jnj.com/contact-us/careers, internal employees contact AskGS to be directed to your accommodation resource.

#LI-Hybrid

#DePuySynthesCareers

Required Skills:

Preferred Skills:

Business Process Design, Crisis Management, Critical Thinking, Information Security Auditing, Information Security Management System (ISMS), Information Technology (IT) Security Assessments, Information Technology Strategies, Mentorship, Organizing, Presentation Design, Process Optimization, Root Cause Analysis (RCA), Security Architecture Design, Security Policies, Technical Credibility, Vulnerability Management

The anticipated base pay range for this position is :

102,000.00 - 204,000.00 USD Annual

Additional Description for Pay Transparency:

Subject to the terms of their respective plans, employees are eligible to participate in the Company’s consolidated retirement plan (pension) and savings plan (401(k)). Subject to the terms of their respective policies and date of hire, employees are eligible for the following time off benefits: • Vacation –120 hours per calendar year • Sick time - 40 hours per calendar year; for employees who reside in the State of Colorado –48 hours per calendar year; for employees who reside in the State of Washington –56 hours per calendar year • Holiday pay, including Floating Holidays –13 days per calendar year • Work, Personal and Family Time - up to 40 hours per calendar year • Parental Leave – 480 hours within one year of the birth/adoption/foster care of a child • Bereavement Leave – 240 hours for an immediate family member: 40 hours for an extended family member per calendar year • Caregiver Leave – 80 hours in a 52-week rolling period10 days • Volunteer Leave – 32 hours per calendar year • Military Spouse Time-Off – 80 hours per calendar year For additional general information on Company benefits, please go to: - https://www.careers.jnj.com/employee-benefits

Job details

Seniority
Principal
Function
Information Technology
Therapeutic area
Not listed
Location
New Brunswick, United States
Employment type
Full time

How this role compares

Computed from every other active Information Technology role in our database, not just this employer's listings.

We currently track 401 comparable Principal Information Technology roles across 43 biopharma companies.

401Comparable roles tracked
383Currently active
43Companies hiring similar roles
21Countries represented

Salary context

49 of 401 peers report a salary range (USD, annualized)

Peers share this role's job function and a matching or adjacent seniority level -- not necessarily the same therapeutic area or country.

This roleSubject $102,000/yr – $204,000/yr
Lowest disclosed · Senior Data Security Engineer (Insider Risk Management – Engineering) · AbbVie $0/hr – $0/hr (≈ $0–$0/yr)
Highest disclosed · Director, Data and AI Product Owner, Research · Gilead Sciences, Inc. $226,185/yr – $292,710/yr
Peer group range $0 – $259,448 (median $155,400)

Where these roles are based

Top locations among the 401 comparable roles

India212
United States86
Spain22
Poland17
Greece11
Portugal10

+ 15 more countries

Seniority mix

401 of 401 peers have a known seniority level

Senior310
Principal55
Director36

Therapeutic area mix

2 of 401 peers have a known therapeutic area; the rest are genuinely unlabeled, not hidden

Oncology1
Vaccines & Infectious Disease1

Similar opportunities

The closest matches from our peer group, ranked by how similar they are, not how well you'd qualify for them -- treat this as market context, not a guaranteed shortlist; a weak match is labeled as one below.

60%similar
Roche Santa Clara, California, United States of America Principal
Same function Same seniority Same country
60%similar
Regeneron Genetics Center (USA) Tarrytown, United States Principal
Same function Same seniority Same country
60%similar
Regeneron Pharmaceuticals, Inc (USA) Renss, United States Principal
Same function Same seniority Same country
60%similar
Regeneron Pharmaceuticals, Inc (USA) Warren, United States Principal
Same function Same seniority Same country
60%similar
Regeneron Pharmaceuticals, Inc (USA) Tarrytown, United States Principal
Same function Same seniority Same country
60%similar
Regeneron Pharmaceuticals, Inc (USA) Tarrytown, United States Principal
Same function Same seniority Same country

Notify me about similar jobs

Get an email when we spot other openings like this one – same job function, comparable seniority, roles you'd actually want to see.

How we calculate "similar"

No black box, no LLM guesswork: a deterministic score built from four normalized attributes. Here's this role's own peer group at different match levels, so you can see the mechanism, not just the result.

Every comparison starts from the same 100-point budget: 25 for working in the same function, 40 for the same therapeutic area, 20 for the same or adjacent seniority, 15 for the same country. A dimension we can't confirm on both sides contributes nothing, never a guess, never a free pass.

60%
Principal Software Development Engineer
Roche · Santa Clara, California, United States of America · Principal
Function Therapeutic area Seniority Country
60%
Principal Business Analyst
Regeneron Pharmaceuticals, Inc (USA) · Warren, United States · Principal
Function Therapeutic area Seniority Country
60%
Principal Business Analyst - Velocigene
Regeneron Pharmaceuticals, Inc (USA) · Tarrytown, United States · Principal
Function Therapeutic area Seniority Country
60%
Principal Business Analyst – Science Data Portal
Regeneron Pharmaceuticals, Inc (USA) · Tarrytown, United States · Principal
Function Therapeutic area Seniority Country
Unmatched or unknown dimensions score exactly the same: 0 points, never a partial guess. A role we know almost nothing about beyond its function bottoms out at 25%; it never inflates to 100% just because there's little to compare against. Seniority uses a defined ladder (Associate → Manager → Associate Director → Senior → Principal → Director → Senior Director → Executive/VP) so "Director" and "Senior Director" count as adjacent, but "Director" and "Executive/VP" do not.