1. Home
  2. Jobs
  3. Brazil
  4. São Paulo
  5. São José dos Campos
  6. Cybersecurity Engineering
  7. Principal Engineer Operational Technology CyberSecurity
J&

Principal Engineer Operational Technology CyberSecurity

Johnson & Johnson
Posted onJan 24, 2026
LocationSão José dos Campos, São Paulo, Brazil (On-site)
Employment typeFull-time

At Johnson & Johnson, we believe health is everything. Our strength in healthcare innovation empowers us to build a world where complex diseases are prevented, treated, and cured, where treatments are smarter and less invasive, and solutions are personal. Through our expertise in Innovative Medicine and MedTech, we are uniquely positioned to innovate across the full spectrum of healthcare solutions today to deliver the breakthroughs of tomorrow, and profoundly impact health for humanity. Learn more at https://www.jnj.com

Job Function:

Technology Enterprise Strategy & Security

Job Sub Function:

Security & Controls

Job Category:

Scientific/Technology

All Job Posting Locations:

São José dos Campos, São Paulo, Brazil

Job Description:

Johnson & Johnson is currently recruiting for a Principal Engineer Operational Technology CyberSecurity within the Information Security and Risk Management (ISRM) organization.

This position is based out Warsaw, Poland or São José dos Campos, Brazil.

As a member of the Operational Technology Cybersecurity Engineering team, you will lead the engineering, deployment, and optimization of Tanium platforms across our global enterprise environment. This role ensures platform scalability, compliance, and integration with organizational security strategies.

This position will also partner with internal ISRM teams such as the Supply Chain security, Cyber Security Operations Center (CSOC), and other groups under the J&J Technology umbrella, including but not limited to End User, Server, and Network support.

Key Responsibilities:

  • Oversee the design and lifecycle management of Tanium SaaS and related services.

  • Define and implement strategies for platform performance, security hardening, and automation.

  • Validate data flows and integration points to maintain accuracy and compliance.

  • Act as the technical authority for Tanium capabilities and provide guidance on best practices.

  • Collaborate with security and infrastructure teams to align Tanium operations with enterprise objectives.

  • Maintain documentation and ensure adherence to regulatory and change management processes. Drive integrations and automation between different IT/OT technologies.

  • Support Cybersecurity workflows, to assess risk, increase visibility and reduce impact of vulnerabilities across the IT/OT environments.

  • Test and validate security controls throughout the different phases of the Cyber Kill Chain, and the MITRE ATT&CK framework to prevent, detect, and respond.

  • Generate innovative threat behavior analytics for discovering historical and emerging threats to networks and systems.

  • Implement detection strategies based on internal and external intelligence reporting and vulnerability research.

  • Perform administrative tasks associated with tuning, alerts, correlation rules, signatures, device configurations, patching, and upgrades.

  • Establish and maintain relationships with the suppliers, vendors, and partners.

  • Assists with security events/incidents, coordinating activities with the CSOC and others – as needed.

Qualifications

Education:

  • A bachelor's degree or equivalent experience in the information security or information technology sector

Experience and Skills

Required:

  • Tanium Certified Administrator with extensive experience managing large-scale deployments. Strong understanding of Tanium SaaS architecture and operational workflows.

  • Hands-on scripting and automation skills (e.g., Python, PowerShell, Bash) for building integrations, automating workflows, and extending platform functionality.

  • Strong foundation in information security principles, with proven ability in debugging and root cause analysis in mixed IT/OT environments.

  • Experience engineering, installing, configuring, and operating security solutions and appliances across large-scale, hybrid environments (AWS, Azure, GCP, on-prem).

  • Ability to engineer, customize, and extend endpoint management and visibility platforms, including developing integrations, automation, and product-level enhancements.

  • Familiarity with agile frameworks and DevSecOps practices, with the ability to deliver iteratively while maintaining reliability in high-risk environments.

  • Proven track record leading complex implementations, demonstrating risk-aware problem solving and balancing security with operational continuity.

  • Strong communication skills (written and verbal), able to translate technical details into clear guidance for both technical and non-technical stakeholders.

  • Knowledge of security frameworks and standards (NIST CSF, CIS Controls, OWASP, SANS) and ability to apply them pragmatically.

  • Working knowledge of the MITRE ATT&CK framework, including TTPs, and ability to map telemetry to adversary behaviors.

  • Experience collaborating with distributed, global teams, working effectively across diverse cultural and technical backgrounds.

Please note that this role is available across multiple countries and may be posted under different requisition numbers to comply with local requirements. While you are welcome to apply to any or all of the postings, we recommend focusing on the specific country(s) that align with your preferred location(s):

Brazil (Sao Jose dos Campos) - Requisition Number: R-045622

Poland (Warsaw) - Requisition Number: R-046644

Required Skills:

Operational Technology (OT) Security

Preferred Skills:

Business Process Design, Crisis Management, Critical Thinking, Information Security Auditing, Information Security Management System (ISMS), Information Technology (IT) Security Assessments, Information Technology Strategies, Mentorship, Organizing, Presentation Design, Process Optimization, Root Cause Analysis (RCA), Security Architecture Design, Security Policies, Technical Credibility, Vulnerability Management

Johnson & Johnson

View company profile

Johnson & Johnson has been transforming healthcare for more than 135 years.

Similar jobs

You might also be interested in...

BO3d

Cybersecurity Engineer / Specialist – Talent Pool

Band of Coders

Buenos Aires, Argentina or Remote (Argentina)

IG1w

Cybersecurity Engineer

Infotree Global Solutions

Worldwide (Remote)

UT1w

Sr Manager, Cybersecurity

USA TODAY Co.

Worldwide (Remote)

$135k – $143k Yearly

IG1w

Cybersecurity Engineer SIEM, EDR, IDS/IPS

Infotree Global Solutions

Hybrid

PE3d

Cybersecurity Engineer - VMware Systems Architect, Active Top Secret

Peraton

Virginia Beach, Virginia, United States (On-site)

$104k – $166k Yearly