Job Function:
Technology Enterprise Strategy & Security
Job Sub Function:
Security & Controls
Job Category:
People Leader
All Job Posting Locations:
Palm Beach Gardens, Florida, United States of America, Raritan, New Jersey, United States of America, Raynham, Massachusetts, United States of America, Warsaw, Indiana, United States of America, West Chester, Pennsylvania, United States of America
Job Description:
DePuy Synthes is recruiting for a(n) Director, Incident Response & Threat; this Hybrid positionwill be in Raynham, MA (USA). Alternate Hybrid locations may be considered at Raritan, NJ (USA), West Chester, PA (USA), Warsaw, IN (USA), Palm Beach Gardens, FL (USA) OR Pune, India.
Please note that this role is available across multiple countries and may be posted under different requisition numbers to comply with local requirements. While you are welcome to apply to any or all of the postings, we recommend focusing on the specific country(s) that align with your preferred location(s):
Raynham, MA (USA) - Requisition Number: R-072535
Pune, India - Requisition Number:R-073281
Remember, whether you apply to one or all of these requisition numbers, your applications will be considered as a single submission.
Johnson & Johnson announced plans to separate our Orthopedics business toestablisha standalone orthopedics company,operatingas DePuy Synthes. The process of the planned separation isanticipatedto be completed within 18 to24 months, subject to legal requirements, including consultation with works councils and other employee representative bodies, as may berequired, regulatory approvals and other customary conditions and approvals. Should you accept this position, it isanticipatedthat, following conclusion of the transaction, you would be an employee of DePuySynthesand your employment would be governed by DePuy Synthes employment processes, programs, policies, and benefit plans. In that case, details of any planned changes would be provided to you by DePuy Synthes atan appropriate timeand subject to any necessary consultation processes.
Job Overview
The Director, Cyber Defense is a senior cybersecurity leadership role responsible for protecting DePuy Synthes92 digital environment, products, and operations from cyber threats. This leader will own the global incident response program and threat management strategy, ensuring rapid detection, containment, and remediation of security incidents. The role plays a critical part in safeguarding patient trust, business continuity, and regulatory compliance while shaping a resilient and forwardlooking security posture across the organization, and reports into the DePuy Synthes Technology organization.
Key Responsibilities:
- Lead the global incident response, digital forensics, defense engineering, and cyber threat intelligence capabilities, with accountability for preparedness, detection, containment, response, recovery, and continuous improvement.
- Build and mature an automation- and AI-first global Security Operations Center operating model that integrates an MSSP, retained services, and an internal team spanning eDiscovery, investigations, threat intelligence, incident response, and defense engineering.
- Direct complex cybersecurity incident investigations, ensuring rapid containment, preservation of forensic evidence, rigorous root-cause analysis, coordinated remediation, and timely executive and post-incident reporting.
- Develop, automate, test, and continuously improve incident response playbooks, escalation paths, communications protocols, and crisis management procedures to enable consistent, timely, and coordinated action during cyber events.
- Partner with IT, Legal, Privacy, Quality, and Business leaders to manage cyber incidents and regulatory or compliance obligations.
- Oversee threat intelligence capabilities that identify and assess emerging threats and vulnerabilities relevant to the MedTech environment, translate intelligence into prioritized defensive actions, and deliver concise executive briefings on business implications and recommended responses.
- Lead tabletop exercises, simulations, and readiness assessments across technology and business functions; translate lessons learned into prioritized remediation plans that measurably improve response maturity.
- Establish and maintain an executive-ready metrics framework - including mean time to acknowledge (MTTA), respond (MTTR), and contain (MTTC) - to demonstrate operational effectiveness, expose performance gaps, enforce accountability, and drive measurable improvements in cyber resilience.
- Provide executive-level reporting and actionable recommendations on cyber risk, incident trends, defensive readiness, investment priorities, and remediation progress to support timely, risk-informed decisions.
- Enhance relationship with the business by promoting awareness, insights and opportunities to improve the company92s risk position
- Lead proactive research to identify relevant threats, develop and perform threat hunts based on that research
- Lead, mentor, and develop a highperforming incident response and threat management team.
- Drive continuous improvement of tools, processes, and technologies supporting security operations and resilience.
Qualifications:
Education:
- Bachelor92s degree in Computer Science, Information Security, Engineering, ora relatedfield (required).
- Master92s degree in Cybersecurity, Information Systems, or Business Administration (preferred).
Experience and Skills:
Required:
- 10-12years of progressive experience in cybersecurity, information security, or IT risk management, including leadership roles.
- Proven experience leading enterprisescale incident response and threat management programs.
- Strong knowledge of cyber threat landscapes, attack techniques, and defensive strategies.
- Experience working in regulated environments (e.g., healthcare, life sciences, MedTech, or similarly regulated industries).
- Demonstrated ability to lead crossfunctional teams during highpressure incidents.
- Excellent executive communication, judgment, and decisionmaking skills.
Preferred:
- Experience supporting global organizations with complex technology environments.
- Familiarity with security frameworks such as NIST, ISO 27001, or similar standards.
- Experience integrating threat intelligence into security operations and risk management.
- Priorpeopleleadership experience managing managers or senior individual contributors.
- Experience with cloud, OT, and medical device security considerations.
Other:
- Language: English (fluent).
- Travel: Up to 10 615%, primarily domestic with occasional international travel.
- Certifications (preferred): CISSP, CISM, GIAC, or equivalent cybersecurity certifications.
For more information on how we support the whole health of our employees throughout their wellness,careerand life journey, please visitwww.careers.jnj.com.
#DePuySynthesCareers
#LI-Hybrid
Required Skills:
Preferred Skills:
Business Process Design, Creating Purpose, Crisis Management, Critical Thinking, Cybersecurity, Developing Others, Inclusive Leadership, Information Security Auditing, Information Security Management System (ISMS), Information Technology (IT) Security Assessments, Information Technology Strategies, Leadership, Organizing, People Performance Management, Presentation Design, Process Optimization, Security Architecture Design, Security Policies
The anticipated base pay range for this position is :
$150,000.00 - $258,750.00
Additional Description for Pay Transparency:
Subject to the terms of their respective plans, employees are eligible to participate in the Company92s consolidated retirement plan (pension) and savings plan (401(k)).
This position is eligible to participate in the Company92s long-term incentive program.
Subject to the terms of their respective policies and date of hire, employees are eligible for the following time off benefits:
Vacation 6120 hours per calendar year
Sick time - 40 hours per calendar year; for employees who reside in the State of Colorado 648 hours per calendar year; for employees who reside in the State of Washington 56 hours per calendar year
Holiday pay, including Floating Holidays 13 days per calendar year
Work, Personal and Family Time - up to 40 hours per calendar year
Parental Leave 6480 hours within one year of the birth/adoption/foster care of a child
Bereavement Leave 6240 hours for an immediate family member: 40 hours for an extended family member per calendar year
Caregiver Leave 680 hours in a 52-week rolling period10 days
Volunteer Leave 32 hours per calendar year
Military Spouse Time-Off 680 hours per calendar year
Additional information can be found through the link below.
Co-Ops and Intern Positions: Please use the following language:
Co-Ops/Interns are eligible to participate in Company sponsored employee medical benefits in accordance with the terms of the plan.
Co-Ops and Interns are eligible for the following sick time benefits: up to 40 hours per calendar year; for employees who reside in the State of Washington, up to 56 hours per calendar year.
Co-Ops and Interns are eligible to participate in the Company92s consolidated retirement plan (pension).
Positions Represented by CBA: Please use the following language:
This position is eligible for benefits to include medical, dental, vision and time off, as well as any others as provided for in the applicable Collective Bargaining Agreement.
The following link to general company benefits information MUST also be included in the posting: Please use the following language:
For additional general information on Company benefits, please go to: - https://www.careers.jnj.com/employee-benefits