Johnson & Johnson

Professional, Compliance Lead

Johnson & Johnson$120K — $145K *
Information Technology
5 - 7 years of experience
Job Overview by Ladders

Qualifications

  • 6+ years in cybersecurity governance or related GRC discipline
  • Ownership experience of a security policy framework
  • Advanced knowledge of NIST CSF, ISO standards, COBIT
  • Experience with cyber risk assessment methodologies
  • Demonstrated ability to design executive-level risk reporting
  • Experience managing third-party cyber risk programs
  • Strong facilitation and influencing skills.

Responsibilities

  • Lead the cybersecurity policy and standards program from start to finish
  • Define and maintain the enterprise cyber risk framework
  • Direct the cyber risk assessment program across various domains
  • Govern the enterprise cyber risk register and ensure data quality
  • Chair cybersecurity governance forums and document outcomes
  • Create executive reports translating technical data for leadership
  • Operationalize cyber risk metrics and establish predictive signals
  • Oversee third-party cyber risk, establishing assessment standards
  • Maintain a library mapping regulatory and framework requirements
  • Align governance with control design alongside IT Control teams
  • Serve as liaison for Internal Audit, external auditors, and regulators
  • Assess compliance impacts of technology changes
  • Drive cyber culture and awareness initiatives
  • Identify automation opportunities in GRC processes.

Benefits

  • Flexible working options including hybrid work model
  • Opportunities for professional development and certification
  • Comprehensive health and wellness programs
  • Supportive company culture fostering innovation and change
  • Engagement in high-impact projects with executive visibility.
Full Job Description
Job Function:
Technology Enterprise Strategy & Security

Job Sub Function:
Security & Controls

Job Category:
Scientific/Technology

All Job Posting Locations:
New Brunswick, New Jersey, United States of America

Job Description:

DePuy Synthes is recruiting for a Professional, Compliance Lead, located in Raritan, New Jersey or West Chester, Pennsylvania or Palm Beach Gardens, Florida or Raynham, Massachusetts or Warsaw, Indiana.
  • Join our change journey at J&J-help shape what's next
  • Step into a high-impact career opportunity with real visibility


THE OPPORTUNITY

The Professional, Compliance Lead is a seasoned individual contributor within the Cybersecurity function, GRC, IT Controls & Cyber Culture sub-function, accountable for leading the cybersecurity compliance and governance agenda across DePuy Synthes. This role owns the policy and standards framework, sets the enterprise cyber risk methodology, leads risk assessments and register governance, and drives the reporting cadence that informs executive and Board-level decision-making. The Compliance Lead directs third-party risk oversight, defines the metrics and KRI model that measures program health, and serves as the primary liaison to Internal Audit, Legal, Privacy, Quality, and external regulators. Applying advanced knowledge of GRC frameworks and regulatory obligations, this role establishes best-in-class policies, procedures, and plans for the area.

RESPONSIBILITIES
  • Lead the cybersecurity policy and standards program end to end - setting the governance lifecycle, approving content, driving annual review and attestation, and adjudicating exceptions and risk acceptances.
  • Define and maintain the enterprise cyber risk framework and methodology, including risk taxonomy, scoring model, risk appetite and tolerance statements, and escalation thresholds.
  • Direct the cyber risk assessment program across applications, infrastructure, business processes, and major change initiatives; ensure consistency of method, quality of output, and traceability of results.
  • Own governance of the enterprise cyber risk register - enforcing data quality, ownership accountability, aging discipline, and timely escalation of elevated or overdue risks to leadership.
  • Chair and orchestrate cybersecurity governance forums, setting agendas, framing decisions, documenting outcomes, and holding owners accountable for committed actions.
  • Build and deliver the executive reporting model - translating aggregated risk, control, and compliance data into concise business-impact narratives for CIO, CISO, and senior leadership audiences.
  • Define, baseline, and operationalize cyber risk metrics and Key Risk Indicators (KRIs), establishing thresholds, trend analysis, and predictive signals that drive proactive intervention.
  • Lead third-party cyber risk oversight - setting the vendor tiering model, assessment standards, contractual security requirements, and continuous monitoring approach for critical aand high-risk suppliers.
  • Maintain the regulatory and framework mapping library (NIST CSF, ISO 27001, HIPAA, GDPR, FDA cybersecurity guidance, SOX ITGC), rationalizing overlapping requirements to reduce duplicate control effort.
  • Partner with the IT Controls and SOX teams to align governance requirements with control design and testing, ensuring a coherent and non-duplicative assurance landscape.
  • Serve as the primary point of contact for Internal Audit, external auditors, regulators, and customer security assessments - coordinating evidence, responses, and issue remediation.
  • Assess and govern the compliance impact of major technology change, including cloud migrations, ERP and platform implementations, and separation/carve-out activity, defining requirements prior to go-live.
  • Drive the cyber culture and awareness agenda - shaping policy communications, training strategy, and targeted enablement to strengthen accountability and risk-aware behavior enterprise-wide.
  • Identify and lead automation opportunities across GRC workflows, evidence collection, and reporting to improve efficiency, data integrity, and program scalability.


ABOUT YOU:

Required:
  • 6 years of progressive experience in cybersecurity governance, IT risk management, technology compliance, or a related GRC discipline.
  • Demonstrated ownership of a security policy and standards framework, including authorship, governance lifecycle, exception management, and stakeholder approval.
  • Advanced working knowledge of NIST CSF, NIST 800-53, ISO 27001/27002, and COBIT, with the ability to rationalize requirements across multiple frameworks.
  • Proven experience designing and operating a cyber risk assessment methodology and enterprise risk register at scale.
  • Experience defining KRIs and building executive-level risk reporting that drives leadership decisions.
  • Experience leading third-party/vendor cyber risk programs, including assessment standards, SOC 2 / ISO evidence review, and contractual security requirements.
  • Strong facilitation and influencing skills, with a track record of driving accountability across senior stakeholders without direct authority.


Preferred:
  • MedTech, Life Sciences, or other regulated industry background; working knowledge of HIPAA, GDPR, and FDA medical device cybersecurity expectations.
  • Experience standing up or maturing a GRC function within a divestiture, carve-out, spin-off, or standalone entity.
  • Hands-on experience with GRC platforms (e.g., ServiceNow IRM, Archer, OneTrust, AuditBoard), including workflow design and reporting configuration.
  • Experience coordinating directly with external auditors, regulators, or major customer security assessment programs.
  • Familiarity with cloud governance (AWS, Azure) and control expectations for SaaS and cloud-hosted environments.
  • Proficiency with data visualization and analytics tools (Power BI, Tableau, SQL) for risk metrics and executive dashboards.
  • Experience applying Generative AI / LLM-enabled tooling to accelerate policy drafting, control mapping, and third-party assessment review.
  • Experience designing and scaling security awareness and cyber culture programs.


Other:
  • Travel: Up to 15% domestic travel expected across DePuy Synthes sites.
  • Language: English proficiency required.
  • Certifications: CISSP, CRISC, CISM, or CISA required or in progress. CGRC, ISO 27001 Lead Implementer/Auditor, or CIPP preferred.


Johnson & Johnson announced plans to separate our Orthopedics business to establish a standalone orthopedics company, operating as DePuy Synthes. The process of the planned separation is anticipated to be completed within 18 to 24 months, subject to legal requirements, including consultation with works councils and other employee representative bodies, as may be required, regulatory approvals and other customary conditions and approvals. Should you accept this position, it is anticipated that, following conclusion of the transaction, you would be an employee of DePuy Synthes and your employment would be governed by DePuy Synthes employment processes, programs, policies, and benefit plans. In that case, details of any planned changes would be provided to you by DePuy Synthes at an appropriate time and subject to any necessary consultation processes.

#LI-Hybrid
#DePuySynthesCareers

Required Skills:

Preferred Skills:
Communication, Corrective and Preventive Action (CAPA), Critical Thinking, Information Security Auditing, Information Security Management System (ISMS), Information Technology (IT) Security Assessments, Information Technology Strategies, Mentorship, Network Optimization, Presentation Design, Process Optimization, Report Writing, Security Policies, Technical Credibility, Technologically Savvy, Training People, Vulnerability Assessments

About Johnson & Johnson

Scio Diamond creates single-crystal Type IIa diamonds for the jewelry market and for industrial applications. It employs a patent-protected chemical vapor deposition (CVD) process in a precisely controlled laboratory setting to produce diamonds. It was founded in 2009 and is headquartered in Greenville, South Carolina.

Johnson & Johnson Careers

Joining Johnson & Johnson provides an unparalleled opportunity to be a part of a global team of professionals dedicated to blending care, science, and innovation to profoundly change the trajectory of health for humanity.

Work You’ll Do

At Johnson & Johnson, you will engage in work that matters. Join our community of professionals in health care to drive significant and impactful changes across the globe. Our team at Johnson & Johnson leads with science and heart in sectors from pharmaceuticals to medical devices and consumer health products.

Transform Health Care

Leverage Johnson & Johnson’s culture of innovation to transform health care and improve the lives of people around the world. Our collaborative environment encourages leadership and growth, allowing you to pioneer new strategies for health care solutions with a diverse team of experts.

Innovative Work

Engage in groundbreaking work that enhances how care is delivered on a global scale. Johnson & Johnson’s commitment to innovative health solutions results in dynamic career paths filled with opportunities for professional growth and development.

Be Part of a Great Team

Our team at Johnson & Johnson thrives on collaboration and diversity. You will work alongside over 130,000 employees globally who are committed to making a lasting impact. With a culture that values diversity training and leadership, you are supported in both personal and professional growth.

Future-Proof Your Career

Johnson & Johnson offers a myriad of job opportunities and employment benefits designed to help you meet your career and personal goals. Our employees enjoy comprehensive benefits, including health insurance, retirement plans, and family-friendly policies that pave the way for a fulfilling career and life balance.

Explore Job Opportunities and Internships

Whether you’re looking to start your career or take it to the next level, Johnson & Johnson offers positions ranging from internships to leadership roles across various sectors. Enhance your skills through hands-on experience and our extensive networking and mentorship programs.

Johnson & Johnson Leadership and Development

Our commitment to leadership and continuous learning is at the core of our employment philosophy. Every position offers chances to lead, learn, and innovate. We provide extensive training programs and development courses that prepare you for the future of health care.

Stay Connected

Join Our Team

Search open positions that match your skills and interests. We are constantly hiring and looking for curious, driven, and compassionate team players.

SEARCH JOHNSON & JOHNSON JOBS

Keep Up to Date

Stay informed with career tips, insider perspectives, and industry-leading insights you can put to use today—all from the people who work here.

READ CAREERS BLOG

Job Alert Emails

Customize your subscription to receive job alerts, latest news, and insider tips tailored to your preferences. Discover the exciting and rewarding career opportunities that await at Johnson & Johnson. Join Johnson & Johnson today to be a part of a team that values innovation, leadership, and diversity, and see how far your ambition can take you.
Learn more about Johnson & Johnson
Size
141,700 employees
Market Cap
$462.7 billion
Industry
Net Income
$14.7 billion
Founded
1886
5 Year Trend
+5.5%
Revenue
$82.5 billion
NASDAQ

Similar Jobs

More Jobs at Johnson & Johnson

More Information Technology Jobs

Find similar Professional, Compliance Lead jobs: