Johnson & Johnson

Professional, SOX Lead

Johnson & Johnson • $94K — $170K *
Information Technology
5 - 7 years of experience
Job Overview by Ladders

Qualifications

  • Bachelor's degree in IT, Computer Science, Accounting, or related field.
  • 6+ years of experience in IT audit, controls, or SOX compliance.
  • Expertise in ITGC areas: access controls, change management, and operations.
  • Working knowledge of COSO, COBIT, PCAOB standards, and SOX 404.
  • Ability to articulate risk to stakeholders and drive remediation plans.

Responsibilities

  • Lead annual SOX IT planning and risk assessment activities.
  • Design and maintain ITGC frameworks aligned with industry standards.
  • Evaluate control effectiveness and conduct root cause analysis on deficiencies.
  • Liaise with external auditors for IT-related SOX compliance.
  • Drive remediation of control deficiencies with stakeholders.
  • Partner with teams to enhance user access and segregation of duties controls.
  • Assess control implications of technology changes, including ERP systems.

Benefits

  • Participation in 401(k) and pension plans.
  • Generous vacation and sick time policies.
  • Parental, bereavement, and caregiver leave provided.
  • Volunteer leave available for community service.
  • Flexible personal time for work-life balance.
Full Job Description
Job Function:
Technology Enterprise Strategy & Security

Job Sub Function:
Security & Controls

Job Category:
Scientific/Technology

All Job Posting Locations:
New Brunswick, New Jersey, United States of America, Palm Beach Gardens, Florida, United States of America, Raritan, New Jersey, United States of America, Raynham, Massachusetts, United States of America, Warsaw, Indiana, United States of America, West Chester, Pennsylvania, United States of America

Job Description:

DePuy Synthes is recruiting for a Professional, SOX Lead, located in New Brunswick, NJ or West Chester, PA or Palm Beach Gardens, FL or Warsaw, IN or Raynham, MA or Raritan, NJ.

Job Overview

The Professional, SOX Lead is a seasoned individual contributor within the Cybersecurity function, GRC, IT Controls & Cyber Culture sub-function, accountable for the design, execution, and continuous improvement of the IT General Controls (ITGC) and IT Application Controls environment supporting SOX compliance for DePuy Synthes. This role establishes control testing methods based on proven assurance frameworks, evaluates the reliability and effectiveness of internal information systems controls, and partners across IT, Finance, Internal Audit, and external auditors to ensure a clean, defensible control environment. The role applies advanced skills in IT controls and assurance to build industry-leading control practices, and contributes to compliance and remediation programs under general direction.

Key Responsibilities
  • Lead the annual SOX IT scoping, risk assessment, and control rationalization exercise across in-scope applications, databases, operating systems, and infrastructure, with direct impact on the achievement of assurance results.
  • Design, document, and maintain ITGC frameworks covering access to programs and data, change management, program development, and IT operations, ensuring alignment with COSO, COBIT, and PCAOB expectations.
  • Plan and execute walkthroughs, control design assessments, and operating effectiveness testing; evaluate results and perform root cause analysis on identified deficiencies.
  • Serve as the primary liaison for external auditors and Internal Audit for all IT-related SOX requests, coordinating PBC (Prepared by Client) deliverables, evidence submission, and issue resolution.
  • Assess and communicate the severity of control deficiencies (deficiency, significant deficiency, material weakness), and drive remediation plans with control owners through to validated closure.
  • Partner with Identity & Access Management and Identity Governance & Administration teams to strengthen user access provisioning, periodic access re-certification, privileged access, and segregation of duties (SoD) controls.
  • Evaluate the SOX control impact of ERP and technology change initiatives - including system implementations, migrations, upgrades, and separation/carve-out activity - and define control requirements prior to go-live.
  • Establish and monitor key control metrics, dashboards, and reporting to provide leadership visibility into control health, testing progress, and remediation status.
  • Assess the control implications of third-party and cloud service providers, including review of SOC 1 / SOC 2 reports and evaluation of complementary user entity controls (CUECs).
  • Interpret evolving regulations as they pertain to information systems, platforms, and IT operating processes, and translate requirements into practical control standards and procedures.
  • Drive automation and continuous controls monitoring opportunities to improve testing efficiency, reduce manual effort, and increase control coverage.
  • Develop and deliver training and awareness materials to control owners, strengthening compliance ownership and cyber culture across the IT organization.
  • Maintain complete and audit-ready documentation including narratives, process flows, RACM (Risk and Control Matrix), test scripts, and evidence repositories.


Qualifications

Education
  • Bachelor's degree in Information Technology, Computer Science, Accounting, Information Systems, Finance, or a related discipline.
  • Advanced degree or equivalent professional experience in cybersecurity or information systems (preferred).

Experience and Skills

Required:
  • 6+ years of progressive experience in IT audit, IT controls, SOX compliance, or technology risk and assurance, including hands-on ITGC design and testing.
  • Demonstrated expertise across the four ITGC domains: logical access, change management, program development, and IT operations.
  • Working knowledge of COSO 2013, COBIT, PCAOB auditing standards, and SOX 404 requirements.
  • Experience testing controls over ERP platforms (e.g., SAP, Oracle) and supporting databases, operating systems, and infrastructure layers.
  • Proven ability to assess deficiency severity, articulate risk to non-technical stakeholders, and drive remediation to closure.
  • Experience coordinating directly with external auditors and Internal Audit through a full annual SOX cycle.
  • Strong analytical, documentation, and written/verbal communication skills, with the ability to influence control owners without direct authority.

Preferred:
  • Big 4 or large multinational IT audit experience; MedTech, Life Sciences, or other regulated industry background.
  • Experience supporting SOX readiness within a divestiture, carve-out, spin-off, or standalone entity stand-up.
  • Familiarity with cloud control environments (AWS, Azure) and evaluation of SOC 1 / SOC 2 reports and CUECs.
  • Exposure to GRC tooling (e.g., ServiceNow IRM, Archer, AuditBoard, SAP GRC) and SoD analysis platforms.
  • Experience with continuous controls monitoring, control automation, or data analytics applied to control testing (e.g., Power BI, Tableau, SQL, Alteryx).
  • Experience adopting Generative AI / LLM-enabled tooling to accelerate evidence review, control documentation, and testing workflows.
  • Working knowledge of adjacent frameworks such as NIST CSF, ISO 27001, and ITIL.

Other:
  • Travel: Up to 10% domestic and international travel expected.
  • Language: English proficiency required.
  • Certifications: CISA required or in progress. CIA, CISSP, CRISC, CPA/CA, or ISO 27001 Lead Auditor preferred.


Johnson & Johnson announced plans to separate our Orthopaedics business to establish a standalone orthopaedics company, operating as DePuy Synthes. The process of the planned separation is anticipated to be completed within 18 to 24 months, subject to legal requirements, including consultation with works councils and other employee representative bodies, as may be required, regulatory approvals and other customary conditions and approvals. Should you accept this position, it is anticipated that, following conclusion of the transaction, you would be an employee of DePuy Synthes and your employment would be governed by DePuy Synthes employment processes, programs, policies, and benefit plans. In that case, details of any planned changes would be provided to you by DePuy Synthes at an appropriate time and subject to any necessary consultation processes.

Required Skills:

Preferred Skills:
Communication, Corrective and Preventive Action (CAPA), Critical Thinking, Information Security Auditing, Information Security Management System (ISMS), Information Technology (IT) Security Assessments, Information Technology Strategies, Mentorship, Network Optimization, Presentation Design, Process Optimization, Report Writing, Security Policies, Technical Credibility, Technologically Savvy, Training People, Vulnerability Assessments

The anticipated base pay range for this position is :
94,000.00 - 170,000.00 USD Annual

Additional Description for Pay Transparency:
Subject to the terms of their respective plans, employees are eligible to participate in the Company's consolidated retirement plan (pension) and savings plan (401(k)). Subject to the terms of their respective policies and date of hire, employees are eligible for the following time off benefits: • Vacation -120 hours per calendar year • Sick time - 40 hours per calendar year; for employees who reside in the State of Colorado -48 hours per calendar year; for employees who reside in the State of Washington -56 hours per calendar year • Holiday pay, including Floating Holidays -13 days per calendar year • Work, Personal and Family Time - up to 40 hours per calendar year • Parental Leave - 480 hours within one year of the birth/adoption/foster care of a child • Bereavement Leave - 240 hours for an immediate family member: 40 hours for an extended family member per calendar year • Caregiver Leave - 80 hours in a 52-week rolling period10 days • Volunteer Leave - 32 hours per calendar year • Military Spouse Time-Off - 80 hours per calendar year For additional general information on Company benefits, please go to: - https://www.careers.jnj.com/employee-benefits

About Johnson & Johnson

Scio Diamond creates single-crystal Type IIa diamonds for the jewelry market and for industrial applications. It employs a patent-protected chemical vapor deposition (CVD) process in a precisely controlled laboratory setting to produce diamonds. It was founded in 2009 and is headquartered in Greenville, South Carolina.

Johnson & Johnson Careers

Joining Johnson & Johnson provides an unparalleled opportunity to be a part of a global team of professionals dedicated to blending care, science, and innovation to profoundly change the trajectory of health for humanity.

Work You’ll Do

At Johnson & Johnson, you will engage in work that matters. Join our community of professionals in health care to drive significant and impactful changes across the globe. Our team at Johnson & Johnson leads with science and heart in sectors from pharmaceuticals to medical devices and consumer health products.

Transform Health Care

Leverage Johnson & Johnson’s culture of innovation to transform health care and improve the lives of people around the world. Our collaborative environment encourages leadership and growth, allowing you to pioneer new strategies for health care solutions with a diverse team of experts.

Innovative Work

Engage in groundbreaking work that enhances how care is delivered on a global scale. Johnson & Johnson’s commitment to innovative health solutions results in dynamic career paths filled with opportunities for professional growth and development.

Be Part of a Great Team

Our team at Johnson & Johnson thrives on collaboration and diversity. You will work alongside over 130,000 employees globally who are committed to making a lasting impact. With a culture that values diversity training and leadership, you are supported in both personal and professional growth.

Future-Proof Your Career

Johnson & Johnson offers a myriad of job opportunities and employment benefits designed to help you meet your career and personal goals. Our employees enjoy comprehensive benefits, including health insurance, retirement plans, and family-friendly policies that pave the way for a fulfilling career and life balance.

Explore Job Opportunities and Internships

Whether you’re looking to start your career or take it to the next level, Johnson & Johnson offers positions ranging from internships to leadership roles across various sectors. Enhance your skills through hands-on experience and our extensive networking and mentorship programs.

Johnson & Johnson Leadership and Development

Our commitment to leadership and continuous learning is at the core of our employment philosophy. Every position offers chances to lead, learn, and innovate. We provide extensive training programs and development courses that prepare you for the future of health care.

Stay Connected

Join Our Team

Search open positions that match your skills and interests. We are constantly hiring and looking for curious, driven, and compassionate team players.

SEARCH JOHNSON & JOHNSON JOBS

Keep Up to Date

Stay informed with career tips, insider perspectives, and industry-leading insights you can put to use today—all from the people who work here.

READ CAREERS BLOG

Job Alert Emails

Customize your subscription to receive job alerts, latest news, and insider tips tailored to your preferences. Discover the exciting and rewarding career opportunities that await at Johnson & Johnson. Join Johnson & Johnson today to be a part of a team that values innovation, leadership, and diversity, and see how far your ambition can take you.
Learn more about Johnson & Johnson
Size
141,700 employees
Market Cap
$462.7 billion
Industry
Net Income
$14.7 billion
Founded
1886
5 Year Trend
+5.5%
Revenue
$82.5 billion
NASDAQ

Similar Jobs

More Jobs at Johnson & Johnson

More Information Technology Jobs

Find similar Professional, SOX Lead jobs: