Johnson & Johnson

Sr. Director, GRC, IT Controls & Cyber Culture, Orthopedics

Johnson & Johnson$178K — $307K *
Healthcare
11 - 15 years of experience
Job Overview by Ladders

Qualifications

  • Bachelor's degree in Information Security, Computer Science, Engineering, or related field; Master's preferred.
  • 12-14 years of experience in cybersecurity and GRC leadership roles.
  • Proven track record in maturing enterprise GRC programs in regulated environments.
  • Experience leading cybersecurity advisory and governance teams.
  • Deep understanding of cybersecurity risk management, compliance frameworks, and SOX control expectations.
  • Background in overseeing external cybersecurity assessments and assurance processes.
  • Strong skills in strategic thinking, communication, and translating technical risks into business implications.

Responsibilities

  • Build and enhance the enterprise Governance, Risk & Compliance (GRC) function.
  • Lead and manage the Business Information Security Officer (BISO) organization to align security priorities with business goals.
  • Oversee enterprise cyber risk management activities, including assessments and reporting to leadership.
  • Manage the lifecycle of cybersecurity policies and standards ensuring compliance with organizational goals.
  • Coordinate external cybersecurity assessments, including insurance and third-party requests.
  • Establish an IT controls and assurance framework for control design and reporting.
  • Drive cybersecurity compliance with global regulations and cultivate security awareness within the organization.

Benefits

  • Participation in the Company's long-term incentive program.
  • 401(k) savings plan with matching contributions.
  • Generous vacation policy - 120 hours per year.
  • Up to 40 hours of personal and family time per year.
  • 480 hours parental leave following a child's birth or adoption.
  • Comprehensive bereavement and caregiver leave policies.
  • Volunteer leave allowance of 32 hours per year.
Full Job Description
Job Function:
Technology Enterprise Strategy & Security

Job Sub Function:
Security & Controls

Job Category:
People Leader

All Job Posting Locations:
Palm Beach Gardens, Florida, United States of America, Raritan, New Jersey, United States of America, Raynham, Massachusetts, United States of America, Warsaw, Indiana, United States of America, West Chester, Pennsylvania, United States of America

Job Description:

DePuy Synthes is recruiting for a(n) Sr. Director, GRC, IT Controls and Cyber Culture.

Johnson & Johnson announced plans to separate our Orthopedics business to establish a standalone orthopedics company, operating as DePuy Synthes. The process of the planned separation is anticipated to be completed within 18 to 24 months, subject to legal requirements, including consultation with works councils and other employee representative bodies, as may be required, regulatory approvals and other customary conditions and approvals. Should you accept this position, it is anticipated that, following conclusion of the transaction, you would be an employee of DePuy Synthes and your employment would be governed by DePuy Synthes employment processes, programs, policies, and benefit plans. In that case, details of any planned changes would be provided to you by DePuy Synthes at an appropriate time and subject to any necessary consultation processes.

Job Overview

This role serves as a senior cybersecurity leader reporting to the CISO, with enterprise accountability for building, maturing, and operationalizing the Governance, Risk & Compliance (GRC) function across DePuy Synthes. The Sr. Director will oversee the BISO manager organization, establish scalable risk governance practices, strengthen security awareness and behavior based culture programs, and drive implementation of IT controls and an enterprise assurance framework. The role will also oversee external cybersecurity assessments and disclosures, including cyber insurance, ESG-related cybersecurity inputs, and other third-party assurance activities. This highly visible leadership role will help ensure cybersecurity risk, compliance, control effectiveness, and cultural adoption are consistently managed across the enterprise in support of business priorities, regulatory expectations, and organizational resilience.

Key Responsibilities

  • Build and mature the enterprise GRC function, including governance forums, risk management processes, compliance oversight, control monitoring, issue management, and executive reporting.


  • Provide leadership and oversight for the BISO manager organization, ensuring consistent engagement with business leaders, effective cyber risk advisory support, and alignment of security priorities to business objectives.


  • Lead enterprise cyber risk management activities, including risk identification, assessment, mitigation planning, escalation, and reporting to senior leadership and governance bodies.


  • Own the enterprise cybersecurity policy and standards lifecycle - from creation and implementation to continuous review - ensuring clarity, compliance, and alignment with organizational goals.


  • Oversee SOX cybersecurity and IT control activities, including implementation, operating effectiveness, evidence readiness, remediation tracking, and partnership with Finance, Internal Audit, External Audit, and IT control owners.


  • Establish and operationalize an enterprise IT controls and assurance framework that enables consistent control design, testing, monitoring, reporting, and continuous improvement across the organization.


  • Lead oversight of external cybersecurity assessments and assurance requests, including cyber insurance questionnaires, ESG-related cybersecurity inputs, customer or partner assessments, and other third-party reviews requiring enterprise cyber risk and control representation.


  • Drive cybersecurity compliance with applicable global regulations, standards, and frameworks, ensuring the organization can demonstrate control effectiveness and audit readiness.


  • Lead security awareness, behavior, and culture initiatives that improve workforce accountability, reduce human-centric risk, and embed secure practices into day-to-day business operations.


  • Lead and develop high-performing cybersecurity leaders and teams, fostering a culture of accountability, collaboration, disciplined execution, and continuous improvement.


  • Provide executive-level reporting on cybersecurity risk, compliance status, control effectiveness, assurance outcomes, and program maturity to senior leadership and governance bodies.


Qualifications

Education

  • Required: Bachelor's degree in Information Security, Computer Science, Engineering, or a related field.


  • Preferred: Master's degree (MS, MBA, or equivalent) in Cybersecurity, Information Systems, or Business.


Experience and Skills

Required:

  • 12-14 years of progressive experience in cybersecurity, information security, technology risk management, IT controls, or GRC, including senior leadership roles.


  • Demonstrated experience building or maturing enterprise GRC programs in a regulated, global, or complex operating environment.


  • Experience leading BISO, cyber risk advisory, security governance, or business aligned cybersecurity teams.


  • Deep knowledge of cybersecurity risk management, compliance frameworks, IT controls, SOX control expectations, assurance practices, and audit readiness.


  • Experience overseeing external cybersecurity assessments, including cyber insurance, ESG-related cybersecurity reporting, customer or partner assessments, and third-party assurance requests.


  • Experience building, mentoring, and leading senior level cybersecurity teams.


  • Strong strategic, analytical, and communication skills, with the ability to translate technical risk, control gaps, and compliance obligations into business impact.


Preferred:

  • Experience implementing or transforming enterprise IT controls, SOX programs, control testing, remediation governance, and assurance frameworks.


  • Experience driving cybersecurity awareness, behavior change, and culture programs across a large enterprise.


  • Experience operating in complex, global organizations undergoing transformation or separation.


  • Demonstrated success improving cybersecurity maturity, control effectiveness, and risk accountability at scale.


  • Proven ability to influence executive stakeholders and partner effectively across IT, Finance, Internal Audit, External Audit, Legal, Risk, Compliance, and business leadership functions.


Other:

  • Language: English (fluent)


  • Travel: Up to 20%, domestic and international


  • Certifications (preferred): CISSP, CISM, CRISC, or equivalent


For more information on how we support the whole health of our employees throughout their wellness, career and life journey, please visit www.careers.jnj.com.

Required Skills:

Preferred Skills:
Business Process Design, Crisis Management, Critical Thinking, Cybersecurity, Developing Others, Inclusive Leadership, Industry Analysis, Information Security Auditing, Information Security Management System (ISMS), Information Technology (IT) Security Assessments, Information Technology Strategies, Leadership, Presentation Design, Process Optimization, Risk Management Framework, Security Architecture Design, Security Policies, Strategic Thinking

The anticipated base pay range for this position is :
$178,000.00 - $307,050.00

Additional Description for Pay Transparency:
Subject to the terms of their respective plans, employees are eligible to participate in the Company's consolidated retirement plan (pension) and savings plan (401(k)).

This position is eligible to participate in the Company's long-term incentive program.

Subject to the terms of their respective policies and date of hire, employees are eligible for the following time off benefits:

Vacation -120 hours per calendar year

Sick time - 40 hours per calendar year; for employees who reside in the State of Colorado -48 hours per calendar year; for employees who reside in the State of Washington -56 hours per calendar year

Holiday pay, including Floating Holidays -13 days per calendar year

Work, Personal and Family Time - up to 40 hours per calendar year

Parental Leave - 480 hours within one year of the birth/adoption/foster care of a child

Bereavement Leave - 240 hours for an immediate family member: 40 hours for an extended family member per calendar year

Caregiver Leave - 80 hours in a 52-week rolling period10 days

Volunteer Leave - 32 hours per calendar year

Military Spouse Time-Off - 80 hours per calendar year

For additional general information on Company benefits, please go to: - https://www.careers.jnj.com/employee-benefits

About Johnson & Johnson

Scio Diamond creates single-crystal Type IIa diamonds for the jewelry market and for industrial applications. It employs a patent-protected chemical vapor deposition (CVD) process in a precisely controlled laboratory setting to produce diamonds. It was founded in 2009 and is headquartered in Greenville, South Carolina.

Johnson & Johnson Careers

Joining Johnson & Johnson provides an unparalleled opportunity to be a part of a global team of professionals dedicated to blending care, science, and innovation to profoundly change the trajectory of health for humanity.

Work You’ll Do

At Johnson & Johnson, you will engage in work that matters. Join our community of professionals in health care to drive significant and impactful changes across the globe. Our team at Johnson & Johnson leads with science and heart in sectors from pharmaceuticals to medical devices and consumer health products.

Transform Health Care

Leverage Johnson & Johnson’s culture of innovation to transform health care and improve the lives of people around the world. Our collaborative environment encourages leadership and growth, allowing you to pioneer new strategies for health care solutions with a diverse team of experts.

Innovative Work

Engage in groundbreaking work that enhances how care is delivered on a global scale. Johnson & Johnson’s commitment to innovative health solutions results in dynamic career paths filled with opportunities for professional growth and development.

Be Part of a Great Team

Our team at Johnson & Johnson thrives on collaboration and diversity. You will work alongside over 130,000 employees globally who are committed to making a lasting impact. With a culture that values diversity training and leadership, you are supported in both personal and professional growth.

Future-Proof Your Career

Johnson & Johnson offers a myriad of job opportunities and employment benefits designed to help you meet your career and personal goals. Our employees enjoy comprehensive benefits, including health insurance, retirement plans, and family-friendly policies that pave the way for a fulfilling career and life balance.

Explore Job Opportunities and Internships

Whether you’re looking to start your career or take it to the next level, Johnson & Johnson offers positions ranging from internships to leadership roles across various sectors. Enhance your skills through hands-on experience and our extensive networking and mentorship programs.

Johnson & Johnson Leadership and Development

Our commitment to leadership and continuous learning is at the core of our employment philosophy. Every position offers chances to lead, learn, and innovate. We provide extensive training programs and development courses that prepare you for the future of health care.

Stay Connected

Join Our Team

Search open positions that match your skills and interests. We are constantly hiring and looking for curious, driven, and compassionate team players.

SEARCH JOHNSON & JOHNSON JOBS

Keep Up to Date

Stay informed with career tips, insider perspectives, and industry-leading insights you can put to use today—all from the people who work here.

READ CAREERS BLOG

Job Alert Emails

Customize your subscription to receive job alerts, latest news, and insider tips tailored to your preferences. Discover the exciting and rewarding career opportunities that await at Johnson & Johnson. Join Johnson & Johnson today to be a part of a team that values innovation, leadership, and diversity, and see how far your ambition can take you.
Learn more about Johnson & Johnson
Size
141,700 employees
Market Cap
$462.7 billion
Industry
Net Income
$14.7 billion
Founded
1886
5 Year Trend
+5.5%
Revenue
$82.5 billion
NASDAQ

Similar Jobs

More Jobs at Johnson & Johnson

More Healthcare Jobs

Find similar Sr. Director, GRC, IT Controls & Cyber Culture, Orthopedics jobs: