Johnson & Johnson

Sr. Manager, IT Control, Assurance & SOX

Johnson & Johnson$122K — $245K *
Information Technology
8 - 10 years of experience
Job Overview by Ladders

Qualifications

  • Bachelor's degree in Computer Science, Information Security, Business, Engineering, or a related field required.
  • 10+ years of experience in IT audit, IT controls, SOX, or IT compliance, ideally at a Big 4 firm.
  • Deep expertise in IT Controls & Assurance, SOX, and IT Compliance.
  • Strong working knowledge of control and compliance frameworks including COBIT and COSO.
  • Proven experience in multi-entity audits with External Auditors and Internal Audit teams.
  • Experience assessing IT controls in cloud environments (AWS, Azure, GCP) and ERP/SaaS platforms.

Responsibilities

  • Own the enterprise IT control framework aligned to COBIT, COSO, and NIST CSF.
  • Lead assessments and remediation efforts for IT controls across multiple platforms.
  • Collaborate with teams to design and embed controls in development cycles.
  • Extend assurance programs to third-party services, reviewing relevant controls and reports.
  • Serve as the primary liaison for audit, coordinating testing and management responses.
  • Drive continuous monitoring and automation to enhance control coverage.
  • Lead end-to-end IT SOX program, including risk assessment and reporting.

Benefits

  • Eligibility to participate in pension and 401(k) plans.
  • 120 hours of vacation time annually.
  • Sick time and personal time off policies vary by state.
  • Up to 480 hours of paid parental leave.
  • Comprehensive bereavement and caregiver leave policies.
  • Volunteer leave and military spouse time-off available.
  • Work-life balance initiatives including floating holidays.
Full Job Description
Job Function:
Technology Enterprise Strategy & Security

Job Sub Function:
Security & Controls

Job Category:
People Leader

All Job Posting Locations:
New Brunswick, New Jersey, United States of America, Palm Beach Gardens, Florida, United States of America, Raynham, Massachusetts, United States of America, Warsaw, Indiana, United States of America, West Chester, Pennsylvania, United States of America

Job Description:

DePuy Synthes is recruiting for a(n) Sr. Manager, IT Controls, Assurance & SOX located in New Brunswick, NJ or Palm Beach Gardens, FL or Warsaw, IN or West Chester, PA or Raynham, MA.

This role leads the design, execution, and continuous improvement of DePuy Synthes' IT controls, assurance, and (SOX) program within the Governance & Risk function of Cybersecurity. The Sr. Manager will own the enterprise IT SOX control framework, IT general controls (ITGCs), automated application controls, and IT-related assurance activities across financially relevant systems, cloud platforms, and third-party services. This position partners closely with Finance, Internal Audit, External Auditors, Application Owners, and Infrastructure teams to ensure a strong control environment, timely remediation of deficiencies, and audit-ready operations as the company stands up as an independent, publicly traded entity.

Key Responsibilities

IT Controls & Assurance

  • Own the enterprise IT control framework - including ITGCs (access, change, operations), automated application controls, and IT-dependent business controls - aligned to COBIT, COSO, NIST CSF, and internal policies


  • Lead design and operating effectiveness assessments of IT controls across ERP, cloud, SaaS, and infrastructure platforms, and drive remediation of identified gaps


  • Partner with application, cloud, and infrastructure teams to embed preventive and detective controls by design in the SDLC, DevOps pipelines, and cloud landing zones


  • Extend the assurance program to third parties and managed service providers, including review of SOC 1/SOC 2 reports, complementary user entity controls (CUECs), and bridge letters


  • Serve as the primary IT liaison for Internal Audit, External Auditors, and regulatory examiners - coordinating walkthroughs, evidence, testing, and management responses


  • Advance continuous controls monitoring (CCM), analytics, and automation to expand control coverage and reduce manual testing effort


SOX

  • Own the end-to-end IT SOX program - scoping, risk assessment, control design, management testing, deficiency evaluation, and reporting across in-scope financial systems and supporting IT infrastructure


  • Define the annual IT SOX plan in partnership with Finance, Internal Audit, and External Auditors, including in-scope applications, ITGCs, key reports, and automated controls


  • Lead management testing of ITGCs and IT-dependent business controls, ensuring timely completion, quality of evidence, and consistent workpaper standards


  • Drive deficiency evaluation, root cause analysis, remediation planning, and status reporting to leadership and the Audit Committee


  • Stand up and operate the first-year SOX program for the standalone DePuy Synthes entity, including RCMs, narratives, and control ownership across the new operating model


  • Modernize the SOX program through GRC tooling (e.g., ServiceNow IRM, AuditBoard, Archer), risk-based sampling, and automated evidence collection


Compliance

  • Lead IT compliance activities across applicable regulatory, contractual, and internal policy requirements - including SOX, SEC, GxP, HIPAA, GDPR, and other data protection and industry regulations


  • Maintain an integrated IT policy, standard, and control library, and drive alignment across Cybersecurity, IT, Legal, Privacy, and Compliance functions


  • Track regulatory change, assess IT impact, and update controls, policies, and evidence to keep the environment continuously compliant


  • Coordinate IT responses to customer, partner, and regulator due diligence requests, security questionnaires, and certification programs (e.g., ISO 27001, HITRUST where applicable)


  • Assess compliance implications of emerging technologies (cloud, AI/ML, GenAI, automation) and update the control and compliance framework accordingly


  • Provide training, guidance, and clear escalation paths to IT and business control owners to reinforce a strong compliance culture


Governance, Reporting & Team Leadership

  • Provide regular reporting to the CISO, Director of Governance & Risk, Finance leadership, and the Audit Committee on IT controls, SOX status, and compliance posture


  • Support Day-1 readiness and post-separation BAU operations for controls, assurance, SOX, and compliance across the standalone DePuy Synthes environment


  • Build, lead, and develop a global team across the US and the GCC in India, and manage co-source/outsourced testing partners for quality, consistency, and efficiency


  • Coach and mentor team members, fostering technical depth, audit acumen, and strong business partnership skills


Qualifications

Education:

  • Bachelor's degree in Computer Science, Information Security, Business, Engineering, or a related field (required).


  • Master's degree in Cybersecurity, Information Systems, or Business Administration (preferred).


Experience and Skills:

Required:

  • 10+ years of experience in IT audit, IT controls, SOX, or IT compliance, including experience in a Big 4 or large public company environment


  • Deep expertise across all three capability areas: IT Controls & Assurance, SOX (ITGCs and IT-dependent business controls), and IT Compliance


  • Strong working knowledge of control and compliance frameworks - COBIT, COSO, NIST CSF, ISO 27001, and SOC 1/SOC 2


  • Proven experience coordinating with External Auditors, Internal Audit, and business process owners on complex, multi-entity audits


  • Demonstrated ability to evaluate control deficiencies, drive remediation, and communicate risk and compliance status to executive stakeholders


  • Experience assessing IT controls and compliance in cloud environments (AWS, Azure, GCP) and across ERP and SaaS platforms


  • Strong leadership, stakeholder management, and cross-functional collaboration skills, including managing global and co-sourced teams


Preferred:

  • Experience supporting a separation, spin-off, IPO, or standalone company standing up its first-year SOX and compliance program


  • Familiarity with SAP S/4HANA, Workday, Oracle, or other ERP platforms and their control configurations


  • Experience with GRC platforms (e.g., ServiceNow IRM, AuditBoard, Archer) and continuous controls monitoring / audit analytics


  • Background in healthcare, MedTech, pharmaceuticals, or other highly regulated industries


  • Familiarity with regulatory and privacy requirements relevant to IT - SOX, SEC, GxP, HIPAA, GDPR, and emerging AI regulations


Other:

  • Language: English proficiency required


  • Travel: Up to 15% domestic and international travel


  • Certifications (preferred): CISA, CPA, CIA, CISSP, or equivalent


Required Skills:

Preferred Skills:
Business Process Design, Collaboration, Crisis Management, Critical Thinking, Cyber Threat Intelligence, Developing Others, Inclusive Leadership, Information Security Auditing, Information Security Management System (ISMS), Information Technology (IT) Security Assessments, Information Technology Strategies, Leadership, Managing Managers, People Performance Management, Presentation Design, Process Optimization, Security Architecture Design, Security Policies

The anticipated base pay range for this position is :
122,000.00 - 245,000.00 USD Annual

Additional Description for Pay Transparency:
Subject to the terms of their respective plans, employees are eligible to participate in the Company's consolidated retirement plan (pension) and savings plan (401(k)). Subject to the terms of their respective policies and date of hire, employees are eligible for the following time off benefits: • Vacation -120 hours per calendar year • Sick time - 40 hours per calendar year; for employees who reside in the State of Colorado -48 hours per calendar year; for employees who reside in the State of Washington -56 hours per calendar year • Holiday pay, including Floating Holidays -13 days per calendar year • Work, Personal and Family Time - up to 40 hours per calendar year • Parental Leave - 480 hours within one year of the birth/adoption/foster care of a child • Bereavement Leave - 240 hours for an immediate family member: 40 hours for an extended family member per calendar year • Caregiver Leave - 80 hours in a 52-week rolling period10 days • Volunteer Leave - 32 hours per calendar year • Military Spouse Time-Off - 80 hours per calendar year For additional general information on Company benefits, please go to: - https://www.careers.jnj.com/employee-benefits

About Johnson & Johnson

Scio Diamond creates single-crystal Type IIa diamonds for the jewelry market and for industrial applications. It employs a patent-protected chemical vapor deposition (CVD) process in a precisely controlled laboratory setting to produce diamonds. It was founded in 2009 and is headquartered in Greenville, South Carolina.

Johnson & Johnson Careers

Joining Johnson & Johnson provides an unparalleled opportunity to be a part of a global team of professionals dedicated to blending care, science, and innovation to profoundly change the trajectory of health for humanity.

Work You’ll Do

At Johnson & Johnson, you will engage in work that matters. Join our community of professionals in health care to drive significant and impactful changes across the globe. Our team at Johnson & Johnson leads with science and heart in sectors from pharmaceuticals to medical devices and consumer health products.

Transform Health Care

Leverage Johnson & Johnson’s culture of innovation to transform health care and improve the lives of people around the world. Our collaborative environment encourages leadership and growth, allowing you to pioneer new strategies for health care solutions with a diverse team of experts.

Innovative Work

Engage in groundbreaking work that enhances how care is delivered on a global scale. Johnson & Johnson’s commitment to innovative health solutions results in dynamic career paths filled with opportunities for professional growth and development.

Be Part of a Great Team

Our team at Johnson & Johnson thrives on collaboration and diversity. You will work alongside over 130,000 employees globally who are committed to making a lasting impact. With a culture that values diversity training and leadership, you are supported in both personal and professional growth.

Future-Proof Your Career

Johnson & Johnson offers a myriad of job opportunities and employment benefits designed to help you meet your career and personal goals. Our employees enjoy comprehensive benefits, including health insurance, retirement plans, and family-friendly policies that pave the way for a fulfilling career and life balance.

Explore Job Opportunities and Internships

Whether you’re looking to start your career or take it to the next level, Johnson & Johnson offers positions ranging from internships to leadership roles across various sectors. Enhance your skills through hands-on experience and our extensive networking and mentorship programs.

Johnson & Johnson Leadership and Development

Our commitment to leadership and continuous learning is at the core of our employment philosophy. Every position offers chances to lead, learn, and innovate. We provide extensive training programs and development courses that prepare you for the future of health care.

Stay Connected

Join Our Team

Search open positions that match your skills and interests. We are constantly hiring and looking for curious, driven, and compassionate team players.

SEARCH JOHNSON & JOHNSON JOBS

Keep Up to Date

Stay informed with career tips, insider perspectives, and industry-leading insights you can put to use today—all from the people who work here.

READ CAREERS BLOG

Job Alert Emails

Customize your subscription to receive job alerts, latest news, and insider tips tailored to your preferences. Discover the exciting and rewarding career opportunities that await at Johnson & Johnson. Join Johnson & Johnson today to be a part of a team that values innovation, leadership, and diversity, and see how far your ambition can take you.
Learn more about Johnson & Johnson
Size
141,700 employees
Market Cap
$462.7 billion
Industry
Net Income
$14.7 billion
Founded
1886
5 Year Trend
+5.5%
Revenue
$82.5 billion
NASDAQ

Similar Jobs

More Jobs at Johnson & Johnson

More Information Technology Jobs

Find similar Sr. Manager, IT Control, Assurance & SOX jobs: