Cybersecurity Lead Medtech R&d

Johnson & Johnson Johnson & Johnson · Pharma · Raritan, NJ +4

Johnson & Johnson is seeking a Cybersecurity Lead for their MedTech R&D division. This role involves partnering with technology and business teams to ensure the secure development and implementation of innovative technology solutions, protect intellectual property, and drive cybersecurity adoption across R&D labs. The lead will provide security guidance, manage security assessments and remediation, and ensure compliance with cybersecurity regulations.

What you'd actually do

  1. Provide early/proactive engagement with project teams to drive business understanding and execution of the security capabilities and services needed for innovative technology solutions; End to end support for large programs.
  2. Provide tailored security guidance (based on risk and complexity) - Interpret & apply the IAPP requirements and standards for unique technology and business initiatives.
  3. Drive cybersecurity adoption across R&D labs and sites (Electrophysiology) to secure IT/OT assets and enable safe & secure innovation.
  4. Lead the cyber operational portfolio from identification > consulting remediation plan > completion partnering across ISRM, business, and technology teams.
  5. Establish data analytics to provide security posture across the business units, functions, and sites.

Skills

Required

  • Bachelor’s degree in computer science, information technology, cybersecurity, business administration, or another rigorous discipline
  • 5+ years of working in IT, OT, and/or Engineering with a security focus
  • hands-on implementation level understanding of key security technologies and controls (e.g., access control, IDP/IDR, anti-malware, patch management, encryption technologies, forensics etc.)
  • Direct working and/or supporting experience for Research and Development functions
  • Experience in leading/performing security assessments and providing security assurance across various levels of the enterprise architecture (data, application, host, middleware, network, Infrastructure) to ensure data protection
  • Solid understanding of current security threats, mitigation measures, and security vendors/technologies.
  • Experience with cloud security (e.g., AWS, Azure, Salesforce)
  • Experience with security standards (e.g., ISO27001, HiTrust, NIST, etc.)
  • Experience leading and influencing security audits (e.g., SOC Type 2 reporting, PCI, ISO 27001)

Nice to have

  • Certifications in cybersecurity (CISM, CISSP, ISA-62443), audit (CISA), or risk management (CRISC) are preferred.
  • Awareness of security trends in process, tooling, and threats
  • Good understanding and exposure to data visualization tools such as PowerBI, Tableau etc.
  • Big picture perspective and attention to detail focus to align strategic and tactical security aspects.
  • Ability to collaborate, network and influence all levels of the organization, cross sector, cross-function and global and establish oneself as an inspiring leader with expertise in space.
  • Excellent communication and collaboration skills, able to network, interface and influence at all levels of the organization, cross sector, cross-functionally and globally.

What the JD emphasized

  • security focus is required
  • security assurance
  • security standards (e.g., ISO27001, HiTrust, NIST, etc.) is required
  • security audits (e.g., SOC Type 2 reporting, PCI, ISO 27001) is