Director, Business Information Security

Johnson & Johnson Johnson & Johnson · Pharma · Pune, Maharashtra, India

Director, Business Information Security for DePuy Synthes, a healthcare company. This role involves developing and executing information security strategies, partnering with business leaders, managing risks, overseeing security controls, driving incident response, influencing secure-by-design practices, and leading cross-functional teams in a regulated environment. The position requires strong leadership, communication, and decision-making skills, with a focus on protecting information assets while enabling business growth and innovation.

What you'd actually do

  1. Lead the development and execution of the business information security strategy aligned with DePuy Synthes objectives and enterprise security direction.
  2. Act as the primary security partner to business leaders, providing risk-based guidance that enables innovation while protecting critical data and systems.
  3. Identify, assess, and manage information security risks across business processes, products, and digital initiatives.
  4. Oversee implementation and adoption of security controls, policies, and standards in alignment with enterprise frameworks and regulatory requirements.
  5. Drive incident preparedness, response, and recovery in partnership with enterprise cyber and technology teams.

Skills

Required

  • 10–12 years of experience in information security, cybersecurity, or technology risk management, including leadership at the director or senior manager level.
  • Demonstrated experience aligning security strategy with complex business objectives in a regulated environment.
  • Strong understanding of security governance, risk management, and compliance frameworks.
  • Proven ability to influence senior stakeholders and translate technical risk into business impact.
  • Experience leading cross-functional, matrixed teams and driving enterprise-scale initiatives.
  • Excellent communication, executive presence, and decision-making skills.
  • Bachelor’s degree in Information Security, Computer Science, Engineering, or a related field

Nice to have

  • Master’s degree in Information Security, Technology Management, Business Administration, or a related discipline.
  • Experience supporting MedTech, healthcare, life sciences, or other highly regulated industries.
  • Hands-on experience with product security, cloud security, and third-party risk management.
  • Track record of leading security transformation or maturity programs.
  • Experience operating in global organ

What the JD emphasized

  • regulated environment
  • regulatory requirements
  • patient safety
  • product integrity
  • regulatory compliance