Director, Incident Response & Threat

Johnson & Johnson Johnson & Johnson · Pharma · Pune, Maharashtra, India

Director, Incident Response & Threat role at Johnson & Johnson (DePuy Synthes) responsible for leading the global incident response program and threat management strategy. This role involves protecting the digital environment from cyber threats, directing investigations, developing playbooks, partnering with various departments, overseeing threat intelligence, and leading a team. Requires experience in cybersecurity, incident response, and regulated environments.

What you'd actually do

  1. Lead the global incident response and threat management program, including preparation, detection, response, and recovery activities.
  2. Direct investigations of cybersecurity incidents, ensuring timely containment, root‑cause analysis, and post‑incident reporting.
  3. Develop and maintain incident response playbooks, escalation paths, and crisis management procedures.
  4. Partner with IT, Legal, Privacy, Quality, and Business leaders to manage cyber incidents and regulatory or compliance obligations.
  5. Oversee threat intelligence capabilities to proactively identify emerging threats and vulnerabilities relevant to the MedTech environment.

Skills

Required

  • 10-12 years of progressive experience in cybersecurity, information security, or IT risk management, including leadership roles.
  • Proven experience leading enterprise‑scale incident response and threat management programs.
  • Strong knowledge of cyber threat landscapes, attack techniques, and defensive strategies.
  • Experience working in regulated environments (e.g., healthcare, life sciences, MedTech, or similarly regulated industries).
  • Demonstrated ability to lead cross‑functional teams during high‑pressure incidents.
  • Excellent executive communication, judgment, and decision‑making skills.
  • Bachelor’s degree in Computer Science, Information Security, Engineering, or a related field.

Nice to have

  • Master’s degree in Cybersecurity, Information Systems, or Business Administration
  • Experience supporting global organizations with complex technology environments.
  • Familiarity with security frameworks such as NIST, ISO 27001, or similar standards.
  • Experience integrating threat intelligence into security operations and risk management.
  • Prior people leadership experience managing managers or senior individual contributors.
  • Experience with cloud, OT, and medical device security considerations.
  • CISSP
  • CISM

What the JD emphasized

  • Experience working in regulated environments (e.g., healthcare, life sciences, MedTech, or similarly regulated industries).
  • Proven experience leading enterprise‑scale incident response and threat management programs.