Sr. Director, Dep Ciso Grc & Security, Orthopedics

Johnson & Johnson Johnson & Johnson · Pharma · New Brunswick, NJ +7

Senior cybersecurity leader responsible for Governance, Risk & Compliance (GRC) and Product Security for DePuy Synthes, a medical technology company. The role involves shaping and executing cybersecurity strategy to protect patients, products, data, and operations within a regulated environment, ensuring compliance with global regulations and standards, and driving secure-by-design principles.

What you'd actually do

  1. Provide strategic leadership and operational oversight for enterprise GRC and Product Security programs, ensuring alignment with business priorities and regulatory requirements.
  2. Partner with the CISO to define and execute the cybersecurity strategy, serving as a delegate and decision authority as needed.
  3. Lead enterprise risk management activities, including cyber risk identification, assessment, mitigation, and reporting to executive leadership.
  4. Own the enterprise cyber security policy lifecycle—from creation and implementation to continuous review—ensuring clarity, compliance, and alignment with organizational goals.
  5. Oversee cybersecurity compliance with global regulations, standards, and frameworks relevant to medical devices and digital health solutions.

Skills

Required

  • cybersecurity
  • information security
  • technology risk management
  • GRC
  • Product Security
  • regulated environment
  • cybersecurity risk management
  • compliance frameworks
  • regulatory expectations
  • building and leading cybersecurity teams
  • strategic thinking
  • analytical skills
  • communication skills
  • translating technical risk into business impact

Nice to have

  • product security for connected, software-enabled, or digital medical devices
  • global regulatory bodies and standards impacting product cybersecurity
  • operating in complex, global organizations undergoing transformation or separation
  • incident response governance
  • vulnerability disclosure
  • post-market surveillance

What the JD emphasized

  • regulated environment
  • global regulations
  • product security