Sr. Director, Dep Ciso Grc & Security, Orthopedics

Johnson & Johnson Johnson & Johnson · Pharma · Pune, Maharashtra, India

This role is a senior cybersecurity leader responsible for Governance, Risk & Compliance (GRC) and Product Security within a regulated medical technology environment. The Sr. Director will shape and execute cybersecurity strategy to protect patients, products, data, and operations, ensuring alignment with business priorities and regulatory requirements. Key responsibilities include leading enterprise risk management, policy lifecycle, product security governance, and developing high-performing teams. Experience in regulated environments and strong strategic, analytical, and communication skills are required.

What you'd actually do

  1. Provide strategic leadership and operational oversight for enterprise GRC and Product Security programs, ensuring alignment with business priorities and regulatory requirements.
  2. Partner with the CISO to define and execute the cybersecurity strategy, serving as a delegate and decision authority as needed.
  3. Lead enterprise risk management activities, including cyber risk identification, assessment, mitigation, and reporting to executive leadership.
  4. Own the enterprise cyber security policy lifecycle—from creation and implementation to continuous review—ensuring clarity, compliance, and alignment with organizational goals.
  5. Oversee cybersecurity compliance with global regulations, standards, and frameworks relevant to medical devices and digital health solutions.

Skills

Required

  • Bachelor’s degree in Information Security, Computer Science, Engineering, or a related field
  • 12–14 years of progressive experience in cybersecurity, information security, or technology risk management, including senior leadership roles
  • Demonstrated experience leading GRC and Product Security programs in a regulated environment (medical device, healthcare, or life sciences strongly preferred)
  • Deep knowledge of cybersecurity risk management, compliance frameworks, and regulatory expectations
  • Experience building, mentoring, and leading senior‑level cybersecurity teams
  • Strong strategic, analytical, and communication skills, with the ability to translate technical risk into business impact

Nice to have

  • Master’s degree (MS, MBA, or equivalent) in Cybersecurity, Information Systems, or Business
  • Experience supporting product security for connected, software‑enabled, or digital medical devices
  • Familiarity with global regulatory bodies and standards impacting product cybersecurity
  • Experience operating in complex, global organizations undergoing transformation or separation
  • Background in incident response governance, vulnerability disclosure, and post‑market surveillance
  • Demonstrated success driving cybersecurity maturity and cultural change at scale
  • Proven ability to influence executive stakeholders and partner effectively across IT, R&D, Quality, Legal, and Regulatory f

What the JD emphasized

  • regulated environment
  • product security
  • cybersecurity risk management
  • compliance frameworks
  • regulatory expectations
  • product security for connected, software‑enabled, or digital medical devices
  • global regulatory bodies and standards impacting product cybersecurity