Sr. Director, Security & Defense, Orthopedics

Johnson & Johnson Johnson & Johnson · Pharma · New Brunswick, NJ +7

This role is for a Sr. Director of Security & Defense within the Orthopedics business (DePuy Synthes) at Johnson & Johnson. The primary focus is on setting and executing the cybersecurity and information protection strategy, safeguarding enterprise systems, data, products, and operations in a complex, regulated environment. Responsibilities include overseeing cybersecurity operations, incident response, vulnerability management, and ensuring compliance with global regulations relevant to medical technology and healthcare.

What you'd actually do

  1. Define and lead the enterprise security and cyber defense strategy aligned to business priorities and regulatory requirements.
  2. Oversee cybersecurity operations, including threat detection, incident response, vulnerability management, and security monitoring.
  3. Build and maintain a program focused on monitoring and responding to insider threats while supporting legal and employee relations as required.
  4. Establish and maintain security governance, policies, standards, and risk management frameworks across the organization.
  5. Lead and develop high‑performing security teams and external partners, fostering a strong culture of accountability and continuous improvement.

Skills

Required

  • 12-14 years of experience in cybersecurity, information security, or technology risk management, including senior leadership roles.
  • Demonstrated experience leading enterprise‑wide security programs in complex, regulated environments.
  • Strong knowledge of cyber defense, incident response, identity and access management, cloud security, and risk frameworks.
  • Experience leading and developing global or cross‑functional teams.

Nice to have

  • Experience supporting healthcare, life sciences, or medical device organizations.
  • Proven ability to influence executive stakeholders and translate technical risk into business impact.
  • Experience with large‑scale technology transformations or corporate separations.
  • Familiarity with global regulatory and compliance standards (e.g., ISO, NIST, GDPR, HIPAA).
  • Strong change leadership and strategic planning capabilities.
  • CISSP, CISM, CRISC, or equivalent.

What the JD emphasized

  • complex, regulated environments
  • global cybersecurity, data protection, and industry regulations