Sr. Director, Security & Defense, Orthopedics

Johnson & Johnson Johnson & Johnson · Pharma · New Brunswick, NJ +7

This role is for a Sr. Director of Security & Defense at DePuy Synthes, a new standalone orthopaedics company being separated from Johnson & Johnson. The position is responsible for setting and executing the cybersecurity and information protection strategy, overseeing cybersecurity operations, and ensuring compliance with global regulations in a regulated medical technology and healthcare environment. It involves leading teams, managing risks, and supporting business growth and digital innovation.

What you'd actually do

  1. Define and lead the enterprise security and cyber defense strategy aligned to business priorities and regulatory requirements.
  2. Oversee cybersecurity operations, including threat detection, incident response, vulnerability management, and security monitoring.
  3. Build and maintain a program focused on monitoring and responding to insider threats while supporting legal and employee relations as required.
  4. Establish and maintain security governance, policies, standards, and risk management frameworks across the organization.
  5. Lead and develop high‑performing security teams and external partners, fostering a strong culture of accountability and continuous improvement.

Skills

Required

  • 12-14 years of experience in cybersecurity, information security, or technology risk management, including senior leadership roles.
  • Demonstrated experience leading enterprise‑wide security programs in complex, regulated environments.
  • Strong knowledge of cyber defense, incident response, identity and access management, cloud security, and risk frameworks.
  • Experience leading and developing global or cross‑functional teams.

Nice to have

  • Experience supporting healthcare, life sciences, or medical device organizations.
  • Proven ability to influence executive stakeholders and translate technical risk into business impact.
  • Experience with large‑scale technology transformations or corporate separations.
  • Familiarity with global regulatory and compliance standards (e.g., ISO, NIST, GDPR, HIPAA).
  • Strong change leadership and strategic planning capabilities.
  • CISSP, CISM, CRISC, or equivalent certifications.

What the JD emphasized

  • complex, regulated environments
  • global cybersecurity, data protection, and industry regulations relevant to medical technology and healthcare environments
  • global regulatory and compliance standards (e.g., ISO, NIST, GDPR, HIPAA)