Sr. Director, Security & Defense, Orthopedics (evergreen)

Johnson & Johnson Johnson & Johnson · Pharma · Pune, Maharashtra, India

This role is for a Sr. Director of Security & Defense in the Orthopaedics business unit (DePuy Synthes) at Johnson & Johnson. The primary focus is on setting and executing the cybersecurity and information protection strategy, overseeing security operations, and ensuring compliance with regulations in a complex, regulated healthcare environment. The role involves leadership of security teams and reporting on security posture to executive leadership.

What you'd actually do

  1. Define and lead the enterprise security and cyber defense strategy aligned to business priorities and regulatory requirements.
  2. Oversee cybersecurity operations, including threat detection, incident response, vulnerability management, and security monitoring.
  3. Build and maintain a program focused on monitoring and responding to insider threats while supporting legal and employee relations as required.
  4. Establish and maintain security governance, policies, standards, and risk management frameworks across the organization.
  5. Lead and develop high‑performing security teams and external partners, fostering a strong culture of accountability and continuous improvement.

Skills

Required

  • 12-14 years of experience in cybersecurity, information security, or technology risk management
  • senior leadership roles
  • leading enterprise-wide security programs in complex, regulated environments
  • cyber defense
  • incident response
  • identity and access management
  • cloud security
  • risk frameworks
  • leading and developing global or cross-functional teams

Nice to have

  • healthcare, life sciences, or medical device organizations experience
  • influence executive stakeholders
  • translate technical risk into business impact
  • large-scale technology transformations or corporate separations
  • global regulatory and compliance standards (e.g., ISO, NIST, GDPR, HIPAA)
  • change leadership
  • strategic planning capabilities
  • CISSP
  • CISM
  • CRISC
  • equivalent certifications

What the JD emphasized

  • senior leadership roles
  • complex, regulated environments
  • global cybersecurity, data protection, and industry regulations