Sr. Director, Security & Defense, Orthopedics (evergreen)

Johnson & Johnson Johnson & Johnson · Pharma · Pune, Maharashtra, India

The Sr. Director, Security & Defense is a senior technology leadership role responsible for setting and executing the cybersecurity and information protection strategy for DePuy Synthes, a global leader in Orthopaedics. This leader will safeguard enterprise systems, data, products, and operations while enabling business growth and digital innovation, partnering with executive leadership, IT, Legal, Privacy, and business stakeholders to ensure a resilient, compliant, and risk-aware security posture. The role involves defining and leading the enterprise security and cyber defense strategy, overseeing cybersecurity operations (threat detection, incident response, vulnerability management, monitoring), building programs for insider threat monitoring, establishing security governance, policies, standards, and risk management frameworks, leading security teams and external partners, providing executive reporting on security posture and risks, ensuring compliance with global cybersecurity and data protection regulations relevant to medical technology and healthcare, and supporting M&A and separation initiatives by assessing and mitigating cybersecurity risks. The role requires 12-14 years of experience in cybersecurity, information security, or technology risk management, including senior leadership roles, and demonstrated experience leading enterprise-wide security programs in complex, regulated environments. Experience supporting healthcare, life sciences, or medical device organizations is preferred, as is familiarity with global regulatory and compliance standards like HIPAA.

What you'd actually do

  1. Define and lead the enterprise security and cyber defense strategy aligned to business priorities and regulatory requirements.
  2. Oversee cybersecurity operations, including threat detection, incident response, vulnerability management, and security monitoring.
  3. Build and maintain a program focused on monitoring and responding to insider threats while supporting legal and employee relations as required.
  4. Establish and maintain security governance, policies, standards, and risk management frameworks across the organization.
  5. Lead and develop high‑performing security teams and external partners, fostering a strong culture of accountability and continuous improvement.

Skills

Required

  • cybersecurity
  • information security
  • technology risk management
  • enterprise security programs
  • cyber defense
  • incident response
  • identity and access management
  • cloud security
  • risk frameworks
  • leading global or cross-functional teams

Nice to have

  • healthcare
  • life sciences
  • medical device organizations
  • influence executive stakeholders
  • translate technical risk into business impact
  • large-scale technology transformations
  • corporate separations
  • ISO
  • NIST
  • GDPR
  • HIPAA
  • change leadership
  • strategic planning
  • CISSP
  • CISM
  • CRISC

What the JD emphasized

  • senior leadership roles
  • enterprise-wide security programs
  • complex, regulated environments
  • global cybersecurity, data protection, and industry regulations