Sign up to access all features of our service.
  • Job search
  • Favorites
  • Create a CV
    New
  • Salaries
  • Subscriptions

Sr. Director, GRC, IT Controls & Cyber Culture, Orthopedics

Johnson & Johnson MedTech

Job Function: Technology Enterprise Strategy & Security Job Sub Function: Security & Controls Job Category: People Leader All Job Posting Locations: Raritan, New Jersey, United States of America Raynham, Massachusetts, United States of America Warsaw, Indiana, United States of America West Chester, Pennsylvania, United States of America West Palm Beach, Florida, United States Job Overview This role serves as a senior cybersecurity leader reporting to the CISO, with enterprise accountability for building, maturing, and operationalizing the Governance, Risk & Compliance (GRC) function across DePuy Synthes. The Sr. Director will oversee the BISO manager organization, establish scalable risk governance practices, strengthen security awareness and behavior‑based culture programs, and drive implementation of IT controls and an enterprise assurance framework. The role will also oversee external cybersecurity assessments and disclosures, including cyber insurance, ESG‑related cybersecurity inputs, and other third‑party assurance activities. This highly visible leadership role will help ensure cybersecurity risk, compliance, control effectiveness, and cultural adoption are consistently managed across the enterprise in support of business priorities, regulatory expectations, and organizational resilience. Key Responsibilities Build and mature the enterprise GRC function, including governance forums, risk management processes, compliance oversight, control monitoring, issue management, and executive reporting. Provide leadership and oversight for the BISO manager organization, ensuring consistent engagement with business leaders, effective cyber risk advisory support, and alignment of security priorities to business objectives. Lead enterprise cyber risk management activities, including risk identification, assessment, mitigation planning, escalation, and reporting to senior leadership and governance bodies. Own the enterprise cybersecurity policy and standards lifecycle – from creation and implementation to continuous review – ensuring clarity, compliance, and alignment with organizational goals. Oversee SOX cybersecurity and IT control activities, including implementation, operating effectiveness, evidence readiness, remediation tracking, and partnership with Finance, Internal Audit, External Audit, and IT control owners. Establish and operationalize an enterprise IT controls and assurance framework that enables consistent control design, testing, monitoring, reporting, and continuous improvement across the organization. Lead oversight of external cybersecurity assessments and assurance requests, including cyber insurance questionnaires, ESG‑related cybersecurity inputs, customer or partner assessments, and other third‑party reviews requiring enterprise cyber risk and control representation. Drive cybersecurity compliance with applicable global regulations, standards, and frameworks, ensuring the organization can demonstrate control effectiveness and audit readiness. Lead security awareness, behavior and culture initiatives that improve workforce accountability, reduce human‑centric risk, and embed secure practices into day‑to‑day business operations. Lead and develop high‑performing cybersecurity leaders and teams, fostering a culture of accountability, collaboration, disciplined execution, and continuous improvement. Provide executive‑level reporting on cybersecurity risk, compliance status, control effectiveness, assurance outcomes, and program maturity to senior leadership and governance bodies. Qualifications Education Required: Bachelor’s degree in Information Security, Computer Science, Engineering, or a related field. Preferred: Master’s degree (MS, MBA, or equivalent) in Cybersecurity, Information Systems, or Business. Required Experience and Skills 12–14 years of progressive experience in cybersecurity, information security, technology risk management, IT controls, or GRC, including senior leadership roles. Demonstrated experience building or maturing enterprise GRC programs in a regulated, global, or complex operating environment. Experience leading BISO, cyber risk advisory, security governance, or business‑aligned cybersecurity teams. Deep knowledge of cybersecurity risk management, compliance frameworks, IT controls, SOX control expectations, assurance practices, and audit readiness. Experience overseeing external cybersecurity assessments, including cyber insurance, ESG‑related cybersecurity reporting, customer or partner assessments, and third‑party assurance requests. Experience building, mentoring, and leading senior‑level cybersecurity teams. Strong strategic, analytical, and communication skills, with the ability to translate technical risk, control gaps, and compliance obligations into business impact. Preferred Experience and Skills Experience implementing or transforming enterprise IT controls, SOX programs, control testing, remediation governance, and assurance frameworks. Experience driving cybersecurity awareness, behavior change, and culture programs across a large enterprise. Experience operating in complex, global organizations undergoing transformation or separation. Demonstrated success improving cybersecurity maturity, control effectiveness, and risk accountability at scale. Proven ability to influence executive stakeholders and partner effectively across IT, Finance, Internal Audit, External Audit, Legal, Risk, Compliance, and business leadership functions. Other Language: English (fluent) Travel: Up to 20%, domestic and international Certifications (preferred): CISSP, CISM, CRISC, or equivalent Salary Anticipated base pay range: $178,000.00 – $307,050.00 Benefits Vacation – 120 hours per calendar year Sick time – 40 hours per calendar year; for employees who reside in Colorado – 48 hours per calendar year; for employees who reside in Washington – 56 hours per calendar year Holiday pay, including floating holidays – 13 days per calendar year Work, personal and family time – up to 40 hours per calendar year Parental leave – 480 hours within one year of the birth/adoption/foster care of a child Bereavement leave – 240 hours for an immediate family member; 40 hours for an extended family member per calendar year Caregiver leave – 80 hours in a 52‑week rolling period; 10 days Volunteer leave – 32 hours per calendar year Military spouse time‑off – 80 hours per calendar year Equal Opportunity Employer Johnson & Johnson is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, age, national origin, disability, protected veteran status or other characteristics protected under federal, state or local law. We actively seek qualified candidates who are protected veterans and individuals with disabilities as defined under VEVRAA and Section 503 of the Rehabilitation Act. Johnson and Johnson is committed to providing an interview process that is inclusive of our applicants’ needs. If you are an individual with a disability and would like to request an accommodation, please email the Employee Health Support Center (View email address on click.appcast.io) or contact AskGS to be directed to your accommodation resource. #J-18808-Ljbffr Johnson & Johnson MedTech

Vacancy posted more than 2 months ago

Do you want to receive more vacancies?

Subscribe and receive similar vacancies to Sr. Director, GRC, IT Controls & Cyber Culture, Orthopedics. Be the first to apply!