Sr. Manager, IT Control, Assurance & SOX
$122k - $245kJohnson & Johnson Innovative Medicine
At Johnson & Johnson, we believe health is everything. Our strength in healthcare innovation empowers us to build a world where complex diseases are prevented, treated, and cured, where treatments are smarter and less invasive, and solutions are personal. Through our expertise in Innovative Medicine and MedTech, we are uniquely positioned to innovate across the full spectrum of healthcare solutions today to deliver the breakthroughs of tomorrow, and profoundly impact health for humanity. Learn more at jnj.com
As guided by Our Credo, Johnson & Johnson is responsible to our employees who work with us throughout the world. We provide an inclusive work environment where each person is considered as an individual. At Johnson & Johnson, we respect the diversity and dignity of our employees and recognize their merit.
Job Function:
Technology Enterprise Strategy & SecurityJob Sub Function:
Security & ControlsJob Category:
People LeaderAll Job Posting Locations:
New Brunswick, New Jersey, United States of America, Palm Beach Gardens, Florida, United States of America, Raynham, Massachusetts, United States of America, Warsaw, Indiana, United States of America, West Chester, Pennsylvania, United States of AmericaJob Description:
DePuy Synthes is recruiting for a(n) Sr. Manager, IT Controls, Assurance & SOX located in New Brunswick, NJ or Palm Beach Gardens, FL or Warsaw, IN or West Chester, PA or Raynham, MA.
This role leads the design, execution, and continuous improvement of DePuy Synthes' IT controls, assurance, and (SOX) program within the Governance & Risk function of Cybersecurity. The Sr. Manager will own the enterprise IT SOX control framework, IT general controls (ITGCs), automated application controls, and IT-related assurance activities across financially relevant systems, cloud platforms, and third-party services. This position partners closely with Finance, Internal Audit, External Auditors, Application Owners, and Infrastructure teams to ensure a strong control environment, timely remediation of deficiencies, and audit-ready operations as the company stands up as an independent, publicly traded entity.
Key Responsibilities
IT Controls & Assurance
Own the enterprise IT control framework — including ITGCs (access, change, operations), automated application controls, and IT-dependent business controls — aligned to COBIT, COSO, NIST CSF, and internal policies
Lead design and operating effectiveness assessments of IT controls across ERP, cloud, SaaS, and infrastructure platforms, and drive remediation of identified gaps
Partner with application, cloud, and infrastructure teams to embed preventive and detective controls by design in the SDLC, DevOps pipelines, and cloud landing zones
Extend the assurance program to third parties and managed service providers, including review of SOC 1/SOC 2 reports, complementary user entity controls (CUECs), and bridge letters
Serve as the primary IT liaison for Internal Audit, External Auditors, and regulatory examiners — coordinating walkthroughs, evidence, testing, and management responses
Advance continuous controls monitoring (CCM), analytics, and automation to expand control coverage and reduce manual testing effort
SOX
Own the end-to-end IT SOX program — scoping, risk assessment, control design, management testing, deficiency evaluation, and reporting across in-scope financial systems and supporting IT infrastructure
Define the annual IT SOX plan in partnership with Finance, Internal Audit, and External Auditors, including in-scope applications, ITGCs, key reports, and automated controls
Lead management testing of ITGCs and IT-dependent business controls, ensuring timely completion, quality of evidence, and consistent workpaper standards
Drive deficiency evaluation, root cause analysis, remediation planning, and status reporting to leadership and the Audit Committee
Stand up and operate the first-year SOX program for the standalone DePuy Synthes entity, including RCMs, narratives, and control ownership across the new operating model
Modernize the SOX program through GRC tooling (e.g., ServiceNow IRM, AuditBoard, Archer), risk-based sampling, and automated evidence collection
Compliance
Lead IT compliance activities across applicable regulatory, contractual, and internal policy requirements — including SOX, SEC, GxP, HIPAA, GDPR, and other data protection and industry regulations
Maintain an integrated IT policy, standard, and control library, and drive alignment across Cybersecurity, IT, Legal, Privacy, and Compliance functions
Track regulatory change, assess IT impact, and update controls, policies, and evidence to keep the environment continuously compliant
Coordinate IT responses to customer, partner, and regulator due diligence requests, security questionnaires, and certification programs (e.g., ISO 27001, HITRUST where applicable)
Assess compliance implications of emerging technologies (cloud, AI/ML, GenAI, automation) and update the control and compliance framework accordingly
Provide training, guidance, and clear escalation paths to IT and business control owners to reinforce a strong compliance culture
Governance, Reporting & Team Leadership
Provide regular reporting to the CISO, Director of Governance & Risk, Finance leadership, and the Audit Committee on IT controls, SOX status, and compliance posture
Support Day-1 readiness and post-separation BAU operations for controls, assurance, SOX, and compliance across the standalone DePuy Synthes environment
Build, lead, and develop a global team across the US and the GCC in India, and manage co-source/outsourced testing partners for quality, consistency, and efficiency
Coach and mentor team members, fostering technical depth, audit acumen, and strong business partnership skills
Qualifications
Education:
Bachelor's degree in Computer Science, Information Security, Business, Engineering, or a related field (required).
Master's degree in Cybersecurity, Information Systems, or Business Administration (preferred).
Experience and Skills:
Required:
10+ years of experience in IT audit, IT controls, SOX, or IT compliance, including experience in a Big 4 or large public company environment
Deep expertise across all three capability areas: IT Controls & Assurance, SOX (ITGCs and IT-dependent business controls), and IT Compliance
Strong working knowledge of control and compliance frameworks — COBIT, COSO, NIST CSF, ISO 27001, and SOC 1/SOC 2
Proven experience coordinating with External Auditors, Internal Audit, and business process owners on complex, multi-entity audits
Demonstrated ability to evaluate control deficiencies, drive remediation, and communicate risk and compliance status to executive stakeholders
Experience assessing IT controls and compliance in cloud environments (AWS, Azure, GCP) and across ERP and SaaS platforms
Strong leadership, stakeholder management, and cross-functional collaboration skills, including managing global and co-sourced teams
Preferred:
Experience supporting a separation, spin-off, IPO, or standalone company standing up its first-year SOX and compliance program
Familiarity with SAP S/4HANA, Workday, Oracle, or other ERP platforms and their control configurations
Experience with GRC platforms (e.g., ServiceNow IRM, AuditBoard, Archer) and continuous controls monitoring / audit analytics
Background in healthcare, MedTech, pharmaceuticals, or other highly regulated industries
Familiarity with regulatory and privacy requirements relevant to IT — SOX, SEC, GxP, HIPAA, GDPR, and emerging AI regulations
Other:
Language: English proficiency required
Travel: Up to 15% domestic and international travel
Certifications (preferred): CISA, CPA, CIA, CISSP, or equivalent
For more information on how we support the whole health of our employees throughout their wellness, career and life journey, please visit .
Johnson & Johnson announced plans to separate our Orthopaedics business to establish a standalone orthopaedics company, operating as DePuy Synthes. The process of the planned separation is anticipated to be completed within 18 to 24 months, subject to legal requirements, including consultation with works councils and other employee representative bodies, as may be required, regulatory approvals and other customary conditions and approvals. Should you accept this position, it is anticipated that, following conclusion of the transaction, you would be an employee of DePuy Synthes and your employment would be governed by DePuy Synthes employment processes, programs, policies, and benefit plans. In that case, details of any planned changes would be provided to you by DePuy Synthes at an appropriate time and subject to any necessary consultation processes.
Johnson & Johnson is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, age, national origin, disability, protected veteran status or other characteristics protected by federal, state or local law. We actively seek qualified candidates who are protected veterans and individuals with disabilities as defined under VEVRAA and Section 503 of the Rehabilitation Act.
Johnson & Johnson is committed to providing an interview process that is inclusive of our applicants’ needs. If you are an individual with a disability and would like to request an accommodation, external applicants please contact us via , internal employees contact AskGS to be directed to your accommodation resource.
#LI-Hybrid
#DePuySynthesCareers
Required Skills:
Preferred Skills:
Business Process Design, Collaboration, Crisis Management, Critical Thinking, Cyber Threat Intelligence, Developing Others, Inclusive Leadership, Information Security Auditing, Information Security Management System (ISMS), Information Technology (IT) Security Assessments, Information Technology Strategies, Leadership, Managing Managers, People Performance Management, Presentation Design, Process Optimization, Security Architecture Design, Security PoliciesThe anticipated base pay range for this position is :
122,000.00 - 245,000.00 USD AnnualAdditional Description for Pay Transparency:
Subject to the terms of their respective plans, employees are eligible to participate in the Company’s consolidated retirement plan (pension) and savings plan (401(k)). Subject to the terms of their respective policies and date of hire, employees are eligible for the following time off benefits: • Vacation –120 hours per calendar year • Sick time - 40 hours per calendar year; for employees who reside in the State of Colorado –48 hours per calendar year; for employees who reside in the State of Washington –56 hours per calendar year • Holiday pay, including Floating Holidays –13 days per calendar year • Work, Personal and Family Time - up to 40 hours per calendar year • Parental Leave – 480 hours within one year of the birth/adoption/foster care of a child • Bereavement Leave – 240 hours for an immediate family member: 40 hours for an extended family member per calendar year • Caregiver Leave – 80 hours in a 52-week rolling period10 days • Volunteer Leave – 32 hours per calendar year • Military Spouse Time-Off – 80 hours per calendar year For additional general information on Company benefits, please go to: -- ...Internal Audit professional to execute financial, operational, SOX, and IT audits. You will lead small audit teams, partner with... ...arrangement and travel up to 25% globally. Join a team focused on strong controls and strategic risk assessment. #J-18808-Ljbffr Merck & Co.Senior
- ...Sr. Manager, Biostatistician/Programmer Legend Biotech is a global biotechnology company dedicated to treating, and one day curing,... ...program specifications, programming documentation, and quality control activities in accordance with internal standards and regulatory...SeniorInterim roleWorldwide
- ...SummaryThe Senior SAP Manufacturing Applications Manager serves as the primary liaison between... ...closely with business stakeholders, IT teams, and external partners to ensure enterprise... ...to SAP softwareSome familiarity with SOX and IRM complianceSome familiarity with FDA...SeniorTemporary workWork experience placementWorldwide
- ...seeking a Senior Specialist (P-3) in Audit and Assurance Services. The role supports financial, operational, SOX and IT audits, with opportunities to lead small audit... ...across the organization to ensure strong internal controls and high-quality audit outputs. The position...Senior
$168.37k - $220.99k
...Legend Biotech is seeking a Sr. Manager Data Governance as part of the... ...to industry regulations (GxP, SOX, NIS2, GDPR, etc.). The role collaborates closely with IT, business stakeholders, and compliance... .... - Set metrics and controls to maintain data accuracy, consistency...SeniorPermanent employmentFull timeTemporary workFor contractorsLocal areaWorldwideFlexible hoursShift work$84.63k - $112.84k
...The Role The Senior Technical Project Manager within the GCO Front Door is... ...Sales, CN Operations, & Delivery. The Sr Technical Project Manager drives structured... ...making. Ensure alignment with CN Project Controls for customer commitments, delivery capabilities...SeniorFull timeContract workTemporary workRemote work- An established industry player is seeking a Senior Manager for ExM Quality Analytical to lead analytical support in a dynamic manufacturing... ...will possess a strong background in pharmaceutical quality control, project management, and analytical methodologies. You will...Senior
$113k - $155k
...with heartJob SummarySr. Manager, Market Intelligence... ...research in the future). The Sr. Manager, Market... ...reports, etc.) to Quality Assurance (QA), and by ensuring... ...promotional material content and control. Follow procedures for... ...systems preferred.It is Terumo’s policy to...SeniorTemporary workWork at officeWorldwideFlexible hours$178k - $307.05k
...Johnson is currently recruiting for an IT Senior Director, Digital Factory... ...operating cadence, performance management, and continuous improvement of the... ...statement-of-work execution, adherence to controls and compliance requirements (e.g., SOX/GxP where applicable), and clear...SeniorFull timeWork at officeImmediate start- Jobtailor in the United States is seeking a senior SAP Testing lead to shape strategies, drive testing initiatives, and assure quality across SAP releases. You will coordinate SIT and UAT efforts and collaborate with cross-functional teams on requirements and testing in...Senior
$85k - $105k
...avoid out‑of‑specification situations. Assure compliance with state and federal regulations... ...cGMP requirements applicable to quality control laboratory; advanced technical skills to... ...and report actions to the laboratory management timely; ability to identify trends in...SeniorTemporary workLocal areaFlexible hours$120.3k - $222.6k
...accounting, upholding workplace safety, managing our supply chain and sampling, supporting... ...innovation, maintaining our facilities and assuring the integrity and completeness of all... ...strategy and partner closely to deliver the IT project. Uses appropriate tools and techniques...SeniorLocal areaFlexible hoursNight shift$178k - $307.05k
...to help shape the legal frameworks that enable innovation while managing cybersecurity, data, AI, and technology risk. As the Senior... ...business objectives. Develop governance frameworks, policies, and controls that align with global legal and regulatory requirements, with...SeniorLocal areaImmediate start- ...firm located in Port Reading, New Jersey is seeking an IT Experienced Manager for Technology Risk Assurance. This role requires a proven track record in... ...preparing reports, and ensuring compliance with IT controls. Candidates should possess a Bachelor's degree in a...Senior
$90k - $115k
...growth driven by market demand for Risk advisory and assurance services. Our team is seeking an experienced IT SOX Senior Consultant with experience performing Sarbanes Oxley (SOX) compliance consulting, Internal Controls assessment, COSO consulting, IT control risk...SeniorFull timeWork at officeLocal area- Description:The Supervisor, Quality Assurance, schedules and coordinates daily priorities... ...strict compliance with cGMP/SOPs.Assists management with the development of new and revised... ...assignments as required.Handles Change Controls, Deviations, Corrective Actions and Preventative...All shiftsShift work
$196k - $342.7k
...decisions—they reshape how HR plans, predicts, personalizes, and performs. By unifying data science, employee listening, knowledge management, and responsible AI, HR Data & Intelligence is transforming workforce signals into strategic advantage, ensuring HR is not only...SeniorFull timeImmediate start$170k - $200k
...or an alternative application process. Director, Quality Assurance Full Time Management E Brunswick, NJ, US 7 days ago Requisition ID: 1633 Salary... ...system documentation, investigations, deviations, change controls, and other Quality Management System (QMS) records....Full timeContract workWork at officeImmediate startVisa sponsorshipWork visaFlexible hours$122k - $211.03k
...searching for the best talent for a Sr. Manager MedTech PLM Platform... ...standards, e.g., APIs, security controls, approved technologies, data standards... ...Processes and related IT Procedures across the platform... ...Implement necessary ISRM, GxP, SOX, Asset mgmt. and other (compliance...SeniorFull timeTemporary workFor contractorsWork at officeLocal areaImmediate start$144k - $374k
...aerospace sector to serve as a Senior Manager who possesses a robust... ...Agentic AI, preferably with a controls systems / electrical engineering... ...outcomes. You will provide assurance to leadership by managing timelines... ..., Business Analysts, and IT teams) to define data requirements...SeniorFull timeSummer holidayFlexible hours$150k - $198k
...wherever we go next!Advancing healthcare with heartJob SummarySr. Manager Medical Writing, manages and oversees the work of medical... ...communication / clinical research related documents. 20% of role. Assure Quality Oversight & Regulatory Compliance. Oversee literature review...SeniorTemporary workWork experience placementWork at officeWorldwide- ...collaborative Digital Systems Quality Assurance function that works closely... ...to work across Quality, CSV, IT, business, and vendor teams.... ..., compliant, and in a controlled state. Review and approve... ...computerized system lifecycle management. Do You Bring Proven Success...SeniorFull time2 days per week1 day per week
$100k - $120k
...the Data Center Cabling Supervisor, Sr. Technician, you will lead and manage, cabling installations for major AI... ...purposes such as training, quality assurance, and process improvement. Candidates... ...desktop as well as providing managed IT services for clients. Our professional...SeniorFull timeFor subcontractorWork at office- HCLTech is seeking a Design Control Lead in Raritan, NJ to drive design controls, risk management and validation across product development teams. The role emphasizes end-to-end traceability, design change control, and regulatory alignment to deliver compliant, high-reliability...Senior
- Virtusa Corporation is expanding its Insurance IT solutions and seeking a high-impact Niche Sales Director/Senior Director to win new... ...multi‑million deals. You will orchestrate internal capabilities, manage the pipeline, and drive BAU, large deals and partner channels. Reporting...Senior
- An established industry player is seeking a skilled networking professional with extensive experience in SDDC technologies and cloud solutions. This role involves building and operating advanced networking infrastructures, utilizing tools like Cisco ACI and VMware NSX. ...Senior
$176.5k - $339k
...business growth and long-term customer value. The CXO Experience Assurance: UAT & Quality Innovation function establishes the vision,... ...automated, zero-human-intervention testing gates. Rather than managing manual upskilling cycles, you bring structural discipline to enforce...SeniorPermanent employmentFull timeTemporary workPart timeWork at officeImmediate startWork from homeShift work3 days per week$85k - $115k
IT Assurance Experienced Senior, Technology Risk Assurance Join to apply for the IT Assurance... ...software systems. Documents and tests general controls across technology environments to... ...computer assisted audit techniques (CAATs) and manages the implementation of those techniques...SeniorWork at office- ...company which partners with many of the leading employers in the Life Sciences, IT, and Financial Services sectors, feel free to check us out at Job Description Job Title: Project Manager/ Sr. IT Consultant Location: Fort Washington, PA / Raritan NJ DURATION: 10+...SeniorWork at office
- ...1200 Airport Road, North Brunswick NJ Title Senior Manager, R&D Department Research & Development Reports to... ...Collaboration Partner closely with Production, Quality Assurance, Quality Control, Regulatory Affairs, Procurement, Supply Chain, Sales, and...SeniorContract workTemporary workWork at officeLocal areaShift work
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Sr. Manager, IT Control, Assurance & SOX. Be the first to apply!
- massage manager New Brunswick, NJ
- court manager New Brunswick, NJ
- renovation manager New Brunswick, NJ
- esports manager New Brunswick, NJ
- online manager New Brunswick, NJ
- storage manager New Brunswick, NJ
- clubhouse manager New Brunswick, NJ
- animal shelter manager New Brunswick, NJ
- ups manager New Brunswick, NJ
- fedex manager New Brunswick, NJ




