
At Johnson & Johnson, we believe health is everything. Our strength in healthcare innovation empowers us to build a world where complex diseases are prevented, treated, and cured, where treatments are smarter and less invasive, and solutions are personal. Through our expertise in Innovative Medicine and MedTech, we are uniquely positioned to innovate across the full spectrum of healthcare solutions today to deliver the breakthroughs of tomorrow, and profoundly impact health for humanity. Learn more at jnj.com
As guided by Our Credo, Johnson & Johnson is responsible to our employees who work with us throughout the world. We provide an inclusive work environment where each person is considered as an individual. At Johnson & Johnson, we respect the diversity and dignity of our employees and recognize their merit.
Job Function:
Legal & Compliance
Job Sub Function:
Law Business Partners
Job Category:
Professional
All Job Posting Locations:
Raynham, Massachusetts, United States of AmericaJohnson & Johnson announced plans to separate our Orthopaedics business to establish a standalone orthopaedics company, operating as DePuy Synthes. The process of the planned separation is anticipated to be completed within 18 to 24 months, subject to legal requirements, including consultation with works councils and other employee representative bodies, as may be required, regulatory approvals and other customary conditions and approvals. Should you accept this position, it is anticipated that, following conclusion of the transaction, you would be an employee of DePuy Synthes and your employment would be governed by DePuy Synthes employment processes, programs, policies, and benefit plans. In that case, details of any planned changes would be provided to you by DePuy Synthes at an appropriate time and subject to any necessary consultation processes.
This role serves as the senior privacy leader for DePuy Synthes in the region, with accountability forprivacy governance and formal Data Protection Officer (DPO) duties. The Director, Privacy Officer & DPOprovides strategic leadership to ensure compliance with global and local data protection laws while enabling responsible innovation across a complex medical technology organization. This role has significant enterprise impact, partnering closely with Legal, IT, Security,Health CareCompliance, HR, Commercial, Clinical, Medical Safety and HEMA,and R&D teams to embedprivacy‑by‑designacross business operations and digitalproducts
Key Responsibilities
Lead the implementation and ongoing oversight of the DePuySynthesprivacyprogram in the region, ensuring alignment with applicable local and regional data protection laws and regulations.
Advise business partners on privacy and data protection requirements in all stages of R&D, product development, commercialization, clinical trials, HEMAactivitiesand lifecycle management.
Serve as the designated Data Protection Officer (DPO), acting as an independent advisor on data protection obligations and risk management.
Lead efforts to embed privacy capabilities in named privacy stewards from relevant functions, including handling escalations, drivingconsistencyand delivering ongoing training and education to the stewards.
Identifyany required regional-specific variants fromglobalprivacypolicies, standards, and proceduresto support compliant collection, use, transfer, and retention of personal data in the region.
Providestrategic guidance to business leaders on privacy risks associated with new products, digital health solutions, clinical activities, and commercial initiatives.
Oversee regional privacy impact assessments, data transfer assessments, and mitigation plans forhigh-riskprocessing activities.
Partner with Information Security and Legal teams to support incident response, breach management, and regulatory communications in the region whenrequired
Lead privacy training and awareness programs to strengthen a culture of data protection and accountability across the organization.
Monitor regional regulatory developments and emerging privacy risks, translating requirements into practical business guidance.
Maintain external relationships with regional regulators and internal stakeholders to support audits, inquiries,inspectionsand data incident responses in conjunction with cross-functional partners.
Provide support for data contracting processes,including forescalations
Qualifications
Education
Bachelor’s degreerequired, preferably in Law, Information Systems, Business, ora relatedfield.
Advanced degree (JD, LLM, MBA, or equivalent) preferred.
Experience and Skills
Required:
Minimum 10–12 yearsof progressive experience in privacy, data protection, cybersecurityor related legal roles, including leadership responsibility, including in a complex global corporation or private practice.
Demonstrated experience serving as, or supporting, a Data Protection Officer function within a regulated environment.
Experience in privacy data regulations in the healthcare industry.
Strong working knowledge of global privacy regulations (e.g., GDPR, APAC privacy frameworks) and their business application.
Proven ability to influence senior leaders andoperateeffectively in a complex, global organization.
Experience partnering with technology, security, and digital teams onprivacy‑by‑designinitiatives.
Preferred:
Specific data protection or privacy experience within medical devices, medtech, life sciencespharmaceutical industriesor healthcare insurers or systems.
Experience supporting global or regional privacy programs across multiplejurisdictions
Strong judgment, independence, and ability to manage sensitive matters with discretion and integrity.
Prior engagement with regulators and supervisory authorities.
Demonstratedpeopleleadership or program leadership experience.
Other:
Language:English (additionallanguages a plus).
Travel:Up to ~20%, domestic and occasional international.
Certifications (Preferred):CIPP/E, CIPP/US, CIPM, or equivalent privacy certifications.
For more information on how we support the whole health of our employees throughout their wellness,careerand life journey, please visit www.careers.jnj.com
Required Skills:
Preferred Skills:
Business Agility, Collaborating, Commercial Laws, Compliance Management, Corporate Governance, Dispute Resolution, Lawyering, Legal Documents Preparation, Legal Services, Negotiation, Process Improvements, Representing, Risk Management, Strategic Thinking, Tactical Planning, Technical Credibility
The anticipated base pay range for this position is :
$150,000.00 - $258,750.00
Additional Description for Pay Transparency:
Subject to the terms of their respective plans, employees are eligible to participate in the Company’s consolidated retirement plan (pension) and savings plan (401(k)).
This position is eligible to participate in the Company’s long-term incentive program.
Subject to the terms of their respective policies and date of hire, employees are eligible for the following time off benefits:
• Vacation –120 hours per calendar year
• Sick time - 40 hours per calendar year; for employees who reside in the State of Colorado –48 hours per calendar year; for employees who reside in the State of Washington –56 hours per calendar year
• Holiday pay, including Floating Holidays –13 days per calendar year
• Work, Personal and Family Time - up to 40 hours per calendar year
• Parental Leave – 480 hours within one year of the birth/adoption/foster care of a child
• Bereavement Leave – 240 hours for an immediate family member: 40 hours for an extended family member per calendar year
• Caregiver Leave – 80 hours in a 52-week rolling period10 days
• Volunteer Leave – 32 hours per calendar year
• Military Spouse Time-Off – 80 hours per calendar year
For additional general information on Company benefits, please go to: - https://www.careers.jnj.com/employee-benefits

At Johnson & Johnson, we believe health is everything. As a focused healthcare company, with expertise in Innovative Medicine and MedTech, we’re empowered to tackle the world’s toughest health challenges, innovate through science and technology, and transform patient care.
All of this is possible because of our people. We’re passionate innovators who put people first, and through our purpose-driven culture and talented workforce, we are stronger than ever.
Learn more at https://www.jnj.com. Community Guidelines: http://www.jnj.com/social-media-community-guidelines