
At Johnson & Johnson, we believe health is everything. Our strength in healthcare innovation empowers us to build a world where complex diseases are prevented, treated, and cured, where treatments are smarter and less invasive, and solutions are personal. Through our expertise in Innovative Medicine and MedTech, we are uniquely positioned to innovate across the full spectrum of healthcare solutions today to deliver the breakthroughs of tomorrow, and profoundly impact health for humanity. Learn more at jnj.com
As guided by Our Credo, Johnson & Johnson is responsible to our employees who work with us throughout the world. We provide an inclusive work environment where each person is considered as an individual. At Johnson & Johnson, we respect the diversity and dignity of our employees and recognize their merit.
Job Function:
Technology Enterprise Strategy & Security
Job Sub Function:
Enterprise Architecture
Job Category:
People Leader
All Job Posting Locations:
New Brunswick, New Jersey, United States of America, Palm Beach Gardens, Florida, United States of America, Raritan, New Jersey, United States of America, Warsaw, Indiana, United States of America, West Chester, Pennsylvania, United States of America
DePuy Synthes is recruiting for a Director, Business Information Security; this Hybrid position will be in Raynham, MA (USA). Alternate Hybrid locations may be considered at Raritan, NJ (USA), West Chester, PA (USA), Warsaw, IN (USA), Palm Beach Gardens, FL (USA).
Johnson & Johnson announced plans to separate our Orthopedics business toestablisha standalone orthopedics company,operatingas DePuy Synthes. The process of the planned separation isanticipatedto be completed within 18 to24 months, subject to legal requirements, including consultation with works councils and other employee representative bodies, as may berequired, regulatory approvals and other customary conditions and approvals. Should you accept this position, it isanticipatedthat, following conclusion of the transaction, you would be an employee of DePuySynthesand your employment would be governed by DePuy Synthes employment processes, programs, policies, and benefit plans. In that case, details of any planned changes would be provided to you by DePuy Synthes atan appropriate timeand subject to any necessary consultation processes.
The Director, Business Information Security serves as a strategic security leader and trusted advisor to the DePuy Synthes business, accountable for protecting information assets while enabling business growth and innovationand reports into the DePuy Synthes Technology organization This role shapes and executesbusiness‑alignedinformation security strategies, partners closely with senior leaders, and ensuresrisk‑based, compliant, and resilient security capabilities across commercial, R&D, manufacturing, and enabling functions. This is a highly visible role withdirectimpact on patient safety, product integrity, regulatory compliance, and enterprise trust.
Key Responsibilities:
Lead the development and execution of the business information security strategy aligned with DePuy Synthes objectives and enterprise security direction.
Act as the primary security partner to business leaders,providingrisk‑based guidance that enables innovation while protecting critical data and systems.
Identify, assess, and manage information security risks across business processes, products, and digital initiatives.
Oversee implementation and adoption of security controls, policies, and standards in alignment with enterprise frameworks and regulatory requirements.
Drive incident preparedness, response, and recovery in partnership with enterprise cyber and technology teams.
Influence secure‑by‑design practices across digital products, platforms, and third‑party engagements.
Lead cross‑functional collaboration with IT, Legal, Privacy, Quality, Regulatory, and Compliance teams to ensure holistic risk management.
Provide executive‑level reporting on security posture, risk trends, and remediation progress.
Guide, mentor, and provide matrix leadership to security professionals supporting the business.
Champion a strong security culture aligned with the Johnson & Johnson Credo and Leadership Imperatives.
Qualifications:
Education:
Bachelor’s degree in Information Security, Computer Science, Engineering, ora relatedfield(required)
Master’s degree in Information Security, Technology Management, Business Administration, ora relateddiscipline(preferred)
Experience and Skills
Required:
10–12 years of experience in information security, cybersecurity, or technology risk management, including leadership at the director or senior manager level.
Demonstrated experience aligning securitystrategywith complex business objectives in a regulated environment.
Strong understanding of security governance, risk management, and compliance frameworks.
Proven ability to influence senior stakeholders and translate technical risk into business impact.
Experience leading cross‑functional, matrixed teams and driving enterprise‑scale initiatives.
Excellent communication, executive presence, and decision‑making skills.
Preferred:
Experience supporting MedTech, healthcare, life sciences, or other highly regulated industries.
Hands‑on experience with product security, cloud security, and third‑party risk management.
Track recordof leading security transformation or maturity programs.
Experienceoperatingin global organizations with complex regulatory landscapes.
Demonstrated success building security culture and awareness programs.
Other:
Language: Englishrequired;additionallanguages are a plus.
Travel: Up to 20%, primarily domestic with occasional international travel.
Certifications (preferred): CISSP, CISM, CISA, or equivalent.
For more information on how we support the whole health of our employees throughout their wellness,careerand life journey, please visit www.careers.jnj.com
Johnson & Johnson is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, age, national origin, disability, protected veteran status or other characteristics protected by federal, state or local law. We actively seek qualified candidates who are protected veterans and individuals with disabilities as defined under VEVRAA and Section 503 of the Rehabilitation Act.
Johnson & Johnson is committed to providing an interview process that is inclusive of our applicants’ needs. If you are an individual with a disability and would like to request an accommodation, external applicants please contact us via https://www.jnj.com/contact-us/careers, internal employees contact AskGS to be directed to your accommodation resource.
#DePuySynthesCareers
#LI-Hybrid
Required Skills:
Preferred Skills:
Business Alignment, Collaborating, Continuous Improvement, Developing Others, Enterprise Application, Enterprise Application Integration (EAI), Enterprise IT Architecture, Enterprise IT Governance, Inclusive Leadership, Information Security Management System (ISMS), Information Security Risk Management, Information Technology Strategies, IT Asset Management Systems, Leadership, Performance Measurement, Process Improvements, Solution Architecture, Technologically Savvy
The anticipated base pay range for this position is :
$150,000.00 - $258,750.00
Additional Description for Pay Transparency:
Subject to the terms of their respective plans, employees are eligible to participate in the Company’s consolidated retirement plan (pension) and savings plan (401(k)).
This position is eligible to participate in the Company’s long-term incentive program.
Subject to the terms of their respective policies and date of hire, employees are eligible for the following time off benefits:
Vacation –120 hours per calendar year
Sick time - 40 hours per calendar year; for employees who reside in the State of Colorado –48 hours per calendar year; for employees who reside in the State of Washington –56 hours per calendar year
Holiday pay, including Floating Holidays –13 days per calendar year
Work, Personal and Family Time - up to 40 hours per calendar year
Parental Leave – 480 hours within one year of the birth/adoption/foster care of a child
Bereavement Leave – 240 hours for an immediate family member: 40 hours for an extended family member per calendar year
Caregiver Leave – 80 hours in a 52-week rolling period10 days
Volunteer Leave – 32 hours per calendar year
Military Spouse Time-Off – 80 hours per calendar year
For additional general information on Company benefits, please go to: - https://www.careers.jnj.com/employee-benefits

At Johnson & Johnson, we believe health is everything. As a focused healthcare company, with expertise in Innovative Medicine and MedTech, we’re empowered to tackle the world’s toughest health challenges, innovate through science and technology, and transform patient care.
All of this is possible because of our people. We’re passionate innovators who put people first, and through our purpose-driven culture and talented workforce, we are stronger than ever.
Learn more at https://www.jnj.com. Community Guidelines: http://www.jnj.com/social-media-community-guidelines