
At Johnson & Johnson, we believe health is everything. Our strength in healthcare innovation empowers us to build a world where complex diseases are prevented, treated, and cured, where treatments are smarter and less invasive, and solutions are personal. Through our expertise in Innovative Medicine and MedTech, we are uniquely positioned to innovate across the full spectrum of healthcare solutions today to deliver the breakthroughs of tomorrow, and profoundly impact health for humanity. Learn more at jnj.com
As guided by Our Credo, Johnson & Johnson is responsible to our employees who work with us throughout the world. We provide an inclusive work environment where each person is considered as an individual. At Johnson & Johnson, we respect the diversity and dignity of our employees and recognize their merit.
Job Function:
Legal & Compliance
Job Sub Function:
Law Business Partners
Job Category:
People Leader
All Job Posting Locations:
New Brunswick, New Jersey, United States of America, Raritan, New Jersey, United States of America, Titusville, New Jersey, United States of America
Johnson & Johnson is transforming healthcare with technology, data, and AI. Across the enterprise, we are scaling AI, modernizing digital platforms, advancing connected healthcare technologies, strengthening cybersecurity capabilities, and investing in the data and technology foundations that support Research & Development, Technical Operations, Commercial, and Corporate Functions.
To support this transformation, the Global Legal Organization (GLO) is establishing a dedicated Technology Advisory Legal team. This newly created team will partner directly with Enterprise Technology leaders to help shape the legal frameworks that enable innovation while managing cybersecurity, data, AI, and technology risk.
As the Senior Legal Director, Cyber & Data Risk, you will serve as the principal legal advisor to the Chief Information Security Officer (CISO) and Information Security & Risk Management (ISRM) organization, along with the broader enterprise technology leaders. As a member of the ISRM Leadership Team, you will advise on the organization's most complex cybersecurity, technology, and data risk legal matters while helping define how legal supports enterprise technology at global scale.
The responsibilities of the Senior Director, Cyber, Data Risk, & Privacy are:
Strategic Advisor to the CISO
Serve as the principal legal advisor to the Chief Information Security Officer (CISO) and Information Security & Risk Management (ISRM) Leadership Team, providing strategic counsel on cybersecurity, enterprise technology risk, data risk, and complex legal matters requiring significant judgment.
Advise executive leadership on legal implications of strategic business decisions, emerging risks, and evolving regulatory requirements affecting the organization's cybersecurity strategy.
Technology Strategy & Business Partnership
Partner with the CISO, ISRM Leadership Team, and Enterprise Technology leaders to embed legal guidance into strategic technology initiatives and operational decision making.
Advise on the cyber and data risk implications of emerging technologies, including AI, cloud, enterprise platforms, and evolving digital capabilities, enabling informed business decisions.
Provide practical, risk based legal counsel that enables innovation while balancing cybersecurity, regulatory, and business objectives.
Develop governance frameworks, policies, and controls that align with global legal and regulatory requirements, with a particular focus on cybersecurity considerations related to AI.
Interpret evolving cybersecurity, AI, critical infrastructure, and technology regulations, translating legal requirements into practical business guidance.
Partner with Government Affairs, Privacy, and other stakeholders to monitor and assess emerging legal and regulatory developments affecting cybersecurity and enterprise technology.
Cyber Incident Response & Enterprise Risk
Lead legal support for significant cybersecurity incidents, vulnerabilities, crisis response activities, and related regulatory matters.
Advise on cyber related communications, SEC and other regulatory disclosure obligations, and interactions with law enforcement and government authorities.
Counsel the business on enterprise asset protection, insider risk, intellectual property misappropriation, employee data theft, and related investigations in partnership with Litigation, Employment Law, Privacy, and Corporate Security.
Data Risk & Information Protection
Advise on legal risks associated with enterprise data protection, information governance, cross border data flows, and cyber related data risk.
Partner with ISRM, Privacy and “High-Risk Country” teams to align cybersecurity practices with global data protection, privacy, and ethical standards.
Provide legal guidance on enterprise data governance and information protection strategies that support secure business operations.
Technology Cyber Agreements
Advise on cybersecurity and product security provisions in strategic technology agreements.
Counsel Enterprise Technology on cybersecurity legal risks associated with mergers, acquisitions, divestitures, strategic partnerships, technology sourcing, and other enterprise technology initiatives.
Manage outside counsel supporting specialized cybersecurity legal matters, as appropriate.
Enterprise Legal Leadership
Collaborate with senior and peer legal leaders across the Technology Advisory Legal team to deliver coordinated legal advice on matters spanning cybersecurity, AI, cloud, enterprise platforms, technology transactions, and data.
Lead and develop a team of cybersecurity legal professionals while fostering collaboration across Legal, Enterprise Technology, Privacy, and other business functions.
Help shape the continued evolution of the Technology Advisory Legal team by developing legal capabilities, governance approaches, and best practices that support the company's technology strategy.
Qualifications
A Juris Doctor (JD) degree is required.
Admission to practice law and good standing in at least one United States jurisdiction is required.
Minimum of 12 years of relevant legal experience, including significant experience advising on cybersecurity legal matters.
Demonstrated experience serving as a trusted legal advisor to senior executives on complex, business critical cybersecurity issues.
Experience leading legal support during significant cybersecurity incidents, investigations, regulatory inquiries, or crisis situations.
Deep knowledge of global cybersecurity legal and regulatory frameworks, including data protection, critical infrastructure, technology regulation, and AI governance.
Experience drafting and negotiating cybersecurity, technology, and product security contractual provisions.
Experience advising on cybersecurity legal risks associated with mergers, acquisitions, divestitures, and strategic technology initiatives.
Proven ability to shape enterprise governance programs and influence decision making within complex global matrix organizations.
Strong leadership and people management experience, with a passion for developing high performing legal teams.
Excellent executive communication, collaboration, and stakeholder management skills, with the ability to influence senior leaders across Legal, Enterprise Technology, and the business.
Demonstrated digital fluency and a learning approach to new technology.
Law firm experience supporting cybersecurity investigations, enforcement actions, or regulatory matters is preferred.
In-house experience supporting a global organization is preferred.
Ability to travel, approximately 10%.
Johnson & Johnson is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, age, national origin, disability, protected veteran status or other characteristics protected by federal, state or local law. We actively seek qualified candidates who are protected veterans and individuals with disabilities as defined under VEVRAA and Section 503 of the Rehabilitation Act.
Johnson and Johnson is committed to providing an interview process that is inclusive of our applicants’ needs. If you are an individual with a disability and would like to request an accommodation, please email the Employee Health Support Center (ra-employeehealthsup@its.jnj.com) or contact AskGS to be directed to your accommodation resource.
Required Skills:
Preferred Skills:
Budget Management, Business Agility, Commercial Laws, Compliance Management, Corporate Governance, Developing Others, Dispute Resolution, Inclusive Leadership, Lawyering, Leadership, Legal Documents Preparation, Legal Services, Negotiation, Representing, Risk Management, Strategic Thinking, Vendor Management
The anticipated base pay range for this position is :
$178,000.00 - $307,050.00
Additional Description for Pay Transparency:
Subject to the terms of their respective plans, employees are eligible to participate in the Company’s consolidated retirement plan (pension) and savings plan (401(k)).
For additional general information on Company benefits, please go to: - https://www.careers.jnj.com/employee-benefits
This position is eligible to participate in the Company’s long-term incentive program.
Subject to the terms of their respective policies and date of hire, employees are eligible for the following time off benefits:
Vacation –120 hours per calendar year
Sick time - 40 hours per calendar year; for employees who reside in the State of Colorado –48 hours per calendar year; for employees who reside in the State of Washington –56 hours per calendar year
Holiday pay, including Floating Holidays –13 days per calendar year
Work, Personal and Family Time - up to 40 hours per calendar year
Parental Leave – 480 hours within one year of the birth/adoption/foster care of a child
Bereavement Leave – 240 hours for an immediate family member: 40 hours for an extended family member per calendar year
Caregiver Leave – 80 hours in a 52-week rolling period10 days
Volunteer Leave – 32 hours per calendar year
Military Spouse Time-Off – 80 hours per calendar year

At Johnson & Johnson, we believe health is everything. As a focused healthcare company, with expertise in Innovative Medicine and MedTech, we’re empowered to tackle the world’s toughest health challenges, innovate through science and technology, and transform patient care.
All of this is possible because of our people. We’re passionate innovators who put people first, and through our purpose-driven culture and talented workforce, we are stronger than ever.
Learn more at https://www.jnj.com. Community Guidelines: http://www.jnj.com/social-media-community-guidelines