Data Security Manager - Information Security & Risk Management

Johnson & Johnson

Raritan (NJ)

On-site

USD 117,000 - 201,000

Full time

2 days ago
Be an early applicant
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Job summary

Johnson & Johnson is recruiting a Data Security Manager - Information Security & Risk Management (ISRM). This position may be based in JNJ office in Raritan, NJ or remote in the U.S.

with the capability to periodically travel into the Raritan, NJ office. Lead the enterprise Data Protection Program, governance, metrics, reporting, and continuous improvement; own exception management including USB, webmail, and secure data transfer; assess requests, coordinate risk reviews, remediation actions,

Qualifications

  • BA/BS degree or equivalent required; graduate degree preferred.
  • Minimum 6 years in IT Security management or IT roles.
  • At least 2 years experience in data security (governance, data labeling, etc.).
  • Advanced knowledge of information security processes and business value.
  • Experience assessing security threats and working with vendors/technologies.
  • Proven ability to partner with IT and business partners.
  • Excellent communication and collaboration skills; able to influence.

Responsibilities

  • Lead the enterprise Data Protection Program with governance, processes, metrics, reporting, and continuous improvement.
  • Own Data Protection exception management including USB, webmail, file-sharing and Secure Data Transfer.
  • Assess exception requests, coordinate risk reviews, remediation actions, and lifecycle management.
  • Reduce exception volume through secure alternatives, controls, education, process optimization, and automation.
  • Partner with ISRM, Compliance, Privacy, Legal, HR, and business partners to design and implement risk-based data protection controls.
  • Develop and implement data security strategies and govern critical information assets.

Skills

Data Security
Governance
Risk Management
Security Architecture
Communication
Leadership
Collaboration

Education

BA/BS degree or equivalent
Graduate degree preferred

Tools

Data protection tools
USB controls
Secure Data Transfer

Job description

At Johnson & Johnson,we believe health is everything. Our strength in healthcare innovation empowers us to build aworld where complex diseases are prevented, treated, and cured,where treatments are smarter and less invasive, andsolutions are personal.Through our expertise in Innovative Medicine and MedTech, we are uniquely positioned to innovate across the full spectrum of healthcare solutions today to deliver the breakthroughs of tomorrow, and profoundly impact health for humanity.Learn more at jnj.com

As guided by Our Credo, Johnson & Johnson is responsible to our employees who work with us throughout the world. We provide an inclusive work environment where each person is considered as an individual. At Johnson & Johnson, we respect the diversity and dignity of our employees and recognize their merit.

Job Function

Technology Enterprise Strategy & Security

Job Sub Function

Multi-Family Technology Enterprise Strategy & Security

Job Category

People Leader

All Job Posting Locations

Raritan, New Jersey, United States of America

Job Description

Johnson and Johnson is recruiting a Data Security Manager - Information Security & Risk Management (ISRM). This position may be based in J&J office in Raritan, NJ or remote in the U.S. with the capability to periodically travel into the Raritan, NJ office.

Key Responsibilities
  • Lead the enterprise Data Protection Program, including governance, operating processes, service oversight, metrics, reporting, and continuous improvement.
  • Own Data Protection exception management processes, including USB, webmail, file-sharing, Trusted Computing, Secure Data Transfer and other approved service exceptions.
  • Assess exception requests and coordinate risk reviews, approvals, remediation actions, and lifecycle management.
  • Reduce exception volume through secure alternatives, enhanced controls, user education, process optimization, and automation.
  • Partner with EUS, ISRM teams, Compliance, Privacy, Legal, HR, and business partners to design and implement risk-based data protection controls.
  • Define, monitor, and report program performance metrics, exception trends, risk themes, and executive-level insights.
  • Maintain data protection policies, standards, procedures, governance documentation, and accountability frameworks.
  • Develop and implement data security strategies to safeguard critical information assets and support enterprise data governance initiatives.
  • Lead initiatives to identify, classify, inventory, and protect critical information assets.
  • Conduct assessments of data security controls, processes, and capabilities to identify gaps, risks, and improvement opportunities.
  • Serve as a domain authority on emerging data security threats, technologies, and standard processes, providing recommendations for proactive risk mitigation.
  • Lead data security awareness, communications, change control, and training programs to drive adoption of security capabilities.
  • Support the implementation of new data security capabilities and collaborate across J&J teams to deliver a coordinated approach to data protection.
Qualifications
Education:
  • A BA/BS degree or equivalent is required for this position. Graduate degree or equivalent experience preferred.
Required
Experience and Skills:
  • A minimum of 6 years of dynamic experience in roles within IT Security management and/or IT is preferred.
  • A minimum of 2 years experience in one of more aspects of data security (governance, deployment of data security measures, data labeling, etc.).
  • Advanced knowledge of information security processes and principles is preferred in explaining the business value of cybersecurity.
  • Experience in assessing current security threats, mitigation measures and security vendors/technologies is required.
  • Previous experience developing effective and strong partnerships along with relationship building skills with IT and business partners is required.
  • Results Orientation – ability to aim to timelines is required.
  • Superb communication and collaboration skills, able to network and influence at all levels of the organization, cross sector, multi-functionally and globally is required.
  • Demonstrable ability to influence/collaborate to get the desired result is required.
Preferred
  • Certifications in cybersecurity (CISM, CISSP), audit (CISA), risk management (CRISC) or Data Security related are preferred.
  • Formal training and experience in developing or supporting a large-scale Data Security program is preferred.
  • Experience in performing Data Security and/or Data Protection project is preferred.
Preferred Skills:
  • Crisis Management
  • Cybersecurity Assessment
  • Developing Others
  • Enterprise Application Integration (EAI)
  • Enterprise IT Governance
  • Global Market
  • Inclusive Leadership
  • Information Security Management System (ISMS)
  • Information Security Risk Management
  • Information Security Strategic Roadmaps
  • Information Technology Strategies
  • Interpersonal Influence
  • Leadership
  • Resource Allocation
  • Security Administration
  • Security Architecture Design
  • Security Monitoring
  • Team Management
The anticipated base pay range for this position is :

The anticipated base pay range for this position is: $117,000- $201,250

Additional Description For Pay Transparency

Subject to the terms of their respective plans, employees and/or eligible dependents are eligible to participate in the following Company sponsored employee benefit programs: medical, dental, vision, life insurance, short- and long-term disability, business accident insurance, and group legal insurance. Subject to the terms of their respective plans, employees are eligible to participate in the Company’s consolidated retirement plan (pension) and savings plan (401(k)). Subject to the terms of their respective policies and date of hire, Employees are eligible for the following time off benefits: Vacation –120 hours per calendar year Sick time - 40 hours per calendar year; for employees who reside in the State of Washington –56 hours per calendar year Holiday pay, including Floating Holidays –13 days per calendar year Work, Personal and Family Time - up to 40 hours per calendar year Parental Leave – 480 hours within one year of the birth/adoption/foster care of a child Condolence Leave – 30 days for an immediate family member: 5 days for an extended family member Caregiver Leave – 10 days Volunteer Leave – 4 days Military Spouse Time-Off – 80 hours Additional information can be found through the link below. https://www.careers.jnj.com/employee-benefits

#JNJTECH

Johnson & Johnson is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, age, national origin, disability, protected veteran status or other characteristics protected by federal, state or local law. We actively seek qualified candidates who are protected veterans and individuals with disabilities as defined under VEVRAA and Section 503 of the Rehabilitation Act.

Johnson & Johnson is committed to providing an interview process that is inclusive of our applicants’ needs. If you are an individual with a disability and would like to request an accommodation, please contact us via https://www.jnj.com/contact-us/careers or contact AskGS to be directed to your accommodation resource.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Data Security Manager - Information Security & Risk Management
Data Security Manager - Information Security & Risk Management

Biopharma Careers • Raritan (NJ)

Hybrid
USD 117,000 - 201,000
Data Security Manager - Information Security & Risk Management
Data Security Manager - Information Security & Risk Management

Johnson & Johnson Innovative Medicine • Raritan (NJ)

Hybrid
USD 117,000 - 201,000
Senior Legal Director, Cyber & Data Risk
Senior Legal Director, Cyber & Data Risk

Johnson & Johnson • Washington

On-site
USD 178,000 - 307,000
Vacation – 120 hours per year
Sick time – 40 hours per year
Holiday pay – 13 days per year
+2
Senior Manager, Commercial Data & Insights
Senior Manager, Commercial Data & Insights

Biopharma Careers • Raritan (NJ)

On-site
USD 122,000 - 211,000
Manager, HR Data & Integrations
Manager, HR Data & Integrations

Biopharma Careers • New Brunswick (NJ)

On-site
USD 138,000 - 168,000
Employee benefits package
Senior Legal Director, Cyber & Data Risk
Senior Legal Director, Cyber & Data Risk

Johnson & Johnson • New Brunswick (NJ)

On-site
USD 178,000 - 307,000
Vacation 120 hours/year
Sick time 40 hours/year
Holiday pay 13 days/year
+2
Senior Manager, Commercial Data & Insights
Senior Manager, Commercial Data & Insights

Johnson & Johnson Innovative Medicine • Raritan (NJ)

On-site
USD 122,000 - 211,000
Principal Product Security Engineer
Principal Product Security Engineer

Johnson & Johnson • Santa Clara (CA)

On-site
USD 118,000 - 204,000
Vacation hours
Parental Leave
Holiday pay
Senior Legal Director, Cyber & Data Risk
Senior Legal Director, Cyber & Data Risk

Johnson & Johnson • Titusville (NJ)

On-site
USD 178,000 - 307,000
Vacation time
Sick time
Parental Leave
Lead Product Security Engineer
Lead Product Security Engineer

Johnson & Johnson Innovative Medicine • Danvers (MA)

Hybrid
USD 94,000 - 152,000