Director, Incident Response & Threat

Johnson & Johnson MedTech

Raynham (MA)

Hybrid

USD 150,000 - 259,000

Full time

15 hours ago
Be an early applicant
Application generator

Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Benefits offered by this job

Vacation –120 hours per calendar year
Sick time –40 hours per calendar year
Holiday pay –13 days per calendar year
Parental Leave – 480 hours within one年

Job summary

Johnson & Johnson MedTech is seeking a Director, Cyber Defense to lead the global incident response and threat management program. The role is hybrid with locations including Raynham, MA, and alternate hybrid sites.

You will own the incident response lifecycle, manage cross-functional teams, and report to the DePuy Synthes Technology organization. The position requires 10–12 years in cybersecurity leadership, experience with regulated environments, and strong executive communication.

Qualifications

  • 10-12 years of progressive cybersecurity or IT risk management experience with leadership.
  • Proven experience leading enterprise-scale incident response and threat management programs.
  • Experience in regulated environments (healthcare, life sciences, MedTech).
  • Excellent executive communication, judgment, and decision-making skills.

Responsibilities

  • Lead global incident response, digital forensics, defense engineering, and cyber threat intelligence capabilities.
  • Build an automation- and AI-first global Security Operations Center operating model.
  • Direct complex cybersecurity incident investigations with rapid containment and remediation.
  • Develop, test, and improve incident response playbooks, escalation paths, and crisis management procedures.
  • Partner with IT, Legal, Privacy, Quality, and Business leaders on cyber incidents and compliance.
  • Oversee threat intelligence to prioritize defensive actions and brief executives.

Skills

Cybersecurity leadership
Incident response
Threat intelligence
Executive communication
Regulated environments
Cross-functional leadership

Education

Bachelor’s degree in Computer Science, Information Security, Engineering, or a related field
Master’s degree in Cybersecurity, Information Systems, or Business Administration

Job description

At Johnson & Johnson,we believe health is everything. Our strength in healthcare innovation empowers us to build a world where complex diseases are prevented, treated, and cured,where treatments are smarter and less invasive, andsolutions are personal.Through our expertise in Innovative Medicine and MedTech, we are uniquely positioned to innovate across the full spectrum of healthcare solutions today to deliver the breakthroughs of tomorrow, and profoundly impact health for humanity.Learn more at jnj.com

As guided by Our Credo, Johnson & Johnson is responsible to our employees who work with us throughout the world. We provide an inclusive work environment where each person is considered as an individual. At Johnson & Johnson, we respect the diversity and dignity of our employees and recognize their merit.

Job Function

Technology Enterprise Strategy & Security

Job Sub Function

Security & Controls

Job Category

People Leader

All Job Posting Locations

Palm Beach Gardens, Florida, United States of America, Raritan, New Jersey, United States of America, Raynham, Massachusetts, United States of America, Warsaw, Indiana, United States of America, West Chester, Pennsylvania, United States of America

Job Description

DePuy Synthes is recruiting for a(n) Director, Incident Response & Threat; this Hybrid position will be in Raynham, MA (USA). Alternate Hybrid locations may be considered at Raritan, NJ (USA), West Chester, PA (USA), Warsaw, IN (USA), Palm Beach Gardens, FL (USA) OR Pune, India.

Please note that this role is available across multiple countries and may be posted under different requisition numbers to comply with local requirements. While you are welcome to apply to any or all of the postings, we recommend focusing on the specific country(s) that align with your preferred location(s):

Raynham, MA (USA) - Requisition Number: R-072535

Pune, India - Requisition Number: R-073281

Remember, whether you apply to one or all of these requisition numbers, your applications will be considered as a single submission.

Johnson & Johnson announced plans to separate our Orthopedics business to establish a standalone orthopedics company, operating as DePuy Synthes. The process of the planned separation is anticipated to be completed within 18 to 24 months, subject to legal requirements, including consultation with works councils and other employee representative bodies, as may be required, regulatory approvals and other customary conditions and approvals. Should you accept this position, it is anticipated that, following conclusion of the transaction, you would be an employee of DePuy Synthes and your employment would be governed by DePuy Synthes employment processes, programs, policies, and benefit plans. In that case, details of any planned changes would be provided to you by DePuy Synthes at an appropriate time and subject to any necessary consultation processes.

Job Overview

The Director, Cyber Defense is a senior cybersecurity leadership role responsible for protecting DePuy Synthes’ digital environment, products, and operations from cyber threats. This leader will own the global incident response program and threat management strategy, ensuring rapid detection, containment, and remediation of security incidents. The role plays a critical part in safeguarding patient trust, business continuity, and regulatory compliance while shaping a resilient and forward‑looking security posture across the organization, and reports into the DePuy Synthes Technology organization.

Key Responsibilities
  • Lead the global incident response, digital forensics, defense engineering, and cyber threat intelligence capabilities, with accountability for preparedness, detection, containment, response, recovery, and continuous improvement.
  • Build and mature an automation- and AI-first global Security Operations Center operating model that integrates an MSSP, retained services, and an internal team spanning eDiscovery, investigations, threat intelligence, incident response, and defense engineering.
  • Direct complex cybersecurity incident investigations, ensuring rapid containment, preservation of forensic evidence, rigorous root‑cause analysis, coordinated remediation, and timely executive and post‑incident reporting.
  • Develop, automate, test, and continuously improve incident response playbooks, escalation paths, communications protocols, and crisis management procedures to enable consistent, timely, and coordinated action during cyber events.
  • Partner with IT, Legal, Privacy, Quality, and Business leaders to manage cyber incidents and regulatory or compliance obligations.
  • Oversee threat intelligence capabilities that identify and assess emerging threats and vulnerabilities relevant to the MedTech environment, translate intelligence into prioritized defensive actions, and deliver concise executive briefings on business implications and recommended responses.
  • Lead tabletop exercises, simulations, and readiness assessments across technology and business functions; translate lessons learned into prioritized remediation plans that measurably improve response maturity.
  • Establish and maintain an executive‑ready metrics framework - including mean time to acknowledge (MTTA), respond (MTTR), and contain (MTTC) - to demonstrate operational effectiveness, expose performance gaps, enforce accountability, and drive measurable improvements in cyber resilience.
  • Provide executive‑level reporting and actionable recommendations on cyber risk, incident trends, defensive readiness, investment priorities, and remediation progress to support timely, risk‑informed decisions.
  • Enhance relationship with the business by promoting awareness, insights and opportunities to improve the company’s risk position
  • Lead proactive research to identify relevant threats, develop and perform threat hunts based on that research
  • Lead, mentor, and develop a high‑performing incident response and threat management team.
  • Drive continuous improvement of tools, processes, and technologies supporting security operations and resilience.
Qualifications
Education
  • Bachelor’s degree in Computer Science, Information Security, Engineering, or a related field (required).
  • Master’s degree in Cybersecurity, Information Systems, or Business Administration (preferred).
Required
  • 10-12 years of progressive experience in cybersecurity, information security, or IT risk management, including leadership roles.
  • Proven experience leading enterprise‑scale incident response and threat management programs.
  • Strong knowledge of cyber threat landscapes, attack techniques, and defensive strategies.
  • Experience working in regulated environments (e.g., healthcare, life sciences, MedTech, or similarly regulated industries).
  • Demonstrated ability to lead cross‑functional teams during high‑pressure incidents.
  • Excellent executive communication, judgment, and decision‑making skills.
Experience and Skills
Preferred
  • Experience supporting global organizations with complex technology environments.
  • Familiarity with security frameworks such as NIST, ISO 27001, or similar standards.
  • Experience integrating threat intelligence into security operations and risk management.
  • Prior people leadership experience managing managers or senior individual contributors.
  • Experience with cloud, OT, and medical device security considerations.
Other
  • Language: English (fluent).
  • Travel: Up to 10–15%, primarily domestic with occasional international travel.
  • Certifications (preferred): CISSP, CISM, GIAC, or equivalent cybersecurity certifications.

For more information on how we support the whole health of our employees throughout their wellness, career and life journey, please visit www.careers.jnj.com.

Johnson & Johnson is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, age, national origin, disability, protected veteran status or other characteristics protected by federal, state or local law. We actively seek qualified candidates who are protected veterans and individuals with disabilities as defined under VEVRAA and Section 503 of the Rehabilitation Act.

Johnson & Johnson is committed to providing an interview process that is inclusive of our applicants’ needs. If you are an individual with a disability and would like to request an accommodation, external applicants please contact us via https://www.jnj.com/contact-us/careers, internal employees contact AskGS to be directed to your accommodation resource.

#DePuySynthesCareers

The anticipated base pay range for this position is :

$150,000.00 - $258,750.00

Additional Description For Pay Transparency

Subject to the terms of their respective plans, employees are eligible to participate in the Company’s consolidated retirement plan (pension) and savings plan (401(k)).

This position is eligible to participate in the Company’s long‑term incentive program.

Benefits
  • Vacation –120 hours per calendar year
  • Sick time - 40 hours per calendar year; for employees who reside in the State of Colorado –48 hours per calendar year; for employees who reside in the State of Washington –56 hours per calendar year
  • Holiday pay, including Floating Holidays –13 days per calendar year
  • Work, Personal and Family Time - up to 40 hours per calendar year
  • Parental Leave – 480 hours within one year of the birth/adoption/foster care of a child
  • Bereavement Leave – 240 hours for an immediate family member: 40 hours for an extended family member per calendar year
  • Caregiver Leave – 80 hours in a 52‑week rolling period10 days
  • Volunteer Leave – 32 hours per calendar year
  • Military Spouse Time‑Off – 80 hours per calendar year

Additional information can be found through the link below.

Co‑Ops and Intern Positions: Please use the following language:

Co‑Ops/Interns are eligible to participate in Company sponsored employee medical benefits in accordance with the terms of the plan.

Co‑Ops and Interns are eligible for the following sick time benefits: up to 40 hours per calendar year; for employees who reside in the State of Washington, up to 56 hours per calendar year.

Co‑Ops and Interns are eligible to participate in the Company’s consolidated retirement plan (pension).

Positions Represented by CBA: Please use the following language:

This position is eligible for benefits to include medical, dental, vision and time off, as well as any others as provided for in the applicable Collective Bargaining Agreement.

The following link to general company benefits information MUST also be included in the posting: Please use the following language:

For additional general information on Company benefits, please go to: - https://www.careers.jnj.com/employee-benefits

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Director, Incident Response & Threat
Director, Incident Response & Threat

Johnson & Johnson MedTech • West Chester

Hybrid
USD 150,000 - 259,000
Vacation – 120 hours/year
Sick time – 40 hours/year
Holiday pay – 13 days/year
+2
Director, Incident Response & Threat
Director, Incident Response & Threat

Johnson & Johnson MedTech • Town of Florida (NY)

Hybrid
USD 150,000 - 259,000
Vacation –120 hours per year
Parental Leave
Sick time – 40 hours/year (Colorado/Wa
+2
Technology Manager, Quality Systems, BA
Technology Manager, Quality Systems, BA

Antler • Raynham (MA)

On-site
USD 102,000 - 204,000
Domestic travel
Professional, Tech Prod IT Sales
Professional, Tech Prod IT Sales

Antler • Town of Florida (NY)

On-site
USD 113,000 - 152,000
Professional, Tech Prod IT Sales
Professional, Tech Prod IT Sales

Antler • Raynham (MA)

On-site
USD 112,000 - 152,000
Sr. Director, Global Benefits COE - Orthopedics
Sr. Director, Global Benefits COE - Orthopedics

Antler • Town of Florida (NY)

On-site
USD 178,000 - 307,000
Vacation time
Sick time
Holiday pay
+1
Professional, Prog Lead, PenTesting Svcs
Professional, Prog Lead, PenTesting Svcs

Johnson & Johnson MedTech • Warsaw (IN)

On-site
USD 94,000 - 170,000
Professional, Tech Prod IT Sales
Professional, Tech Prod IT Sales

Antler • West Chester

On-site
USD 119,000 - 145,000
Professional, Tech Prod IT Sales
Professional, Tech Prod IT Sales

Antler • Warsaw (IN)

On-site
USD 112,000 - 152,000
Professional, Quality Steward
Professional, Quality Steward

6090-Johnson & Johnson Services Inc. Legal Entity • New Brunswick (NJ)

On-site
USD 79,000 - 142,000
Vacation time
Parental Leave
Volunteer Leave