A complete application in a minute — tailored resume and cover letter, ready to send.
Johnson & Johnson seeks a Professional, Compliance Lead in Cybersecurity GRC to own policy and standards, drive risk assessments, and deliver executive risk reporting from New Jersey and other U.S. locations.
You will lead third-party risk programs, coordinate with Internal Audit and regulators, and shape risk-aware culture across the enterprise. Requires 6+ years in GRC and certifications such as CISSP/CRISC/CISM/CISA.
Technology Enterprise Strategy & Security
Security & Controls
Scientific/Technology
New Brunswick, New Jersey, United States of America
At Johnson & Johnson,we believe health is everything. Our strength in healthcare innovation empowers us to build aworld where complex diseases are prevented, treated, and cured,where treatments are smarter and less invasive, andsolutions are personal.Through our expertise in Innovative Medicine and MedTech, we are uniquely positioned to innovate across the full spectrum of healthcare solutions today to deliver the breakthroughs of tomorrow, and profoundly impact health for humanity.Learn more at jnj.com. As guided by Our Credo, Johnson & Johnson is responsible to our employees who work with us throughout the world. We provide an inclusive work environment where each person is considered as an individual. At Johnson & Johnson, we respect the diversity and dignity of our employees and recognize their merit.
DePuy Synthes is recruiting for a Professional, Compliance Lead, located in Raritan, New Jersey or West Chester, Pennsylvania or Palm Beach Gardens, Florida or Raynham, Massachusetts or Warsaw, Indiana. Join our change journey at J&J—help shape what’s next Step into a high-impact career opportunity with real visibility THE OPPORTUNITY The Professional, Compliance Lead is a seasoned individual contributor within the Cybersecurity function, GRC, IT Controls & Cyber Culture sub-function, accountable for leading the cybersecurity compliance and governance agenda across DePuy Synthes. This role owns the policy and standards framework, sets the enterprise cyber risk methodology, leads risk assessments and register governance, and drives the reporting cadence that informs executive and Board-level decision-making. The Compliance Lead directs third-party risk oversight, defines the metrics and KRI model that measures program health, and serves as the primary liaison to Internal Audit, Legal, Privacy, Quality, and external regulators. Applying advanced knowledge of GRC frameworks and regulatory obligations, this role establishes best-in-class policies, procedures, and plans for the area.
Required: 6 years of progressive experience in cybersecurity governance, IT risk management, technology compliance, or a related GRC discipline.
Demonstrated ownership of a security policy and standards framework, including authorship, governance lifecycle, exception management, and stakeholder approval.
Advanced working knowledge of NIST CSF, NIST 800-53, ISO 27001/27002, and COBIT, with the ability to rationalize requirements across multiple frameworks.
Proven experience designing and operating a cyber risk assessment methodology and enterprise risk register at scale.
Experience defining KRIs and building executive-level risk reporting that drives leadership decisions.
Experience leading third-party/vendor cyber risk programs, including assessment standards, SOC 2 / ISO evidence review, and contractual security requirements.
Strong facilitation and influencing skills, with a track record of driving accountability across senior stakeholders without direct authority.
Johnson & Johnson announced plans to separate our Orthopedics business to establish a standalone orthopedics company, operating as DePuy Synthes. The process of the planned separation is anticipated to be completed within 18 to 24 months, subject to legal requirements, including consultation with works councils and other employee representative bodies, as may be required, regulatory approvals and other customary conditions and approvals. Should you accept this position, it is anticipated that, following conclusion of the transaction, you would be an employee of DePuy Synthes and your employment would be governed by DePuy Synthes employment processes, programs, policies, and benefit plans. In that case, details of any planned changes would be provided to you by DePuy Synthes at an appropriate time and subject to any necessary consultation processes.
Johnson & Johnson is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, age, national origin, disability, protected veteran status or other characteristics protected by federal, state or local law. We actively seek qualified candidates who are protected veterans and individuals with disabilities as defined under VEVRAA and Section 503 of the Rehabilitation Act. Johnson & Johnson is committed to providing an interview process that is inclusive of our applicants’ needs. If you are an individual with a disability and would like to request an accommodation, external applicants please contact us via https://www.jnj.com/contact-us/careers, internal employees contact AskGS to be directed to your accommodation resource.
At Johnson & Johnson,we believe health is everything. Our strength in healthcare innovation empowers us to build aworld where complex diseases are prevented, treated, and cured,where treatments are smarter and less invasive, andsolutions are personal.Through our expertise in Innovative Medicine and MedTech, we are uniquely positioned to innovate across the full spectrum of healthcare solutions today to deliver the breakthroughs of tomorrow, and profoundly impact health for humanity.Learn more at https://www.jnj.com/.
Do Not Sell or Share My Personal Information Limit the Use of My Personal Information