Professional, Compliance Lead

Johnson Johnson

New Brunswick (NJ)

On-site

USD 120,000 - 180,000

Full time

2 days ago
Be an early applicant
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Job summary

Johnson & Johnson is seeking a seasoned Professional, Compliance Lead in Cybersecurity to drive governance, risk, and regulatory compliance across DePuy Synthes. You will own policy frameworks, risk assessments, and executive reporting, interfacing with Internal Audit, Legal, Privacy, and regulators.

The role demands navigating complex standards and improving cyber risk maturity. Location flexibility includes multiple U.S.

Qualifications

  • 6 years of progressive experience in cybersecurity
  • Experience leading governance, risk, and compliance initiatives
  • Strong knowledge of regulatory obligations and industry frameworks

Responsibilities

  • Lead cybersecurity policy and standards program end to end
  • Define enterprise cyber risk framework and scoring model
  • Direct cyber risk assessment across apps, infra, and processes
  • Govern cyber risk register and escalation to leadership
  • Coordinate governance forums and executive reporting
  • Partner with audit, legal, privacy, and QA teams to align controls

Skills

Cybersecurity
GRC
Risk assessment
Policy development
Regulatory compliance
Stakeholder management

Tools

NIST CSF
ISO 27001
HIPAA
GDPR
FDA cybersecurity guidance
SOX ITGC

Job description

At Johnson & Johnson, we believe health is everything. Our strength in healthcare innovation empowers us to build a world where complex diseases are prevented, treated, and cured, where treatments are smarter and less invasive, and solutions are personal. Through our expertise in Innovative Medicine and MedTech, we are uniquely positioned to innovate across the full spectrum of healthcare solutions today to deliver the breakthroughs of tomorrow, and profoundly impact health for humanity. Learn more at jnj.com .

As guided by Our Credo, Johnson & Johnson is responsible to our employees who work with us throughout the world. We provide an inclusive work environment where each person is considered as an individual. At Johnson & Johnson, we respect the diversity and dignity of our employees and recognize their merit.

Job Function

Technology Enterprise Strategy & Security

Job Sub Function

Security & Controls

Job Category

Scientific/Technology

All Job Posting Locations

New Brunswick, New Jersey, United States of America

Job Description

DePuy Synthes is recruiting for a Professional, Compliance Lead , located in Raritan, New Jersey or West Chester, Pennsylvania or Palm Beach Gardens, Florida or Raynham, Massachusetts or Warsaw, Indiana.

Join our change journey at J&J-help shape what's next Step into a high-impact career opportunity with real visibilit y

THE OPPORTUNITY

The Professional , Compliance Lead is a seasoned individual contributor within the Cybersecurity function, GRC, IT Controls & Cyber Culture sub-function, accountable for leading the cybersecurity compliance and governance agenda across DePuy Synthes. This role owns the policy and standards framework, sets the enterprise cyber risk methodology , leads risk assessments and register governance, and drives the reporting cadence that informs executive and Board-level decision-making. The Compliance Lead directs third-party risk oversight, defines the metrics and KRI model that measures program health, and serves as the primary liaison to Internal Audit, Legal, Privacy, Quality, and external regulators. Applying advanced knowledge of GRC frameworks and regulatory obligations, this role establishes best-in-class policies, procedures, and plans for the area.

RESPONSIBILITIES
  • Lead the cybersecurity policy and standards program end to end - setting the governance lifecycle, approving content, driving annual review and attestation, and adjudicating exceptions and risk acceptances.
  • Define and maintain the enterprise cyber risk framework and methodology , including risk taxonomy, scoring model, risk appetite and tolerance statements, and escalation thresholds.
  • Direct the cyber risk assessment program across applications, infrastructure, business processes, and major change initiatives; ensure consistency of method, quality of output, and traceability of results.
  • Own governance of the enterprise cyber risk register - enforcing data quality, ownership accountability, aging discipline, and timely escalation of elevated or overdue risks to leadership.
  • Chair and orchestrate cybersecurity governance forums, setting agendas, framing decisions, documenting outcomes, and holding owners accountable for committed actions.
  • Build and deliver the executive reporting model - translating aggregated risk, control, and compliance data into concise business-impact narratives for CIO, CISO, and senior leadership audiences.
  • Define, baseline, and operationalize cyber risk metrics and Key Risk Indicators (KRIs), establishing thresholds, trend analysis, and predictive signals that drive proactive intervention.
  • Lead third-party cyber risk oversight - setting the vendor tiering model, assessment standards, contractual security requirements, and continuous monitoring approach for critical aand high-risk suppliers.
  • Maintain the regulatory and framework mapping library (NIST CSF, ISO 27001, HIPAA, GDPR, FDA cybersecurity guidance, SOX ITGC), rationalizing overlapping requirements to reduce duplicate control effort.
  • Partner with the IT Controls and SOX teams to align governance requirements with control design and testing, ensuring a coherent and non-duplicative assurance landscape.
  • Serve as the primary point of contact for Internal Audit, external auditors, regulators, and customer security assessments - coordinating evidence, responses, and issue remediation.
  • Assess and govern the compliance impact of major technology change , including cloud migrations, ERP and platform implementations, and separation/carve-out activity, defining requirements prior to go-live.
  • Drive the cyber culture and awareness agenda - shaping policy communications, training strategy, and targeted enablement to strengthen accountability and risk-aware behavior enterprise-wide.
  • Identify and lead automation opportunities across GRC workflows, evidence collection, and reporting to improve efficiency, data integrity, and program scalability.
ABOUT YOU:

Required: 6 years of progressive experience in cybersecu

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Professional, Compliance Lead
Professional, Compliance Lead

Johnson & Johnson Co. • New Brunswick (NJ)

On-site
USD 140,000 - 180,000
Professional, Compliance Lead
Professional, Compliance Lead

Antler Co • New Brunswick (NJ)

On-site
USD 140,000 - 190,000
Professional, Compliance Lead
Professional, Compliance Lead

Johnson & Johnson MedTech • New Brunswick (NJ)

On-site
USD 140,000 - 190,000
Professional, Compliance Lead
Professional, Compliance Lead

6090-Johnson & Johnson Services Inc. Legal Entity • New Brunswick (NJ)

On-site
USD 140,000 - 200,000
Cyber GRC & Policy Lead | Enterprise Risk & Compliance
Cyber GRC & Policy Lead | Enterprise Risk & Compliance

Johnson & Johnson Co. • New Brunswick (NJ)

On-site
USD 140,000 - 180,000
Senior Cybersecurity GRC Lead
Senior Cybersecurity GRC Lead

Johnson Johnson • New Brunswick (NJ)

On-site
USD 120,000 - 180,000
Cyber Governance Lead: Policy, Risk & Compliance
Cyber Governance Lead: Policy, Risk & Compliance

Johnson & Johnson MedTech • New Brunswick (NJ)

On-site
USD 140,000 - 190,000
Cyber GRC Lead - Policy, Risk & Exec Reporting
Cyber GRC Lead - Policy, Risk & Exec Reporting

Antler Co • New Brunswick (NJ)

On-site
USD 140,000 - 190,000
Professional Governance & Policy Analyst
Professional Governance & Policy Analyst

Johnson & Johnson Co. • New Brunswick (NJ)

On-site
USD 79,000 - 142,000
Director, Incident Response & Threat
Director, Incident Response & Threat

Johnson Johnson • Raynham (MA)

Hybrid
USD 180,000 - 240,000