Professional, SOX Lead

6090-Johnson & Johnson Services Inc. Legal Entity

New Brunswick (NJ)

On-site

USD 94,000 - 170,000

Full time

2 days ago
Be an early applicant
Application generator

Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Job summary

Johnson & Johnson is recruiting a Professional, SOX Lead for DePuy Synthes, with location flexibility across New Brunswick, NJ; West Chester, PA; Palm Beach Gardens, FL; Warsaw, IN; Raynham, MA or Raritan, NJ. The role drives IT controls testing, SOX program design, and governance across IT and Finance, partnering with Internal Audit and external auditors.

The ideal candidate has 6+ years in IT audit, IT controls, SOX, and ERP testing, plus COSO/COBIT knowledge and strong communication.

Qualifications

  • Bachelor's degree in Information Technology, Computer Science, Accounting, Information Systems, Finance, or related discipline.
  • Experience with ITGC design and testing in SOX programs.
  • Familiarity with COSO, COBIT, PCAOB standards; ERP control testing (SAP/Oracle) preferred.

Responsibilities

  • Lead annual SOX IT scoping, risk assessment, and control rationalization for in-scope apps and infra.
  • Design and maintain ITGC frameworks for access, change management, and operations.
  • Plan and perform walkthroughs, design assessments, and testing; analyze deficiencies.
  • Coordinate with external auditors and Internal Audit for SOX requests and evidence submission.
  • Assess deficiency severity and drive remediation with control owners until closure.
  • Collaborate with IAM teams to strengthen access controls and SoD.
  • Evaluate SOX impact of ERP changes and pre-live control requirements.
  • Establish dashboards and reporting on control health and remediation status.
  • Assess third-party and cloud providers; review SOC reports and CUECs.
  • Drive automation and continuous controls monitoring initiatives.

Skills

IT audit
SOX compliance
ITGC design
COSO/COBIT
ERP testing
Communication
Documentation
Stakeholder mgmt
External audit coordination

Education

Bachelor's degree in IT or related field
CISA (required or in progress)

Tools

ServiceNow IRM
Archer
AuditBoard
SAP GRC
Power BI

Job description

At Johnson & Johnson,we believe health is everything. Our strength in healthcare innovation empowers us to build aworld where complex diseases are prevented, treated, and cured,where treatments are smarter and less invasive, andsolutions are personal.Through our expertise in Innovative Medicine and MedTech, we are uniquely positioned to innovate across the full spectrum of healthcare solutions today to deliver the breakthroughs of tomorrow, and profoundly impact health for humanity.Learn more at jnj.com As guided by Our Credo, Johnson & Johnson is responsible to our employees who work with us throughout the world. We provide an inclusive work environment where each person is considered as an individual. At Johnson & Johnson, we respect the diversity and dignity of our employees and recognize their merit.

Job Function:

Technology Enterprise Strategy & Security

Job Sub Function:

Security & Controls

Job Category:

Scientific/Technology

All Job Posting Locations:

New Brunswick, New Jersey, United States of America, Palm Beach Gardens, Florida, United States of America, Raritan, New Jersey, United States of America, Raynham, Massachusetts, United States of America, Warsaw, Indiana, United States of America, West Chester, Pennsylvania, United States of America

Job Description:

DePuy Synthes is recruiting for a Professional, SOX Lead, located in New Brunswick, NJ or West Chester, PA or Palm Beach Gardens, FL or Warsaw, IN or Raynham, MA or Raritan, NJ.

Job Overview The Professional, SOX Lead is a seasoned individual contributor within the Cybersecurity function, GRC, IT Controls & Cyber Culture sub-function, accountable for the design, execution, and continuous improvement of the IT General Controls (ITGC) and IT Application Controls environment supporting SOX compliance for DePuy Synthes. This role establishes control testing methods based on proven assurance frameworks, evaluates the reliability and effectiveness of internal information systems controls, and partners across IT, Finance, Internal Audit, and external auditors to ensure a clean, defensible control environment. The role applies advanced skills in IT controls and assurance to build industry-leading control practices, and contributes to compliance and remediation programs under general direction.

Key Responsibilities:
  • Lead the annual SOX IT scoping, risk assessment, and control rationalization exercise across in-scope applications, databases, operating systems, and infrastructure, with direct impact on the achievement of assurance results.
  • Design, document, and maintain ITGC frameworks covering access to programs and data, change management, program development, and IT operations, ensuring alignment with COSO, COBIT, and PCAOB expectations.
  • Plan and execute walkthroughs, control design assessments, and operating effectiveness testing; evaluate results and perform root cause analysis on identified deficiencies.
  • Serve as the primary liaison for external auditors and Internal Audit for all IT-related SOX requests, coordinating PBC (Prepared by Client) deliverables, evidence submission, and issue resolution.
  • Assess and communicate the severity of control deficiencies (deficiency, significant deficiency, material weakness), and drive remediation plans with control owners through to validated closure.
  • Partner with Identity & Access Management and Identity Governance & Administration teams to strengthen user access provisioning, periodic access re-certification, privileged access, and segregation of duties (SoD) controls.
  • Evaluate the SOX control impact of ERP and technology change initiatives — including system implementations, migrations, upgrades, and separation/carve-out activity — and define control requirements prior to go-live.
  • Establish and monitor key control metrics, dashboards, and reporting to provide leadership visibility into control health, testing progress, and remediation status.
  • Assess the control implications of third‑party and cloud service providers, including review of SOC 1 / SOC 2 reports and evaluation of complementary user entity controls (CUECs).
  • Interpret evolving regulations as they pertain to information systems, platforms, and IT operating processes, and translate requirements into practical control standards and procedures.
  • Drive automation and continuous controls monitoring opportunities to improve testing efficiency, reduce manual effort, and increase control coverage.
  • Develop and deliver training and awareness materials to control owners, strengthening compliance ownership and cyber culture across the IT organization.
  • Maintain complete and audit‑ready documentation including narratives, process flows, RACM (Risk and Control Matrix), test scripts, and evidence repositories.
Qualifications

Education Bachelor's degree in Information Technology, Computer Science, Accounting, Information Systems, Finance, or a related discipline.

Advanced degree or equivalent professional experience in cybersecurity or information systems (preferred).

Experience and Skills Required:

6+ years of progressive experience in IT audit, IT controls, SOX compliance, or technology risk and assurance, including hands on ITGC design and testing.

Demonstrated expertise across the four ITGC domains: logical access, change management, program development, and IT operations.

Working knowledge of COSO 2013, COBIT, PCAOB auditing standards, and SOX 404 requirements.

Experience testing controls over ERP platforms (e.g., SAP, Oracle) and supporting databases, operating systems, and infrastructure layers.

Proven ability to assess deficiency severity, articulate risk to non‑technical stakeholders, and drive remediation to closure.

Experience coordinating directly with external auditors and Internal Audit through a full annual SOX cycle.

Strong analytical, documentation, and written/verbal communication skills, with the ability to influence control owners without direct authority.

Preferred:

Big 4 or large multinational IT audit experience; MedTech, Life Sciences, or other regulated industry background.

Experience supporting SOX readiness within a divestiture, carve‑out, spin‑off, or standalone entity stand‑up.

Familiarity with cloud control environments (AWS, Azure) and evaluation of SOC 1 / SOC 2 reports and CUECs.

Exposure to GRC tooling (e.g., ServiceNow IRM, Archer, AuditBoard, SAP GRC) and SoD analysis platforms.

Experience with continuous controls monitoring, control automation, or data analytics applied to control testing (e.g., Power BI, Tableau, SQL, Alteryx).

Experience adopting Generative AI / LLM‑enabled tooling to accelerate evidence review, control documentation, and testing workflows.

Working knowledge of adjacent frameworks such as NIST CSF, ISO 27001, and ITIL.

Other:

Travel: Up to 10% domestic and international travel expected.

Language: English proficiency required.

Certifications:

CISA required or in progress. CIA, CISSP, CRISC, CPA/CA, or ISO 27001 Lead Auditor preferred.

Additional Information:

For more information on how we support the whole health of our employees throughout their wellness, career and life journey, please visit www.careers.jnj.com.

Johnson & Johnson announced plans to separate our Orthopaedics business to establish a standalone orthopaedics company, operating as DePuy Synthes. The process of the planned separation is anticipated to be completed within 18 to 24 months, subject to legal requirements, including consultation with works councils and other employee representative bodies, as may be required, regulatory approvals and other customary conditions and approvals. Should you accept this position, it is anticipated that, following conclusion of the transaction, you would be an employee of DePuy Synthes and your employment would be governed by DePuy Synthes employment processes, programs, policies, and benefit plans. In that case, details of any planned changes would be provided to you by DePuy Synthes at an appropriate time and subject to any necessary consultation processes.

Johnson & Johnson is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, age, national origin, disability, protected veteran status or other characteristics protected by federal, state or local law. We actively seek qualified candidates who are protected veterans and individuals with disabilities as defined under VEVRAA and Section 503 of the Rehabilitation Act.

If you are an individual with a disability and would like to request an accommodation, external applicants please contact us via https://www.jnj.com/contact-us/careers, internal employees contact AskGS to be directed to your accommodation resource.

Required Skills:
  • Communication
  • Corrective and Preventive Action (CAPA)
  • Critical Thinking
  • Information Security Auditing
  • Information Security Management System (ISMS)
  • Information Technology (IT) Security Assessments
  • Information Technology Strategies
  • Mentorship
  • Network Optimization
  • Presentation Design
  • Process Optimization
  • Report Writing
  • Security Policies
  • Technical Credibility
  • Technologically Savvy
  • Training People
  • Vulnerability Assessments
Preferred Skills:
  • Communication
  • Corrective and Preventive Action (CAPA)
  • Critical Thinking
  • Information Security Auditing
  • Information Security Management System (ISMS)
  • Information Technology (IT) Security Assessments
  • Information Technology Strategies
  • Mentorship
  • Network Optimization
  • Presentation Design
  • Process Optimization
  • Report Writing
  • Security Policies
  • Technical Credibility
  • Technologically Savvy
  • Training People
  • Vulnerability Assessments
Pay Transparency:

The anticipated base pay range for this position is : 94,000.00 - 170,000.00 USD Annual Additional Description for Pay Transparency: Subject to the terms of their respective plans, employees are eligible to participate in the Company’s consolidated retirement plan (pension) and savings plan (401(k)). Subject to the terms of their respective policies and date of hire, employees are eligible for the following time off benefits:

  • Vacation –120 hours per calendar year
  • Sick time - 40 hours per calendar year; for employees who reside in the State of Colorado –48 hours per calendar year; for employees who reside in the State of Washington –56 hours per calendar year
  • Holiday pay, including Floating Holidays –13 days per calendar year
  • Work, Personal and Family Time - up to 40 hours per calendar year
  • Parental Leave – 480 hours within one year of the birth/adoption/foster care of a child
  • Bereavement Leave – 240 hours for an immediate family member: 40 hours for an extended family member per calendar year
  • Caregiver Leave – 80 hours in a 52-week rolling period10 days
  • Volunteer Leave – 32 hours per calendar year
  • Military Spouse Time-Off – 80 hours per calendar year

For additional general information on Company benefits, please go to: - https://www.careers.jnj.com/employee-benefits

At Johnson & Johnson,we believe health is everything. Our strength in healthcare innovation empowers us to build aworld where complex diseases are prevented, treated, and cured,where treatments are smarter and less invasive, andsolutions are personal.Through our expertise in Innovative Medicine and MedTech, we are uniquely positioned to innovate across the full spectrum of healthcare solutions today to deliver the breakthroughs of tomorrow, and profoundly impact health for humanity.Learn more at https://www.jnj.com/.

Do Not Sell or Share My Personal Information Limit the Use of My Personal Information

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Professional Governance & Policy Analyst
Professional Governance & Policy Analyst

6090-Johnson & Johnson Services Inc. Legal Entity • New Brunswick (NJ)

Hybrid
USD 79,000 - 142,000
Professional, Compliance Lead
Professional, Compliance Lead

6090-Johnson & Johnson Services Inc. Legal Entity • New Brunswick (NJ)

On-site
USD 140,000 - 200,000
Professional, Quality Steward
Professional, Quality Steward

6090-Johnson & Johnson Services Inc. Legal Entity • New Brunswick (NJ)

On-site
USD 79,000 - 142,000
Vacation time
Parental Leave
Volunteer Leave
Exp, Analyst, Security Engineer Product
Exp, Analyst, Security Engineer Product

6090-Johnson & Johnson Services Inc. Legal Entity • New Brunswick (NJ)

On-site
USD 79,000 - 142,000
Professional Governance & Policy Analyst
Professional Governance & Policy Analyst

Johnson & Johnson MedTech • Warsaw (IN)

On-site
USD 79,000 - 142,000
Professional Governance & Policy Analyst
Professional Governance & Policy Analyst

Johnson & Johnson MedTech • Town of Florida (NY)

On-site
USD 79,000 - 142,000
Professional Governance & Policy Analyst
Professional Governance & Policy Analyst

Johnson & Johnson MedTech • Raynham (MA)

On-site
USD 79,000 - 142,000
Professional, Prog Lead, PenTesting Svcs
Professional, Prog Lead, PenTesting Svcs

6090-Johnson & Johnson Services Inc. Legal Entity • New Brunswick (NJ)

On-site
USD 94,000 - 170,000
Manager, Culture & Inclusion
Manager, Culture & Inclusion

6090-Johnson & Johnson Services Inc. Legal Entity • Raynham (MA)

On-site
USD 102,000 - 204,000
Vacation 120 hours per year
Sick time 40 hours per year
Holiday pay 13 days per year
+1
Professional Governance & Policy Analyst
Professional Governance & Policy Analyst

Johnson & Johnson MedTech • Raritan (NJ)

On-site
USD 79,000 - 142,000