Senior Manager MedTech Cybersecurity

Johnson & Johnson


Job Location:

Irvine, CA - USA

Monthly Salary: Not Disclosed
Posted on: 8 hours ago
Vacancies: 1 Vacancy

Job Summary

At Johnson & Johnsonwe believe health is everything. Our strength in healthcare innovation empowers us to build aworld where complex diseases are prevented treated and curedwhere treatments are smarter and less invasive andsolutions are our expertise in Innovative Medicine and MedTech we are uniquely positioned to innovate across the full spectrum of healthcare solutions today to deliver the breakthroughs of tomorrow and profoundly impact health for more at

As guided by Our Credo Johnson & Johnson is responsible to our employees who work with us throughout the world. We provide an inclusive work environment where each person is considered as an individual. At Johnson & Johnson we respect the diversity and dignity of our employees and recognize their merit.

Job Function:

Technology Enterprise Strategy & Security

Job Sub Function:

Security & Controls

Job Category:

People Leader

All Job Posting Locations:

Irvine California United States of America

Job Description:

About Johnson & Johnson MedTech Cardiovascular:

Fueled by innovation at the intersection of biology and technology were developing the next generation of smarter less invasive more personalized treatments.

Are you passionate about improving and expanding the possibilities of Cardiovascular Ready to join a team thats reimagining how we heal Our Cardiovascular team develops leading solutions for heart recovery electrophysiology and stroke. You will join a proud heritage of continually elevating standards of care for stroke heart failure and atrial fibrillation (AFib) patients.

Your unique talents will help patients on their journey to wellness. Learn more at are searching for the best talent for a Senior Manager MedTech Cybersecurity role to join our team located in Irvine US.

Purpose:
Johnson & Johnson is currently seeking a Sr. Manager for Electrophysiology (EP) and Neurovascular (NV) Cardiovascular business units part of Information Security & Risk Management (ISRM) organization. This position is preferred to be based in Yokneam Haifa Israel or Irvine California with an option for US. Remote work options may be considered on a case-by-case basis and if approved by the Company.

This candidate will have a diverse background with strong business acumen technology and security expertise. He/she will be a strategic thinker who leads with impact inclusively driving intentional change proactively and be result driven keeping up with industry trends in cybersecurity. This role will embed directly with our J&J Technology and MedTech EP & NV teams across Research & Development Supply Chain and Commercial teams providing the security posture and the end-to-end security portfolio/capability roadmap to improve identify and remediate cyber security vulnerabilities.

You will manage and inspire 1 team member and work across a matrixed organization demonstrating authentic leadership driving results and showing dedication to our Credo. Your site scope includes global cyber security responsibility for 4 internal Manufacturing sites (IT/OT) 4 R&D sites and labs Application Security of 300 applications inclusive of Sarbanes-Oxley and 3rd party vendors of 200.

You will be responsible for:

  • Shape the E2E cybersecurity profile and portfolio from assessment to remediation through developing influencing and driving a financial and remediation plan both yearly and long term with strategic roadmaps and business value.

  • Provide early/proactive engagement through security by design with project teams to drive business understanding and execution of the security controls and capabilities needed for the project.

  • Perform cybersecurity risk assessments of IT/OT assets within the R&D & Manufacturing sites.

  • Drive cybersecurity capability adoption R&D Supply Chain and Commercial functions to secure assets and enable safe & secure reliability and innovation.

  • Provide tailored security guidance (based on risk and complexity) - Interpret & apply the internal security requirements and standards for unique IT & OT (Operational Technology) initiatives.

  • Lead the cyber operational portfolio from identification > driving remediation plan > completion partnering across ISRM business and technology teams.

  • Establish data analytics to provide security posture across EP & NV business units functions and sites.

  • Proactively promote the importance of cybersecurity shared responsibility across the sector and sites through advancing cyber awareness program.

  • Assist the Security Operations Center (SOC) with security incident investigation activities; work closely with business teams to support affected users and provide liaison with central investigation team.

  • Drive business understanding of critical cybersecurity regulations and ensuring solutions are compliant (NIST NIS2 Safe Data etc.).

  • Support the global deployment of security initiatives with awareness sessions identify alternative ways of working to avoid business disruptions and review exception requests.

  • Provide audit support as the liaison between audit technology and business functions from pre-work to remediation plans.

Qualifications and Requirements:

  • 8 years of direct or supporting experience in cybersecurity leadership and execution roles with a background in Research & Development and Commercial environments required.

  • Bachelors degree in computer science information technology business administration or another rigorous discipline required; MBA preferred.

  • 6 years of hands-on experience delivering technology and cybersecurity design capabilities across IT and OT environments including firewalls network intrusion detection systems backup and recovery required.

  • Experience with security standards such as ISO 27001 HITRUST and NIST required.

  • Cybersecurity audit or risk management certifications such as CISM CISSP ISA/IEC 62443 CISA or CRISC preferred.

  • Excellent communication and collaboration skills with the ability to network engage and influence across all organizational levels sectors functions and regions.

  • Strategic mindset to develop capability roadmaps that strengthen proactive reliability through data and automation.

  • Experience with cloud security platforms such as AWS Azure or Salesforce required.

  • Experience securing multiple layers of enterprise architecture including data applications hosts middleware networks and infrastructure.

  • Strong understanding of current security threats mitigation strategies and security vendors and technologies.

  • Strong understanding of security data protection and related capabilities in R&D labs clinical and regulatory environments required.

  • Direct or supporting experience with application security required; Sarbanes-Oxley compliance and audit experience required.

  • Understanding of ISA/IEC 62443 NIST 800-53 and NIST 800-82 required.

  • Experience leading diverse team members with varying cybersecurity expertise including resource allocation and planning to meet business needs.

  • Ability to balance strategic perspective with attention to detail to align tactical and long-term security priorities.

  • Ability to collaborate build networks and influence globally across sectors functions and organizational levels while establishing credibility as an inspiring cybersecurity leader.

Required Skills:

Preferred Skills:

Business Process Design Collaboration Crisis Management Critical Thinking Cyber Threat Intelligence Developing Others Inclusive Leadership Information Security Auditing Information Security Management System (ISMS) Information Technology (IT) Security Assessments Information Technology Strategies Leadership Managing Managers People Performance Management Presentation Design Process Optimization Security Architecture Design Security Policies

The anticipated base pay range for this position is :

Additional Description for Pay Transparency:


Required Experience:

Senior Manager

At Johnson & Johnsonwe believe health is everything. Our strength in healthcare innovation empowers us to build aworld where complex diseases are prevented treated and curedwhere treatments are smarter and less invasive andsolutions are our expertise in Innovative Medicine and MedTech we are unique...

About Company

Company Logo

About Johnson & Johnson A t Johnson & Johnson, we believe good health is the foundation of vibrant lives, thriving communities and forward progress. That’s why for more than 130 years, we have aimed to keep people well at every age and every stage of life. Today, as the world’s larges ... View more

View Profile View Profile