Sr. Director, GRC, IT Controls & Cyber Culture, Orthopedics
- Discuss this with your agent
- Open in Claude
- Open in ChatGPT
Role details
Tech stack
Job description
DePuy Synthes is recruiting for a(n) Sr. Director, GRC, IT Controls and Cyber Culture.
Johnson & Johnson announced plans to separate our Orthopedics business to establish a standalone orthopedics company, operating as DePuy Synthes. The process of the planned separation is anticipated to be completed within 18 to 24 months, subject to legal requirements, including consultation with works councils and other employee representative bodies, as may be required, regulatory approvals and other customary conditions and approvals. Should you accept this position, it is anticipated that, following conclusion of the transaction, you would be an employee of DePuy Synthes and your employment would be governed by DePuy Synthes employment processes, programs, policies, and benefit plans. In that case, details of any planned changes would be provided to you by DePuy Synthes at an appropriate time and subject to any necessary consultation processes., This role serves as a senior cybersecurity leader reporting to the CISO, with enterprise accountability for building, maturing, and operationalizing the Governance, Risk & Compliance (GRC) function across DePuy Synthes. The Sr. Director will oversee the BISO manager organization, establish scalable risk governance practices, strengthen security awareness and behavior based culture programs, and drive implementation of IT controls and an enterprise assurance framework. The role will also oversee external cybersecurity assessments and disclosures, including cyber insurance, ESG-related cybersecurity inputs, and other third-party assurance activities. This highly visible leadership role will help ensure cybersecurity risk, compliance, control effectiveness, and cultural adoption are consistently managed across the enterprise in support of business priorities, regulatory expectations, and organizational resilience., * Build and mature the enterprise GRC function, including governance forums, risk management processes, compliance oversight, control monitoring, issue management, and executive reporting.
- Provide leadership and oversight for the BISO manager organization, ensuring consistent engagement with business leaders, effective cyber risk advisory support, and alignment of security priorities to businessobjectives.
- Lead enterprise cyber risk management activities, including risk identification, assessment, mitigation planning, escalation, and reporting to senior leadership and governance bodies.
- Own the enterprise cybersecurity policy and standards lifecycle - from creation and implementation to continuous review - ensuring clarity, compliance, and alignment with organizational goals.
- Oversee SOX cybersecurity and IT control activities, including implementation, operating effectiveness,evidencereadiness, remediation tracking, and partnership with Finance, Internal Audit, External Audit, and IT control owners.
- Establish and operationalize an enterprise IT controls and assurance framework that enables consistent control design, testing, monitoring, reporting, and continuous improvement across the organization.
- Lead oversight of external cybersecurity assessments and assurance requests, including cyber insurance questionnaires, ESG-related cybersecurity inputs, customer or partner assessments, and other third-party reviews requiring enterprise cyber risk and control representation.
- Drive cybersecurity compliance with applicable global regulations, standards, and frameworks, ensuring the organization candemonstratecontrol effectiveness and audit readiness.
- Lead security awareness, behavior, and culture initiatives that improve workforce accountability, reducehuman-centricrisk, and embed secure practices intoday-to-daybusiness operations.
- Lead and develophigh-performingcybersecurity leaders and teams, fostering a culture of accountability, collaboration, disciplined execution, and continuous improvement.
- Provideexecutive-levelreporting on cybersecurity risk, compliance status, control effectiveness, assurance outcomes, and program maturity to senior leadership and governance bodies.
Requirements
- Required:Bachelor’s degree in Information Security, Computer Science, Engineering, ora relatedfield.
- Preferred: Master’s degree (MS, MBA, or equivalent) in Cybersecurity, Information Systems, or Business.
Experience and Skills
Required:
- 12-14 years of progressive experience in cybersecurity, information security, technology risk management, IT controls, or GRC, including senior leadership roles.
- Demonstrated experience building or maturing enterprise GRC programs in a regulated, global, or complex operating environment.
- Experience leading BISO, cyber risk advisory, security governance, or business aligned cybersecurity teams.
- Deep knowledge of cybersecurity risk management, compliance frameworks, IT controls, SOX control expectations, assurance practices, and audit readiness.
- Experience overseeing external cybersecurity assessments, including cyber insurance, ESG-related cybersecurity reporting, customer or partner assessments, and third-party assurance requests.
- Experience building, mentoring, and leading senior level cybersecurity teams.
- Strong strategic, analytical, and communication skills, with the ability to translate technical risk, control gaps, and compliance obligations into business impact.
Preferred:
- Experience implementing or transforming enterprise IT controls, SOX programs, control testing, remediation governance, and assurance frameworks.
- Experience driving cybersecurity awareness, behavior change, and culture programs across a large enterprise.
- Experienceoperatingin complex, global organizations undergoing transformation or separation.
- Demonstrated success improvingcybersecuritymaturity, control effectiveness, and risk accountability at scale.
- Proven ability to influence executive stakeholders andpartnereffectively across IT, Finance, Internal Audit, External Audit, Legal, Risk, Compliance, and business leadership functions.
Other:
- Language: English (fluent)
- Travel: Up to 20%, domestic and international
- Certifications (preferred): CISSP, CISM, CRISC, or equivalent
Benefits & conditions
Business Process Design, Crisis Management, Critical Thinking, Cybersecurity, Developing Others, Inclusive Leadership, Industry Analysis, Information Security Auditing, Information Security Management System (ISMS), Information Technology (IT) Security Assessments, Information Technology Strategies, Leadership, Presentation Design, Process Optimization, Risk Management Framework, Security Architecture Design, Security Policies, Strategic Thinking
The anticipated base pay range for this position is :
$178,000.00 - $307,050.00
Additional Description for Pay Transparency:
Subject to the terms of their respective plans, employees are eligible to participate in the Company’s consolidated retirement plan (pension) and savings plan (401(k)).
This position is eligible to participate in the Company’s long-term incentive program.
Subject to the terms of their respective policies and date of hire, employees are eligible for the following time off benefits:
Vacation -120 hours per calendar year
Sick time - 40 hours per calendar year; for employees who reside in the State of Colorado -48 hours per calendar year; for employees who reside in the State of Washington -56 hours per calendar year
Holiday pay, including Floating Holidays -13 days per calendar year
Work, Personal and Family Time - up to 40 hours per calendar year
Parental Leave - 480 hours within one year of the birth/adoption/foster care of a child
Bereavement Leave - 240 hours for an immediate family member: 40 hours for an extended family member per calendar year
Caregiver Leave - 80 hours in a 52-week rolling period10 days
Volunteer Leave - 32 hours per calendar year
Military Spouse Time-Off - 80 hours per calendar year
About the company
At Johnson & Johnson, we believe health is everything. Our strength in healthcare innovation empowers us to build a world where complex diseases are prevented, treated, and cured, where treatments are smarter and less invasive, and solutions are personal. Through our expertise in Innovative Medicine and MedTech, we are uniquely positioned to innovate across the full spectrum of healthcare solutions today to deliver the breakthroughs of tomorrow, and profoundly impact health for humanity. Learn more at jnj.com
As guided by Our Credo, Johnson & Johnson is responsible to our employees who work with us throughout the world. We provide an inclusive work environment where each person is considered as an individual. At Johnson & Johnson, we respect the diversity and dignity of our employees and recognize their merit.
Apply for this position
This job is hosted externally. Click below to view the full posting and apply.
Apply on dejobs.orgGood distractions
Talks and stories from around this role — technically off-topic, practically not.
Moments
Explore playlistsVideos
See allRelated articles
See all
Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.
Résumé-Driven Development: How IT trends affect the job market for software developers
System change: restart as developer?
Now is the time for industrialized software development