> Markdown version of [/jobs/ext/1611300-sr-director-grc-it-controls-cyber-culture-orthopedics](https://www.wearedevelopers.com/jobs/ext/1611300-sr-director-grc-it-controls-cyber-culture-orthopedics). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Sr. Director, GRC, IT Controls & Cyber Culture, Orthopedics - **Company:** Johnson & Johnson - **Location:** Raritan, NJ, United States - **Experience:** Expert - **Salary:** $178,000.0 - $307,050.0 - **Contract:** Permanent contract - **Skills:** Cyber Security, Information Systems, IT General Controls (ITGC), Cyber Threat Analysis, Information Technology - **Published:** July 15, 2026 - **Apply:** https://dejobs.org/x/x/00902EB7D5D3472CA3DEB02BFB548CE8/job/ ## About the Role * Required:Bachelor's degree in Information Security, Computer Science, Engineering, ora relatedfield. * Preferred: Master's degree (MS, MBA, or equivalent) in Cybersecurity, Information Systems, or Business. Experience and Skills Required: * 12-14 years of progressive experience in cybersecurity, information security, technology risk management, IT controls, or GRC, including senior leadership roles. * Demonstrated experience building or maturing enterprise GRC programs in a regulated, global, or complex operating environment. * Experience leading BISO, cyber risk advisory, security governance, or business aligned cybersecurity teams. * Deep knowledge of cybersecurity risk management, compliance frameworks, IT controls, SOX control expectations, assurance practices, and audit readiness. * Experience overseeing external cybersecurity assessments, including cyber insurance, ESG-related cybersecurity reporting, customer or partner assessments, and third-party assurance requests. * Experience building, mentoring, and leading senior level cybersecurity teams. * Strong strategic, analytical, and communication skills, with the ability to translate technical risk, control gaps, and compliance obligations into business impact. Preferred: * Experience implementing or transforming enterprise IT controls, SOX programs, control testing, remediation governance, and assurance frameworks. * Experience driving cybersecurity awareness, behavior change, and culture programs across a large enterprise. * Experienceoperatingin complex, global organizations undergoing transformation or separation. * Demonstrated success improvingcybersecuritymaturity, control effectiveness, and risk accountability at scale. * Proven ability to influence executive stakeholders andpartnereffectively across IT, Finance, Internal Audit, External Audit, Legal, Risk, Compliance, and business leadership functions. Other: * Language: English (fluent) * Travel: Up to 20%, domestic and international * Certifications (preferred): CISSP, CISM, CRISC, or equivalent ## Description DePuy Synthes is recruiting for a(n) Sr. Director, GRC, IT Controls and Cyber Culture. Johnson & Johnson announced plans to separate our Orthopedics business to establish a standalone orthopedics company, operating as DePuy Synthes. The process of the planned separation is anticipated to be completed within 18 to 24 months, subject to legal requirements, including consultation with works councils and other employee representative bodies, as may be required, regulatory approvals and other customary conditions and approvals. Should you accept this position, it is anticipated that, following conclusion of the transaction, you would be an employee of DePuy Synthes and your employment would be governed by DePuy Synthes employment processes, programs, policies, and benefit plans. In that case, details of any planned changes would be provided to you by DePuy Synthes at an appropriate time and subject to any necessary consultation processes., This role serves as a senior cybersecurity leader reporting to the CISO, with enterprise accountability for building, maturing, and operationalizing the Governance, Risk & Compliance (GRC) function across DePuy Synthes. The Sr. Director will oversee the BISO manager organization, establish scalable risk governance practices, strengthen security awareness and behavior based culture programs, and drive implementation of IT controls and an enterprise assurance framework. The role will also oversee external cybersecurity assessments and disclosures, including cyber insurance, ESG-related cybersecurity inputs, and other third-party assurance activities. This highly visible leadership role will help ensure cybersecurity risk, compliance, control effectiveness, and cultural adoption are consistently managed across the enterprise in support of business priorities, regulatory expectations, and organizational resilience., * Build and mature the enterprise GRC function, including governance forums, risk management processes, compliance oversight, control monitoring, issue management, and executive reporting. * Provide leadership and oversight for the BISO manager organization, ensuring consistent engagement with business leaders, effective cyber risk advisory support, and alignment of security priorities to businessobjectives. * Lead enterprise cyber risk management activities, including risk identification, assessment, mitigation planning, escalation, and reporting to senior leadership and governance bodies. * Own the enterprise cybersecurity policy and standards lifecycle - from creation and implementation to continuous review - ensuring clarity, compliance, and alignment with organizational goals. * Oversee SOX cybersecurity and IT control activities, including implementation, operating effectiveness,evidencereadiness, remediation tracking, and partnership with Finance, Internal Audit, External Audit, and IT control owners. * Establish and operationalize an enterprise IT controls and assurance framework that enables consistent control design, testing, monitoring, reporting, and continuous improvement across the organization. * Lead oversight of external cybersecurity assessments and assurance requests, including cyber insurance questionnaires, ESG-related cybersecurity inputs, customer or partner assessments, and other third-party reviews requiring enterprise cyber risk and control representation. * Drive cybersecurity compliance with applicable global regulations, standards, and frameworks, ensuring the organization candemonstratecontrol effectiveness and audit readiness. * Lead security awareness, behavior, and culture initiatives that improve workforce accountability, reducehuman-centricrisk, and embed secure practices intoday-to-daybusiness operations. * Lead and develophigh-performingcybersecurity leaders and teams, fostering a culture of accountability, collaboration, disciplined execution, and continuous improvement. * Provideexecutive-levelreporting on cybersecurity risk, compliance status, control effectiveness, assurance outcomes, and program maturity to senior leadership and governance bodies. ## Related Videos - [What makes Cybersecurity different for critical infrastructure?](https://www.wearedevelopers.com/videos/571-what-makes-cybersecurity-different-for-critical-infrastructure) - [Cyber Sleuth: Finding Hidden Connections in Cyber Data](https://www.wearedevelopers.com/videos/893-cyber-sleuth-finding-hidden-connections-in-cyber-data) - [Microservices? Monoliths? An Annoying Discussion!](https://www.wearedevelopers.com/videos/970-microservices-monoliths-an-annoying-discussion) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [Reporting Active Exploits in 24 Hours: Are You Ready for the CRA?](https://www.wearedevelopers.com/videos/100248-reporting-active-exploits-in-24-hours-are-you-ready-for-the-cra) - [Forecasting Cyber Attacks with Glassdoor Reviews - Lianne Potter](https://www.wearedevelopers.com/videos/2143-forecasting-cyber-attacks-with-glassdoor-reviews-lianne-potter) ## Related Articles - [What’s the Difference between a Junior, Mid, and Senior Developer?](https://www.wearedevelopers.com/magazine/238-what-s-the-difference-between-a-junior-mid-and-senior-developer) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Résumé-Driven Development: How IT trends affect the job market for software developers](https://www.wearedevelopers.com/magazine/59-resume-driven-development-how-it-trends-affect-the-job-market-for-software-developers) - [System change: restart as developer?](https://www.wearedevelopers.com/magazine/39-system-change-restart-as-developer) - [Now is the time for industrialized software development](https://www.wearedevelopers.com/magazine/601-now-is-the-time-for-industrialized-software-development) - [Best Paying Jobs in Technology](https://www.wearedevelopers.com/magazine/256-best-paying-jobs-in-technology)