At Johnson & Johnson, we believe health is everything. Our strength in healthcare innovation empowers us to build a world where complex diseases are prevented, treated, and cured, where treatments are smarter and less invasive, and solutions are personal. Through our expertise in Innovative Medicine and MedTech, we are uniquely positioned to innovate across the full spectrum of healthcare solutions today to deliver the breakthroughs of tomorrow, and profoundly impact health for humanity. Learn more at jnj.com.
As guided by Our Credo, Johnson & Johnson is responsible to our employees who work with us throughout the world. We provide an inclusive work environment where each person is considered as an individual. At Johnson & Johnson, we respect the diversity and dignity of our employees and recognize their merit.
Job Function:
Technology Enterprise Strategy & SecurityJob Sub Function:
Security & ControlsJob Category:
People LeaderAll Job Posting Locations:
Irvine, California, United States of America, Yokneam, Haifa District, IsraelJob Description:
About Johnson & Johnson MedTech Cardiovascular:
Fueled by innovation at the intersection of biology and technology, we’re developing the next generation of smarter, less invasive, more personalized treatments.
Are you passionate about improving and expanding the possibilities of Cardiovascular? Ready to join a team that’s reimagining how we heal? Our Cardiovascular team develops leading solutions for heart recovery, electrophysiology, and stroke. You will join a proud heritage of continually elevating standards of care for stroke, heart failure and atrial fibrillation (AFib) patients.
Your unique talents will help patients on their journey to wellness. Learn more at https://www.jnj.com/medtech
We are searching for the best talent for a Senior Manager MedTech Cybersecurity role, to join our team located in Israel or US.
Purpose:
Johnson & Johnson is currently seeking a Sr. Manager for Electrophysiology (EP) and Neurovascular (NV) Cardiovascular business units’ part of Information Security & Risk Management (ISRM) organization. This position is preferred to be based in Yokneam, Haifa Israel or Irvine, California with an option for US. Remote work options may be considered on a case-by-case basis and if approved by the Company.
This candidate will have a diverse background with strong business acumen, technology, and security expertise. He/she will be a strategic thinker who leads with impact inclusively, driving intentional change proactively, and be result driven keeping up with industry trends in cybersecurity. This role will embed directly with our J&J Technology and MedTech EP & NV teams across Research & Development, Supply Chain, and Commercial teams providing the security posture and the end-to-end security portfolio/capability roadmap to improve, identify, and remediate cyber security vulnerabilities.
You will manage and inspire 1 team member and work across a matrixed organization demonstrating authentic leadership, driving results, and showing dedication to our Credo. Your site scope includes global cyber security responsibility for 4 internal Manufacturing sites (IT/OT), 4 R&D sites and labs, Application Security of 300+ applications inclusive of Sarbanes-Oxley, and 3rd party vendors of 200+.
You will be responsible for:
Shape the E2E cybersecurity profile and portfolio from assessment to remediation through developing, influencing, and driving a financial and remediation plan both yearly and long term with strategic roadmaps and business value.
Provide early/proactive engagement through security by design with project teams to drive business understanding and execution of the security controls and capabilities needed for the project.
Perform cybersecurity risk assessments of IT/OT assets within the R&D & Manufacturing sites.
Drive cybersecurity capability adoption R&D, Supply Chain, and Commercial functions to secure assets and enable safe & secure reliability and innovation.
Provide tailored security guidance (based on risk and complexity) - Interpret & apply the internal security requirements and standards for unique IT & OT (Operational Technology) initiatives.
Lead the cyber operational portfolio from identification > driving remediation plan > completion partnering across ISRM, business, and technology teams.
Establish data analytics to provide security posture across EP & NV business units, functions, and sites.
Proactively promote the importance of cybersecurity shared responsibility across the sector and sites through advancing cyber awareness program.
Assist the Security Operations Center (SOC) with security incident investigation activities; work closely with business teams to support affected users and provide liaison with central investigation team.
Drive business understanding of critical cybersecurity regulations and ensuring solutions are compliant (NIST, NIS2, Safe Data, etc.).
Support the global deployment of security initiatives with awareness sessions, identify alternative ways of working to avoid business disruptions, and review exception requests.
Provide audit support as the liaison between audit, technology, and business functions from pre-work to remediation plans.
Qualifications and Requirements:
8+ years of direct or supporting experience in cybersecurity leadership and execution roles, with a background in Research & Development and Commercial environments, required.
Bachelor’s degree in computer science, information technology, business administration, or another rigorous discipline required; MBA preferred.
6+ years of hands-on experience delivering technology and cybersecurity design capabilities across IT and OT environments, including firewalls, network intrusion detection systems, backup, and recovery, required.
Experience with security standards such as ISO 27001, HITRUST, and NIST required.
Cybersecurity, audit, or risk management certifications such as CISM, CISSP, ISA/IEC 62443, CISA, or CRISC preferred.
Excellent communication and collaboration skills, with the ability to network, engage, and influence across all organizational levels, sectors, functions, and regions.
Strategic mindset to develop capability roadmaps that strengthen proactive reliability through data and automation.
Experience with cloud security platforms such as AWS, Azure, or Salesforce required.
Experience securing multiple layers of enterprise architecture, including data, applications, hosts, middleware, networks, and infrastructure.
Strong understanding of current security threats, mitigation strategies, and security vendors and technologies.
Strong understanding of security data protection and related capabilities in R&D labs, clinical, and regulatory environments required.
Direct or supporting experience with application security required; Sarbanes-Oxley compliance and audit experience required.
Understanding of ISA/IEC 62443, NIST 800-53, and NIST 800-82 required.
Experience leading diverse team members with varying cybersecurity expertise, including resource allocation and planning to meet business needs.
Ability to balance strategic perspective with attention to detail to align tactical and long-term security priorities.
Ability to collaborate, build networks, and influence globally across sectors, functions, and organizational levels while establishing credibility as an inspiring cybersecurity leader.
#LI-AB6#LI-Hybrid
Required Skills:
Preferred Skills:
Business Process Design, Collaboration, Crisis Management, Critical Thinking, Cyber Threat Intelligence, Developing Others, Inclusive Leadership, Information Security Auditing, Information Security Management System (ISMS), Information Technology (IT) Security Assessments, Information Technology Strategies, Leadership, Managing Managers, People Performance Management, Presentation Design, Process Optimization, Security Architecture Design, Security PoliciesSkills Required
- 8+ years of direct or supporting cybersecurity leadership and execution experience
- Bachelor's degree in computer science, information technology, business administration, or related field
- MBA
- 6+ years hands-on experience delivering cybersecurity design capabilities across IT and OT (firewalls, NIDS, backup/recovery)
- Experience with ISO 27001, HITRUST, and NIST security standards
- Understanding of ISA/IEC 62443, NIST 800-53, and NIST 800-82
- Experience with cloud security platforms (AWS, Azure, Salesforce)
- Direct or supporting experience with application security
- Sarbanes-Oxley compliance and audit experience
- Experience securing multiple layers of enterprise architecture (data, applications, hosts, middleware, networks, infrastructure)
- Experience in R&D, manufacturing, supply chain, or clinical/regulatory environments with data protection understanding
- Cybersecurity, audit, or risk management certifications (CISM, CISSP, CISA, CRISC) or ISA/IEC 62443 certification
Johnson & Johnson Compensation & Benefits Highlights
The following summarizes recurring compensation and benefits themes identified from responses generated by popular LLMs to common candidate questions about Johnson & Johnson and has not been reviewed or approved by Johnson & Johnson.
-
Healthcare Strength — Healthcare coverage is characterized as comprehensive across medical, dental, and vision, with added supports like onsite clinics, fitness centers, and Employee Assistance resources. Mental-health services and wellbeing reimbursements are also described as meaningful components of the overall package.
-
Retirement Support — Retirement offerings are portrayed as a major differentiator, combining a 401(k) with employer matching and an employer-funded pension plan. Stock options and other long-term financial supports are also positioned as part of the broader rewards mix.
-
Parental & Family Support — Family-related benefits are presented as notably strong, including paid parental leave for all new parents and additional leave types for caregiving and bereavement. Financial assistance for adoption, fertility treatment, and surrogacy is highlighted as a significant support.
Johnson & Johnson Insights
What We Do
Profound Change Requires Boldness. Johnson & Johnson is the largest and most broadly based healthcare company in the world. We’re producing life-changing breakthroughs every day, and have been for the last 130 years. The combination of new technologies and your expertise enables amazing things to happen. Teams from J&J’s consumer business are creating digital tools to help people track the health of their skin. Those working in medical devices are 3-D printing artificial joints personalized for each patient, while researchers in pharmaceuticals use AI to discover lifesaving drugs. Imagine what the rest of our team of 134,000 people at 260 companies in more than 60 countries across the world is accomplishing. We redefine what it means to be a big company in today’s world. Social Media Community Guidelines: http://www.jnj.com/social-media-community-guidelines

.png)





