Senior Manager MedTech Cybersecurity

Posted 3 Days Ago
Be an Early Applicant
Irvine, CA, USA
In-Office
Senior level
Healthtech • Biotech • Pharmaceutical • Manufacturing
The Role
Lead MedTech cybersecurity for Electrophysiology and Neurovascular business units, embedding with R&D, Supply Chain and Commercial teams to assess IT/OT risk, drive remediation, adopt security capabilities, support SOC investigations, ensure regulatory compliance (NIST, NIS2, ISO, HITRUST), provide audit liaison, and build security posture analytics while managing and developing a small team.
Summary Generated by Built In

At Johnson & Johnson, we believe health is everything. Our strength in healthcare innovation empowers us to build a world where complex diseases are prevented, treated, and cured, where treatments are smarter and less invasive, and solutions are personal. Through our expertise in Innovative Medicine and MedTech, we are uniquely positioned to innovate across the full spectrum of healthcare solutions today to deliver the breakthroughs of tomorrow, and profoundly impact health for humanity. Learn more at jnj.com

As guided by Our Credo, Johnson & Johnson is responsible to our employees who work with us throughout the world.  We provide an inclusive work environment where each person is considered as an individual.  At Johnson & Johnson, we respect the diversity and dignity of our employees and recognize their merit.

Job Function:

Technology Enterprise Strategy & Security

Job Sub Function:

Security & Controls

Job Category:

People Leader

All Job Posting Locations:

Irvine, California, United States of America

Job Description:

About Johnson & Johnson MedTech Cardiovascular:

Fueled by innovation at the intersection of biology and technology, we’re developing the next generation of smarter, less invasive, more personalized treatments.

Are you passionate about improving and expanding the possibilities of Cardiovascular? Ready to join a team that’s reimagining how we heal? Our Cardiovascular team develops leading solutions for heart recovery, electrophysiology, and stroke. You will join a proud heritage of continually elevating standards of care for stroke, heart failure and atrial fibrillation (AFib) patients.

Your unique talents will help patients on their journey to wellness. Learn more at https://www.jnj.com/medtech
We are searching for the best talent for a Senior Manager MedTech Cybersecurity role, to join our team located in Irvine, US.

Purpose:
Johnson & Johnson is currently seeking a Sr. Manager for Electrophysiology (EP) and Neurovascular (NV) Cardiovascular business units’ part of Information Security & Risk Management (ISRM) organization. This position is preferred to be based in Yokneam, Haifa Israel or Irvine, California with an option for US. Remote work options may be considered on a case-by-case basis and if approved by the Company. 

This candidate will have a diverse background with strong business acumen, technology, and security expertise. He/she will be a strategic thinker who leads with impact inclusively, driving intentional change proactively, and be result driven keeping up with industry trends in cybersecurity.  This role will embed directly with our J&J Technology and MedTech EP & NV teams across Research & Development, Supply Chain, and Commercial teams providing the security posture and the end-to-end security portfolio/capability roadmap to improve, identify, and remediate cyber security vulnerabilities.

You will manage and inspire 1 team member and work across a matrixed organization demonstrating authentic leadership, driving results, and showing dedication to our Credo. Your site scope includes global cyber security responsibility for 4 internal Manufacturing sites (IT/OT), 4 R&D sites and labs, Application Security of 300+ applications inclusive of Sarbanes-Oxley, and 3rd party vendors of 200+.

You will be responsible for:

  • Shape the E2E cybersecurity profile and portfolio from assessment to remediation through developing, influencing, and driving a financial and remediation plan both yearly and long term with strategic roadmaps and business value.

  • Provide early/proactive engagement through security by design with project teams to drive business understanding and execution of the security controls and capabilities needed for the project.

  • Perform cybersecurity risk assessments of IT/OT assets within the R&D & Manufacturing sites.

  • Drive cybersecurity capability adoption R&D, Supply Chain, and Commercial functions to secure assets and enable safe & secure reliability and innovation.

  • Provide tailored security guidance (based on risk and complexity) - Interpret & apply the internal security requirements and standards for unique IT & OT (Operational Technology) initiatives.

  • Lead the cyber operational portfolio from identification > driving remediation plan > completion partnering across ISRM, business, and technology teams.

  • Establish data analytics to provide security posture across EP & NV business units, functions, and sites.

  • Proactively promote the importance of cybersecurity shared responsibility across the sector and sites through advancing cyber awareness program.

  • Assist the Security Operations Center (SOC) with security incident investigation activities; work closely with business teams to support affected users and provide liaison with central investigation team.

  • Drive business understanding of critical cybersecurity regulations and ensuring solutions are compliant (NIST, NIS2, Safe Data, etc.).

  • Support the global deployment of security initiatives with awareness sessions, identify alternative ways of working to avoid business disruptions, and review exception requests.

  • Provide audit support as the liaison between audit, technology, and business functions from pre-work to remediation plans.

 

Qualifications and Requirements:

  • 8+ years of direct or supporting experience in cybersecurity leadership and execution roles, with a background in Research & Development and Commercial environments, required.

  • Bachelor’s degree in computer science, information technology, business administration, or another rigorous discipline required; MBA preferred.

  • 6+ years of hands-on experience delivering technology and cybersecurity design capabilities across IT and OT environments, including firewalls, network intrusion detection systems, backup, and recovery, required.

  • Experience with security standards such as ISO 27001, HITRUST, and NIST required.

  • Cybersecurity, audit, or risk management certifications such as CISM, CISSP, ISA/IEC 62443, CISA, or CRISC preferred.

  • Excellent communication and collaboration skills, with the ability to network, engage, and influence across all organizational levels, sectors, functions, and regions.

  • Strategic mindset to develop capability roadmaps that strengthen proactive reliability through data and automation.

  • Experience with cloud security platforms such as AWS, Azure, or Salesforce required.

  • Experience securing multiple layers of enterprise architecture, including data, applications, hosts, middleware, networks, and infrastructure.

  • Strong understanding of current security threats, mitigation strategies, and security vendors and technologies.

  • Strong understanding of security data protection and related capabilities in R&D labs, clinical, and regulatory environments required.

  • Direct or supporting experience with application security required; Sarbanes-Oxley compliance and audit experience required.

  • Understanding of ISA/IEC 62443, NIST 800-53, and NIST 800-82 required.

  • Experience leading diverse team members with varying cybersecurity expertise, including resource allocation and planning to meet business needs.

  • Ability to balance strategic perspective with attention to detail to align tactical and long-term security priorities.

  • Ability to collaborate, build networks, and influence globally across sectors, functions, and organizational levels while establishing credibility as an inspiring cybersecurity leader.

Required Skills:



Preferred Skills:

Business Process Design, Collaboration, Crisis Management, Critical Thinking, Cyber Threat Intelligence, Developing Others, Inclusive Leadership, Information Security Auditing, Information Security Management System (ISMS), Information Technology (IT) Security Assessments, Information Technology Strategies, Leadership, Managing Managers, People Performance Management, Presentation Design, Process Optimization, Security Architecture Design, Security Policies

The anticipated base pay range for this position is :

Additional Description for Pay Transparency:

Skills Required

  • 8+ years direct or supporting experience in cybersecurity leadership and execution roles in R&D and commercial environments
  • Bachelor's degree in computer science, information technology, business administration, or related discipline
  • MBA
  • 6+ years hands-on experience delivering cybersecurity design capabilities across IT and OT, including firewalls, network IDS, backup and recovery
  • Experience with ISO 27001, HITRUST, and NIST frameworks
  • Cybersecurity, audit, or risk certifications (CISM, CISSP, ISA/IEC 62443, CISA, CRISC)
  • Experience with cloud security platforms such as AWS, Azure, or Salesforce
  • Experience securing multiple layers of enterprise architecture (data, applications, hosts, middleware, networks, infrastructure)
  • Direct or supporting experience with application security and Sarbanes-Oxley (SOX) compliance and audit
  • Understanding of ISA/IEC 62443, NIST 800-53, and NIST 800-82
  • Strong understanding of security data protection and related capabilities in R&D labs, clinical, and regulatory environments
  • Excellent communication, collaboration, and ability to influence across organizational levels and regions
  • Experience leading diverse cybersecurity team members, including resource allocation and planning
  • Strategic mindset to develop capability roadmaps and use data/automation to strengthen security posture

Johnson & Johnson Compensation & Benefits Highlights

The following summarizes recurring compensation and benefits themes identified from responses generated by popular LLMs to common candidate questions about Johnson & Johnson and has not been reviewed or approved by Johnson & Johnson.

  • Healthcare Strength Healthcare coverage is characterized as comprehensive across medical, dental, and vision, with added supports like onsite clinics, fitness centers, and Employee Assistance resources. Mental-health services and wellbeing reimbursements are also described as meaningful components of the overall package.
  • Retirement Support Retirement offerings are portrayed as a major differentiator, combining a 401(k) with employer matching and an employer-funded pension plan. Stock options and other long-term financial supports are also positioned as part of the broader rewards mix.
  • Parental & Family Support Family-related benefits are presented as notably strong, including paid parental leave for all new parents and additional leave types for caregiving and bereavement. Financial assistance for adoption, fertility treatment, and surrogacy is highlighted as a significant support.

Johnson & Johnson Insights

Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
HQ: New Brunswick, NJ
143,612 Employees
Year Founded: 1886

What We Do

Profound Change Requires Boldness. Johnson & Johnson is the largest and most broadly based healthcare company in the world. We’re producing life-changing breakthroughs every day, and have been for the last 130 years. The combination of new technologies and your expertise enables amazing things to happen. Teams from J&J’s consumer business are creating digital tools to help people track the health of their skin. Those working in medical devices are 3-D printing artificial joints personalized for each patient, while researchers in pharmaceuticals use AI to discover lifesaving drugs. Imagine what the rest of our team of 134,000 people at 260 companies in more than 60 countries across the world is accomplishing. We redefine what it means to be a big company in today’s world. Social Media Community Guidelines: http://www.jnj.com/social-media-community-guidelines

Similar Jobs

Johnson & Johnson Logo Johnson & Johnson

Senior Manager MedTech Cybersecurity

Healthtech • Biotech • Pharmaceutical • Manufacturing
In-Office
2 Locations
143612 Employees

Revivn Logo Revivn

Human Resources Generalist

Greentech • Information Technology • Social Impact • Software
Easy Apply
In-Office
Fresno, CA, USA
120 Employees
70K-80K Annually

Beyond Finance Logo Beyond Finance

Application Security Engineer

Fintech • Financial Services
Easy Apply
Remote or Hybrid
United States
2200 Employees
160K-195K Annually

MongoDB Logo MongoDB

Staff Engineer

Big Data • Cloud • Software • Database
Easy Apply
Remote or Hybrid
United States
5550 Employees
151K-297K Annually

Similar Companies Hiring

Fortune Brands Innovations Thumbnail
Manufacturing
Deerfield, IL
10000 Employees
OneImaging Thumbnail
Healthtech
Miami, FL
62 Employees
Amalgamated Sugar Thumbnail
Food • Greentech • Agriculture • Industrial • Manufacturing
Boise, Idaho
768 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account