Sr. Manager, IT Control, Assurance & SOX

Posted 8 Hours Ago
Be an Early Applicant
5 Locations
In-Office
122K-245K Annually
Senior level
Healthtech • Biotech • Pharmaceutical • Manufacturing
The Role
Lead design, execution, and continuous improvement of enterprise IT controls, assurance, and SOX programs across ERP, cloud, SaaS, and infrastructure. Manage ITGCs, automated controls, third-party assurance, audit coordination, remediation, GRC tooling, compliance (SOX, HIPAA, GDPR), reporting to executives, and build/lead a global team to ensure audit-ready operations for the standalone DePuy Synthes entity.
Summary Generated by Built In

At Johnson & Johnson, we believe health is everything. Our strength in healthcare innovation empowers us to build a world where complex diseases are prevented, treated, and cured, where treatments are smarter and less invasive, and solutions are personal. Through our expertise in Innovative Medicine and MedTech, we are uniquely positioned to innovate across the full spectrum of healthcare solutions today to deliver the breakthroughs of tomorrow, and profoundly impact health for humanity. Learn more at jnj.com

As guided by Our Credo, Johnson & Johnson is responsible to our employees who work with us throughout the world.  We provide an inclusive work environment where each person is considered as an individual.  At Johnson & Johnson, we respect the diversity and dignity of our employees and recognize their merit.

Job Function:

Technology Enterprise Strategy & Security

Job Sub Function:

Security & Controls

Job Category:

People Leader

All Job Posting Locations:

New Brunswick, New Jersey, United States of America, Palm Beach Gardens, Florida, United States of America, Raynham, Massachusetts, United States of America, Warsaw, Indiana, United States of America, West Chester, Pennsylvania, United States of America

Job Description:

DePuy Synthes is recruiting for a(n) Sr. Manager, IT Controls, Assurance & SOX  located in New Brunswick, NJ or Palm Beach Gardens, FL or Warsaw, IN or West Chester, PA or Raynham, MA.

This role leads the design, execution, and continuous improvement of DePuy Synthes' IT controls, assurance, and (SOX) program within the Governance & Risk function of Cybersecurity. The Sr. Manager will own the enterprise IT SOX control framework, IT general controls (ITGCs), automated application controls, and IT-related assurance activities across financially relevant systems, cloud platforms, and third-party services. This position partners closely with Finance, Internal Audit, External Auditors, Application Owners, and Infrastructure teams to ensure a strong control environment, timely remediation of deficiencies, and audit-ready operations as the company stands up as an independent, publicly traded entity. 

Key Responsibilities 

IT Controls & Assurance  

  • Own the enterprise IT control framework — including ITGCs (access, change, operations), automated application controls, and IT-dependent business controls — aligned to COBIT, COSO, NIST CSF, and internal policies  

  • Lead design and operating effectiveness assessments of IT controls across ERP, cloud, SaaS, and infrastructure platforms, and drive remediation of identified gaps  

  • Partner with application, cloud, and infrastructure teams to embed preventive and detective controls by design in the SDLC, DevOps pipelines, and cloud landing zones  

  • Extend the assurance program to third parties and managed service providers, including review of SOC 1/SOC 2 reports, complementary user entity controls (CUECs), and bridge letters  

  • Serve as the primary IT liaison for Internal Audit, External Auditors, and regulatory examiners — coordinating walkthroughs, evidence, testing, and management responses  

  • Advance continuous controls monitoring (CCM), analytics, and automation to expand control coverage and reduce manual testing effort  

SOX  

  • Own the end-to-end IT SOX program — scoping, risk assessment, control design, management testing, deficiency evaluation, and reporting across in-scope financial systems and supporting IT infrastructure  

  • Define the annual IT SOX plan in partnership with Finance, Internal Audit, and External Auditors, including in-scope applications, ITGCs, key reports, and automated controls  

  • Lead management testing of ITGCs and IT-dependent business controls, ensuring timely completion, quality of evidence, and consistent workpaper standards  

  • Drive deficiency evaluation, root cause analysis, remediation planning, and status reporting to leadership and the Audit Committee  

  • Stand up and operate the first-year SOX program for the standalone DePuy Synthes entity, including RCMs, narratives, and control ownership across the new operating model  

  • Modernize the SOX program through GRC tooling (e.g., ServiceNow IRM, AuditBoard, Archer), risk-based sampling, and automated evidence collection  

Compliance  

  • Lead IT compliance activities across applicable regulatory, contractual, and internal policy requirements — including SOX, SEC, GxP, HIPAA, GDPR, and other data protection and industry regulations  

  • Maintain an integrated IT policy, standard, and control library, and drive alignment across Cybersecurity, IT, Legal, Privacy, and Compliance functions  

  • Track regulatory change, assess IT impact, and update controls, policies, and evidence to keep the environment continuously compliant  

  • Coordinate IT responses to customer, partner, and regulator due diligence requests, security questionnaires, and certification programs (e.g., ISO 27001, HITRUST where applicable)  

  • Assess compliance implications of emerging technologies (cloud, AI/ML, GenAI, automation) and update the control and compliance framework accordingly  

  • Provide training, guidance, and clear escalation paths to IT and business control owners to reinforce a strong compliance culture  

Governance, Reporting & Team Leadership  

  • Provide regular reporting to the CISO, Director of Governance & Risk, Finance leadership, and the Audit Committee on IT controls, SOX status, and compliance posture  

  • Support Day-1 readiness and post-separation BAU operations for controls, assurance, SOX, and compliance across the standalone DePuy Synthes environment  

  • Build, lead, and develop a global team across the US and the GCC in India, and manage co-source/outsourced testing partners for quality, consistency, and efficiency  

  • Coach and mentor team members, fostering technical depth, audit acumen, and strong business partnership skills 

Qualifications 

Education: 

  • Bachelor's degree in Computer Science, Information Security, Business, Engineering, or a related field (required). 

  • Master's degree in Cybersecurity, Information Systems, or Business Administration (preferred). 

Experience and Skills: 

Required: 

  • 10+ years of experience in IT audit, IT controls, SOX, or IT compliance, including experience in a Big 4 or large public company environment  

  • Deep expertise across all three capability areas: IT Controls & Assurance, SOX (ITGCs and IT-dependent business controls), and IT Compliance  

  • Strong working knowledge of control and compliance frameworks — COBIT, COSO, NIST CSF, ISO 27001, and SOC 1/SOC 2  

  • Proven experience coordinating with External Auditors, Internal Audit, and business process owners on complex, multi-entity audits  

  • Demonstrated ability to evaluate control deficiencies, drive remediation, and communicate risk and compliance status to executive stakeholders  

  • Experience assessing IT controls and compliance in cloud environments (AWS, Azure, GCP) and across ERP and SaaS platforms  

  • Strong leadership, stakeholder management, and cross-functional collaboration skills, including managing global and co-sourced teams 

Preferred: 

  • Experience supporting a separation, spin-off, IPO, or standalone company standing up its first-year SOX and compliance program  

  • Familiarity with SAP S/4HANA, Workday, Oracle, or other ERP platforms and their control configurations  

  • Experience with GRC platforms (e.g., ServiceNow IRM, AuditBoard, Archer) and continuous controls monitoring / audit analytics  

  • Background in healthcare, MedTech, pharmaceuticals, or other highly regulated industries  

  • Familiarity with regulatory and privacy requirements relevant to IT — SOX, SEC, GxP, HIPAA, GDPR, and emerging AI regulations 

Other: 

  • Language: English proficiency required  

  • Travel: Up to 15% domestic and international travel  

  • Certifications (preferred): CISA, CPA, CIA, CISSP, or equivalent 

For more information on how we support the whole health of our employees throughout their wellness, career and life journey, please visit www.careers.jnj.com.

Johnson & Johnson announced plans to separate our Orthopaedics business to establish a standalone orthopaedics company, operating as DePuy Synthes. The process of the planned separation is anticipated to be completed within 18 to 24 months, subject to legal requirements, including consultation with works councils and other employee representative bodies, as may be required, regulatory approvals and other customary conditions and approvals. Should you accept this position, it is anticipated that, following conclusion of the transaction, you would be an employee of DePuy Synthes and your employment would be governed by DePuy Synthes employment processes, programs, policies, and benefit plans. In that case, details of any planned changes would be provided to you by DePuy Synthes at an appropriate time and subject to any necessary consultation processes. 

 

 Johnson & Johnson is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, age, national origin, disability, protected veteran status or other characteristics protected by federal, state or local law. We actively seek qualified candidates who are protected veterans and individuals with disabilities as defined under VEVRAA and Section 503 of the Rehabilitation Act. 

 

Johnson & Johnson is committed to providing an interview process that is inclusive of our applicants’ needs. If you are an individual with a disability and would like to request an accommodation, external applicants please contact us via https://www.jnj.com/contact-us/careers, internal employees contact AskGS to be directed to your accommodation resource. 

 

#LI-Hybrid 

#DePuySynthesCareers 

Required Skills:



Preferred Skills:

Business Process Design, Collaboration, Crisis Management, Critical Thinking, Cyber Threat Intelligence, Developing Others, Inclusive Leadership, Information Security Auditing, Information Security Management System (ISMS), Information Technology (IT) Security Assessments, Information Technology Strategies, Leadership, Managing Managers, People Performance Management, Presentation Design, Process Optimization, Security Architecture Design, Security Policies

The anticipated base pay range for this position is :

122,000.00 - 245,000.00 USD Annual

Additional Description for Pay Transparency:

Subject to the terms of their respective plans, employees are eligible to participate in the Company’s consolidated retirement plan (pension) and savings plan (401(k)). Subject to the terms of their respective policies and date of hire, employees are eligible for the following time off benefits: • Vacation –120 hours per calendar year • Sick time - 40 hours per calendar year; for employees who reside in the State of Colorado –48 hours per calendar year; for employees who reside in the State of Washington –56 hours per calendar year • Holiday pay, including Floating Holidays –13 days per calendar year • Work, Personal and Family Time - up to 40 hours per calendar year • Parental Leave – 480 hours within one year of the birth/adoption/foster care of a child • Bereavement Leave – 240 hours for an immediate family member: 40 hours for an extended family member per calendar year • Caregiver Leave – 80 hours in a 52-week rolling period10 days • Volunteer Leave – 32 hours per calendar year • Military Spouse Time-Off – 80 hours per calendar year For additional general information on Company benefits, please go to: - https://www.careers.jnj.com/employee-benefits

Skills Required

  • Bachelor's degree in Computer Science, Information Security, Business, Engineering, or related field
  • 10+ years experience in IT audit, IT controls, SOX, or IT compliance (Big 4 or large public company experience)
  • Deep expertise across IT Controls & Assurance, SOX (ITGCs and IT-dependent business controls), and IT Compliance
  • Strong working knowledge of COBIT, COSO, NIST CSF, ISO 27001, and SOC 1/SOC 2
  • Experience coordinating with External Auditors, Internal Audit, and business process owners on complex, multi-entity audits
  • Demonstrated ability to evaluate control deficiencies, drive remediation, and communicate risk to executive stakeholders
  • Experience assessing IT controls and compliance in cloud environments (AWS, Azure, GCP) and across ERP and SaaS platforms
  • Strong leadership, stakeholder management, and cross-functional collaboration skills, including managing global and co-sourced teams
  • English proficiency
  • Master's degree in Cybersecurity, Information Systems, or Business Administration
  • Experience supporting a separation, spin-off, IPO, or standing up a first-year SOX program
  • Familiarity with SAP S/4HANA, Workday, Oracle, or other ERP platforms and control configurations
  • Experience with GRC platforms (ServiceNow IRM, AuditBoard, Archer) and continuous controls monitoring/audit analytics
  • Background in healthcare, MedTech, pharmaceuticals, or other highly regulated industries
  • Certifications such as CISA, CPA, CIA, CISSP (preferred)

Johnson & Johnson Compensation & Benefits Highlights

The following summarizes recurring compensation and benefits themes identified from responses generated by popular LLMs to common candidate questions about Johnson & Johnson and has not been reviewed or approved by Johnson & Johnson.

  • Healthcare Strength Healthcare coverage is characterized as comprehensive across medical, dental, and vision, with added supports like onsite clinics, fitness centers, and Employee Assistance resources. Mental-health services and wellbeing reimbursements are also described as meaningful components of the overall package.
  • Retirement Support Retirement offerings are portrayed as a major differentiator, combining a 401(k) with employer matching and an employer-funded pension plan. Stock options and other long-term financial supports are also positioned as part of the broader rewards mix.
  • Parental & Family Support Family-related benefits are presented as notably strong, including paid parental leave for all new parents and additional leave types for caregiving and bereavement. Financial assistance for adoption, fertility treatment, and surrogacy is highlighted as a significant support.

Johnson & Johnson Insights

Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
HQ: New Brunswick, NJ
143,612 Employees
Year Founded: 1886

What We Do

Profound Change Requires Boldness. Johnson & Johnson is the largest and most broadly based healthcare company in the world. We’re producing life-changing breakthroughs every day, and have been for the last 130 years. The combination of new technologies and your expertise enables amazing things to happen. Teams from J&J’s consumer business are creating digital tools to help people track the health of their skin. Those working in medical devices are 3-D printing artificial joints personalized for each patient, while researchers in pharmaceuticals use AI to discover lifesaving drugs. Imagine what the rest of our team of 134,000 people at 260 companies in more than 60 countries across the world is accomplishing. We redefine what it means to be a big company in today’s world. Social Media Community Guidelines: http://www.jnj.com/social-media-community-guidelines

Similar Jobs

Nourish Logo Nourish

Medical Director - Nourish Medical

Artificial Intelligence • Healthtech • Software • Telehealth
Easy Apply
In-Office or Remote
2 Locations
315 Employees

CSC Logo CSC

Tax Research & QA Intern

Fintech • Legal Tech • Software • Financial Services • Cybersecurity • Data Privacy
Remote or Hybrid
4 Locations
8500 Employees

SailPoint Logo SailPoint

Customer Success Manager

Artificial Intelligence • Cloud • Sales • Security • Software • Cybersecurity • Data Privacy
Remote or Hybrid
United States
2461 Employees
60K-101K Annually

SailPoint Logo SailPoint

Customer Success Manager

Artificial Intelligence • Cloud • Sales • Security • Software • Cybersecurity • Data Privacy
Remote or Hybrid
United States
2461 Employees
60K-101K Annually

Similar Companies Hiring

Fortune Brands Innovations Thumbnail
Manufacturing
Deerfield, IL
10000 Employees
OneImaging Thumbnail
Healthtech
Miami, FL
62 Employees
Amalgamated Sugar Thumbnail
Food • Greentech • Agriculture • Industrial • Manufacturing
Boise, Idaho
768 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account