Senior Manager, Supply Chain Cybersecurity (IT and OT), APAC

Sorry, this job was removed at 10:12 a.m. (CST) on Thursday, Dec 25, 2025
Be an Early Applicant
4 Locations
In-Office
Healthtech • Pharmaceutical • Manufacturing
The Role

At Johnson & Johnson, we believe health is everything. Our strength in healthcare innovation empowers us to build a world where complex diseases are prevented, treated, and cured, where treatments are smarter and less invasive, and solutions are personal. Through our expertise in Innovative Medicine and MedTech, we are uniquely positioned to innovate across the full spectrum of healthcare solutions today to deliver the breakthroughs of tomorrow, and profoundly impact health for humanity. Learn more at https://www.jnj.com

Job Function:

Technology Enterprise Strategy & Security

Job Sub Function:

Security & Controls

Job Category:

People Leader

All Job Posting Locations:

Beijing, China, Shanghai, China, Singapore, Singapore, Suzhou, Jiangsu, China

Job Description:

Sr. Manager, Supply Chain Cybersecurity (IT and OT) - ASPAC

Johnson & Johnson is currently seeking a Senior Manager in the Information Security & Risk Management (ISRM) organization supporting the MedTech Supply Chain – ASPAC. This position can be based in China or Singapore.

This candidate will have a diverse background with strong business acumen, technology, and security expertise. They will be a strategic thinker who leads with impact inclusively, driving intentional change proactively, and be driven to keep up with industry trends in cybersecurity.  This role will embed directly with our J&J Technology and MedTech Supply Chain teams providing the security posture and the end-to-end security portfolio/capability roadmap to improve, identify, and remediate cyber security vulnerabilities.

You will work across ISRM demonstrating authentic leadership, driving results, and showing dedication to our Credo. Your scope includes regional cyber security responsibility for MedTech Manufacturing sites, Distribution sites (Internal and External / 3PL), Application Security, and Third-Party Risk Management.

Responsibilities:

  • Champion a Secure-by-Design approach with stakeholders to embed security capabilities and services within business initiatives.

  • Perform cybersecurity risk assessments of IT and OT assets within the manufacturing and distribution sites.

  • Drive the OT cybersecurity capability adoption across sites to secure IT and OT assets and enable safe & secure innovation.

  • Provide tailored security guidance (based on risk and complexity) by interpreting and applying the internal cybersecurity policy requirements and standards for innovative IT and OT initiatives.

  • Partner with security, business, and technology teams to identify, assist with the creation of mitigation and remediation plans, and track the closure of cybersecurity risks.

  • Provide regular cybersecurity posture updates to business, function, site leadership and regional teams.

  • Create site-specific cybersecurity roadmaps to provide input into the cybersecurity business planning process and improve the cybersecurity posture of the sites

  • Promote the importance of cybersecurity across the region and sites.

  • Assist the Security Operations Center (SOC) with security incident investigation activities; work closely with business teams to support affected users and be the liaison with central investigation teams.

  • Drive business understanding of critical cybersecurity regulations and ensuring solutions are compliant (CPC, NIST, NIS2, Safe Data, Zero Trust, etc.).

  • Support the global deployment of security initiatives with awareness sessions, identify alternative ways of working to avoid business disruptions, and review exception requests

  • Provide audit support as the liaison between corporate audit functions from pre-work to consulting remediation plans.

  • Interpret gaps identified by the Third-Party Risk Management team and collaborate with business and technology stakeholders to ensure vendors remediate the gaps identified.

  • Enhance Application Security used within the region by interpreting internal security and regulatory requirements such as Sarbanes–Oxley (SOX), Payment Card Industry (PCI), Health Insurance Portability and Accountability Act (HIPAA), European Union Network and Information Security 2 (NIS2), China's Cybersecurity Law (CSL), etc.

Qualifications: 

  • 8+ years of related experience in leadership and execution roles within Cybersecurity or Risk Management with background in Supply Chain required.

  • Bachelor’s degree in computer science, information technology, business administration, or another rigorous discipline is required. MBA preferred.

  • 6+ years of hands-on experience in delivering technology; and cybersecurity design and capabilities required.

  • Direct working and/or supporting experience of Supply Chain applications and China Cybersecurity Law compliance is required.

  • Understanding of IEC 62443, NIST 800-53, and 800-82 required.

  • Ability to independently complete tasks accurately and thoroughly is required.

  • Strong understanding of security data protection and capabilities in a manufacturing and/or distribution site is required.

  • Excellent communication and collaboration skills, able to network, interface and influence at all levels of the organization, cross-functionally and globally, establishing oneself as an inspiring leader with expertise in space.

  • Certifications in cybersecurity (CISM, CISSP, GICSP, ISA-62443), audit (CISA), manufacturing, or risk management (CRISC) are preferred.

  • Strategic mindset to develop capability roadmaps that will enable proactive reliability through data & automation.

  • Experience in working/securing various levels of enterprise architecture (data, application, host, middleware, network, Infrastructure).

  • Solid understanding of current security threats, mitigation measures, and security vendors/technologies.

  • Leading diverse team members with varying cybersecurity experience and proficient in resource allocation and planning to meet business needs.

  • Big picture perspective and attention to detail focus to align strategic and tactical security aspects.



Required Skills:



Preferred Skills:

Johnson & Johnson Compensation & Benefits Highlights

The following summarizes recurring compensation and benefits themes identified from responses generated by popular LLMs to common candidate questions about Johnson & Johnson and has not been reviewed or approved by Johnson & Johnson.

  • Healthcare Strength Healthcare coverage is characterized as comprehensive across medical, dental, and vision, with added supports like onsite clinics, fitness centers, and Employee Assistance resources. Mental-health services and wellbeing reimbursements are also described as meaningful components of the overall package.
  • Retirement Support Retirement offerings are portrayed as a major differentiator, combining a 401(k) with employer matching and an employer-funded pension plan. Stock options and other long-term financial supports are also positioned as part of the broader rewards mix.
  • Parental & Family Support Family-related benefits are presented as notably strong, including paid parental leave for all new parents and additional leave types for caregiving and bereavement. Financial assistance for adoption, fertility treatment, and surrogacy is highlighted as a significant support.

Johnson & Johnson Insights

Similar Jobs

Cloudflare Logo Cloudflare

Account Executive

Cloud • Information Technology • Security • Software • Cybersecurity
Hybrid
Beijing, CHN
4400 Employees

Ericsson Logo Ericsson

Account Manager

Cloud • Information Technology • Internet of Things • Machine Learning • Software • Cybersecurity • Infrastructure as a Service (IaaS)
In-Office
Beijing, CHN
88000 Employees

Ericsson Logo Ericsson

Design Engineer

Cloud • Information Technology • Internet of Things • Machine Learning • Software • Cybersecurity • Infrastructure as a Service (IaaS)
In-Office
Beijing, CHN
88000 Employees

Ericsson Logo Ericsson

Software Engineer

Cloud • Information Technology • Internet of Things • Machine Learning • Software • Cybersecurity • Infrastructure as a Service (IaaS)
In-Office
Beijing, CHN
88000 Employees
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
HQ: New Brunswick, NJ
143,612 Employees
Year Founded: 1886

What We Do

Profound Change Requires Boldness. Johnson & Johnson is the largest and most broadly based healthcare company in the world. We’re producing life-changing breakthroughs every day, and have been for the last 130 years. The combination of new technologies and your expertise enables amazing things to happen. Teams from J&J’s consumer business are creating digital tools to help people track the health of their skin. Those working in medical devices are 3-D printing artificial joints personalized for each patient, while researchers in pharmaceuticals use AI to discover lifesaving drugs. Imagine what the rest of our team of 134,000 people at 260 companies in more than 60 countries across the world is accomplishing. We redefine what it means to be a big company in today’s world. Social Media Community Guidelines: http://www.jnj.com/social-media-community-guidelines

Similar Companies Hiring

Granted Thumbnail
Mobile • Insurance • Healthtech • Financial Services • Artificial Intelligence
New York, New York
23 Employees
Fortune Brands Innovations Thumbnail
Manufacturing
Deerfield, IL
2450 Employees
Amalgamated Sugar Thumbnail
Food • Greentech • Agriculture • Industrial • Manufacturing
Boise, Idaho
768 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account