Sr. Director, GRC, IT Controls & Cyber Culture, Orthopedics
Listed on 2026-07-22
-
IT/Tech
Cybersecurity
At Johnson & Johnson, we believe health is everything. Our strength in healthcare innovation empowers us to build a world where complex diseases are prevented, treated, and cured, where treatments are smarter and less invasive, and solutions are personal. Through our expertise in Innovative Medicine and Med Tech, we are uniquely positioned to innovate across the full spectrum of healthcare solutions today to deliver the breakthroughs of tomorrow, and profoundly impact health for humanity.
Learn more at
Technology Enterprise Strategy & Security
Job Sub FunctionSecurity & Controls
Job CategoryPeople Leader
All Job Posting LocationsPalm Beach Gardens, Florida, United States of America;
Raritan, New Jersey, United States of America;
Raynham, Massachusetts, United States of America;
Warsaw, Indiana, United States of America;
West Chester, Pennsylvania, United States of America.
DePuy Synthes is recruiting for a Sr. Director, GRC, IT Controls and Cyber Culture.
Johnson & Johnson announced plans to separate our Orthopedics business to establish a standalone orthopedics company, operating as DePuy Synthes. The process of the planned separation is anticipated to be completed within 18 to 24 months, subject to legal requirements, including consultation with works councils and other employee representative bodies, regulatory approvals and other customary conditions.
Should you accept this position, it is anticipated that, following conclusion of the transaction, you would be an employee of DePuy Synthes and your employment would be governed by DePuy Synthes employment processes, programs, policies, and benefit plans. Details of any planned changes would be provided to you by DePuy Synthes at an appropriate time and subject to any necessary consultation processes.
JobOverview
This role serves as a senior cybersecurity leader reporting to the CISO, with enterprise accountability for building, maturing, and operationalizing the Governance, Risk & Compliance (GRC) function across DePuy Synthes. The Sr. Director will oversee the BISO manager organization, establish scalable risk governance practices, strengthen security awareness and behavior based culture programs, and drive implementation of IT controls and an enterprise assurance framework.
The role will also oversee external cybersecurity assessments and disclosures, including cyber insurance, ESG‑related cybersecurity inputs, and other third‑party assurance activities. This highly visible leadership role will help ensure cybersecurity risk, compliance, control effectiveness, and cultural adoption are consistently managed across the enterprise in support of business priorities, regulatory expectations, and organizational resilience.
- Build and mature the enterprise GRC function, including governance forums, risk management processes, compliance oversight, control monitoring, issue management, and executive reporting.
- Provide leadership and oversight for the BISO manager organization, ensuring consistent engagement with business leaders, effective cyber risk advisory support, and alignment of security priorities to business objectives.
- Lead enterprise cyber risk management activities, including risk identification, assessment, mitigation planning, escalation, and reporting to senior leadership and governance bodies.
- Own the enterprise cybersecurity policy and standards lifecycle – from creation and implementation to continuous review – ensuring clarity, compliance, and alignment with organizational goals.
- Oversee SOX cybersecurity and IT control activities, including implementation, operating effectiveness, evidence readiness, remediation tracking, and partnership with Finance, Internal Audit, External Audit, and IT control owners.
- Establish and operationalize an enterprise IT controls and assurance framework that enables consistent control design, testing, monitoring, reporting, and continuous improvement across the organization.
- Lead oversight of external cybersecurity assessments and assurance requests, including cyber insurance questionnaires, ESG‑related cybersecurity inputs, customer or partner assessments, and…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).