Johnson & Johnson logo

Professional, Compliance Lead

Johnson & Johnson
  • New Brunswick, NJ
  • Autofill and Review
6 days ago

Job Description

At Johnson & Johnson, we believe health is everything. Our strength in healthcare innovation empowers us to build a world where complex diseases are prevented, treated, and cured, where treatments are smarter and less invasive, and solutions are personal. Through our expertise in Innovative Medicine and MedTech, we are uniquely positioned to innovate across the full spectrum of healthcare solutions today to deliver the breakthroughs of tomorrow, and profoundly impact health for humanity. Learn more at jnj.com.

As guided by Our Credo, Johnson & Johnson is responsible to our employees who work with us throughout the world. We provide an inclusive work environment where each person is considered as an individual. At Johnson & Johnson, we respect the diversity and dignity of our employees and recognize their merit.

Job Function:

Technology Enterprise Strategy & Security

Job Sub Function:

Security & Controls

Job Category:

Scientific/Technology

All Job Posting Locations:

New Brunswick, New Jersey, United States of America

Job Description:

DePuy Synthes is recruiting for a Professional, Compliance Lead, located in Raritan, New Jersey or West Chester, Pennsylvania or Palm Beach Gardens, Florida or Raynham, Massachusetts or Warsaw, Indiana.

  • Join our change journey at J&J-help shape what's next
  • Step into a high-impact career opportunity with real visibility

THE OPPORTUNITY

The Professional, Compliance Lead is a seasoned individual contributor within the Cybersecurity function, GRC, IT Controls & Cyber Culture sub-function, accountable for leading the cybersecurity compliance and governance agenda across DePuy Synthes. This role owns the policy and standards framework, sets the enterprise cyber risk methodology, leads risk assessments and register governance, and drives the reporting cadence that informs executive and Board-level decision-making. The Compliance Lead directs third-party risk oversight, defines the metrics and KRI model that measures program health, and serves as the primary liaison to Internal Audit, Legal, Privacy, Quality, and external regulators. Applying advanced knowledge of GRC frameworks and regulatory obligations, this role establishes best-in-class policies, procedures, and plans for the area.

RESPONSIBILITIES

  • Lead the cybersecurity policy and standards program end to end - setting the governance lifecycle, approving content, driving annual review and attestation, and adjudicating exceptions and risk acceptances.
  • Define and maintain the enterprise cyber risk framework and methodology, including risk taxonomy, scoring model, risk appetite and tolerance statements, and escalation thresholds.
  • Direct the cyber risk assessment program across applications, infrastructure, business processes, and major change initiatives; ensure consistency of method, quality of output, and traceability of results.
  • Own governance of the enterprise cyber risk register - enforcing data quality, ownership accountability, aging discipline, and timely escalation of elevated or overdue risks to leadership.
  • Chair and orchestrate cybersecurity governance forums, setting agendas, framing decisions, documenting outcomes, and holding owners accountable for committed actions.
  • Build and deliver the executive reporting model - translating aggregated risk, control, and compliance data into concise business-impact narratives for CIO, CISO, and senior leadership audiences.
  • Define, baseline, and operationalize cyber risk metrics and Key Risk Indicators (KRIs), establishing thresholds, trend analysis, and predictive signals that drive proactive intervention.
  • Lead third-party cyber risk oversight - setting the vendor tiering model, assessment standards, contractual security requirements, and continuous monitoring approach for critical aand high-risk suppliers.
  • Maintain the regulatory and framework mapping library (NIST CSF, ISO 27001, HIPAA, GDPR, FDA cybersecurity guidance, SOX ITGC), rationalizing overlapping requirements to reduce duplicate control effort.
  • Partner with the IT Controls and SOX teams to align governance requirements with control design and testing, ensuring a coherent and non-duplicative assurance landscape.
  • Serve as the primary point of contact for Internal Audit, external auditors, regulators, and customer security assessments - coordinating evidence, responses, and issue remediation.
  • Assess and govern the compliance impact of major technology change, including cloud migrations, ERP and platform implementations, and separation/carve-out activity, defining requirements prior to go-live.
  • Drive the cyber culture and awareness agenda - shaping policy communications, training strategy, and targeted enablement to strengthen accountability and risk-aware behavior enterprise-wide.
  • Identify and lead automation opportunities across GRC workflows, evidence collection, and reporting to improve efficiency, data integrity, and program scalability.

ABOUT YOU:

Required:

  • 6 years of progressive experience in cybersecurity governance, IT risk management, technology compliance, or a related GRC discipline.
  • Demonstrated ownership of a security policy and standards framework, including authorship, governance lifecycle, exception management, and stakeholder approval.
  • Advanced working knowledge of NIST CSF, NIST 800-53, ISO 27001/27002, and COBIT, with the ability to rationalize requirements across multiple frameworks.
  • Proven experience designing and operating a cyber risk assessment methodology and enterprise risk register at scale.
  • Experience defining KRIs and building executive-level risk reporting that drives leadership decisions.
  • Experience leading third-party/vendor cyber risk programs, including assessment standards, SOC 2 / ISO evidence review, and contractual security requirements.
  • Strong facilitation and influencing skills, with a track record of driving accountability across senior stakeholders without direct authority.

Preferred:

  • MedTech, Life Sciences, or other regulated industry background; working knowledge of HIPAA, GDPR, and FDA medical device cybersecurity expectations.
  • Experience standing up or maturing a GRC function within a divestiture, carve-out, spin-off, or standalone entity.
  • Hands-on experience with GRC platforms (e.g., ServiceNow IRM, Archer, OneTrust, AuditBoard), including workflow design and reporting configuration.
  • Experience coordinating directly with external auditors, regulators, or major customer security assessment programs.
  • Familiarity with cloud governance (AWS, Azure) and control expectations for SaaS and cloud-hosted environments.
  • Proficiency with data visualization and analytics tools (Power BI, Tableau, SQL) for risk metrics and executive dashboards.
  • Experience applying Generative AI / LLM-enabled tooling to accelerate policy drafting, control mapping, and third-party assessment review.
  • Experience designing and scaling security awareness and cyber culture programs.

Other:

  • Travel: Up to 15% domestic travel expected across DePuy Synthes sites.
  • Language: English proficiency required.
  • Certifications: CISSP, CRISC, CISM, or CISA required or in progress. CGRC, ISO 27001 Lead Implementer/Auditor, or CIPP preferred.

Johnson & Johnson announced plans to separate our Orthopedics business to establish a standalone orthopedics company, operating as DePuy Synthes. The process of the planned separation is anticipated to be completed within 18 to 24 months, subject to legal requirements, including consultation with works councils and other employee representative bodies, as may be required, regulatory approvals and other customary conditions and approvals. Should you accept this position, it is anticipated that, following conclusion of the transaction, you would be an employee of DePuy Synthes and your employment would be governed by DePuy Synthes employment processes, programs, policies, and benefit plans. In that case, details of any planned changes would be provided to you by DePuy Synthes at an appropriate time and subject to any necessary consultation processes.

Johnson & Johnson is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, age, national origin, disability, protected veteran status or other characteristics protected by federal, state or local law. We actively seek qualified candidates who are protected veterans and individuals with disabilities as defined under VEVRAA and Section 503 of the Rehabilitation Act.

Johnson & Johnson is committed to providing an interview process that is inclusive of our applicants' needs. If you are an individual with a disability and would like to request an accommodation, external applicants please contact us via https://www.jnj.com/contact-us/careers, internal employees contact AskGS to be directed to your accommodation resource.

#LI-Hybrid

#DePuySynthesCareers

Required Skills:

Preferred Skills:

Communication, Corrective and Preventive Action (CAPA), Critical Thinking, Information Security Auditing, Information Security Management System (ISMS), Information Technology (IT) Security Assessments, Information Technology Strategies, Mentorship, Network Optimization, Presentation Design, Process Optimization, Report Writing, Security Policies, Technical Credibility, Technologically Savvy, Training People, Vulnerability Assessments

Numbers & Facts

LocationNew Brunswick, NJ
IndustryHealthcare Services
Company Size10,000 employees or more
Year Founded1887
Websitehttp://www.jnj.com/

About Company

Caring for the world, one person at a time... inspires and unites the people of Johnson & Johnson. We embrace research and science - bringing innovative ideas, products and services to advance the health and well-being of people. Employees of the Johnson & Johnson Family of Companies work with partners in health care to touch the lives of over a billion people every day, throughout the world.

Our Family of Companies comprises: The world’s sixth-largest consumer health company.
The world’s most comprehensive medical devices business.
The world’s sixth-largest biologics company.
And the world’s fifth-largest pharmaceuticals company.

We have more than 265 operating companies in more than 60 countries employing approximately 126,500 people. Our worldwide headquarters is in New Brunswick, New Jersey, USA.

Skills

  • Adjudicationunmatched
  • Amazon Web Services (AWS)unmatched
  • Artificial Intelligence (AI)unmatched
  • Auditingunmatched
  • Automationunmatched
  • Biologyunmatched
  • Business Processesunmatched
  • CISA - Certified Information Systems Auditorunmatched
  • CISM - Certified Information Security Managerunmatched
  • CISSP - Certified Information Systems Security Professionalunmatched
  • Cadenceunmatched
  • Cloud Computingunmatched
  • Compensation and Benefitsunmatched
  • Computer Securityunmatched
  • Contract Requirementsunmatched
  • Contract Reviewunmatched
  • Control Objectives for Information and related Technology (COBIT)unmatched
  • Corrective Actionunmatched
  • Corrective and Preventative Action (CAPA) Systemsunmatched
  • Data Analysisunmatched
  • Data Qualityunmatched
  • Data Visualization Toolsunmatched
  • Disease Prevention and Controlunmatched
  • Diversityunmatched
  • Documentationunmatched
  • ERP (Enterprise Resource Planning)unmatched
  • English Languageunmatched
  • Enterprise Protectionunmatched
  • External Auditunmatched
  • FDA (Food and Drug Administration)unmatched
  • HIPAA (Health Insurance Portability and Accountability Act)unmatched
  • Healthcareunmatched
  • ISO (International Organization for Standardization)unmatched
  • IT Governanceunmatched
  • Information Technology & Information Systemsunmatched
  • Information/Data Security (InfoSec)unmatched
  • Internal Auditunmatched
  • Internet Securityunmatched
  • Leadershipunmatched
  • Legalunmatched
  • Machine Toolunmatched
  • Medical Equipmentunmatched
  • Medicineunmatched
  • Mentoringunmatched
  • Metricsunmatched
  • Microsoft Windows Azureunmatched
  • Orthopedicsunmatched
  • Policy Developmentunmatched
  • Power BIunmatched
  • Process Improvementunmatched
  • Program Evaluationunmatched
  • Regulationsunmatched
  • Regulatory Requirementsunmatched
  • Reporting Dashboardsunmatched
  • Reporting Skillsunmatched
  • Requirements Managementunmatched
  • Riskunmatched
  • Risk Analysisunmatched
  • Risk Managementunmatched
  • Risk Modelingunmatched
  • SQL (Structured Query Language)unmatched
  • Sarbanes-Oxley Act (SOX)unmatched
  • Security Analysisunmatched
  • Security Auditingunmatched
  • Security Monitoringunmatched
  • Security Policyunmatched
  • ServiceNowunmatched
  • Software as a Service (SaaS)unmatched
  • Tableauunmatched
  • Taxonomiesunmatched
  • Technical Strategyunmatched
  • Test Designunmatched
  • Time Managementunmatched
  • Traceabilityunmatched
  • Trend Analysisunmatched
  • U.S. National Institute of Standards and Technology (NIST)unmatched
  • Web Analyticsunmatched
  • Web Application Frameworkunmatched
  • Willing to Travelunmatched

Be found by employers

5,500+ employers search our resume database daily. Add yours to get found by recruiters looking for candidates like you.

Level up your application

Professional resume templates

Browse dozens of recruiter approved resume templates, layouts and formats. Choose your favorite and make it your own in minutes.

Free resume templates

Free resume builder

Improve your existing resume or start from scratch and create a standout, ATS-friendly resume. Add job-specific content, download and apply.

Free resume builder