Johnson & Johnson Logo

Johnson & Johnson

Senior Manager MedTech Cybersecurity

Posted 12 Days Ago
Be an Early Applicant
In-Office
Irvine, CA, USA
Senior level
In-Office
Irvine, CA, USA
Senior level
Lead cybersecurity for MedTech Electrophysiology and Neurovascular units across R&D, manufacturing, supply chain and commercial. Develop end-to-end security portfolio, perform IT/OT risk assessments, drive remediation and capability adoption, support SOC incident investigations, ensure regulatory compliance (NIST, NIS2, etc.), provide audit liaison, and build security awareness and analytics across global sites and vendors.
The summary above was generated by AI

At Johnson & Johnson, we believe health is everything. Our strength in healthcare innovation empowers us to build a world where complex diseases are prevented, treated, and cured, where treatments are smarter and less invasive, and solutions are personal. Through our expertise in Innovative Medicine and MedTech, we are uniquely positioned to innovate across the full spectrum of healthcare solutions today to deliver the breakthroughs of tomorrow, and profoundly impact health for humanity. Learn more at jnj.com.

As guided by Our Credo, Johnson & Johnson is responsible to our employees who work with us throughout the world. We provide an inclusive work environment where each person is considered as an individual. At Johnson & Johnson, we respect the diversity and dignity of our employees and recognize their merit.

Job Function:

Technology Enterprise Strategy & Security

Job Sub Function:

Security & Controls

Job Category:

People Leader

All Job Posting Locations:

Irvine, California, United States of America, Yokneam, Haifa District, Israel

Job Description:

About Johnson & Johnson MedTech Cardiovascular:

Fueled by innovation at the intersection of biology and technology, we’re developing the next generation of smarter, less invasive, more personalized treatments.

Are you passionate about improving and expanding the possibilities of Cardiovascular? Ready to join a team that’s reimagining how we heal? Our Cardiovascular team develops leading solutions for heart recovery, electrophysiology, and stroke. You will join a proud heritage of continually elevating standards of care for stroke, heart failure and atrial fibrillation (AFib) patients.

Your unique talents will help patients on their journey to wellness. Learn more at https://www.jnj.com/medtech
We are searching for the best talent for a Senior Manager MedTech Cybersecurity role, to join our team located in Israel or US.

Purpose:
Johnson & Johnson is currently seeking a Sr. Manager for Electrophysiology (EP) and Neurovascular (NV) Cardiovascular business units’ part of Information Security & Risk Management (ISRM) organization. This position is preferred to be based in Yokneam, Haifa Israel or Irvine, California with an option for US. Remote work options may be considered on a case-by-case basis and if approved by the Company. 

This candidate will have a diverse background with strong business acumen, technology, and security expertise. He/she will be a strategic thinker who leads with impact inclusively, driving intentional change proactively, and be result driven keeping up with industry trends in cybersecurity.  This role will embed directly with our J&J Technology and MedTech EP & NV teams across Research & Development, Supply Chain, and Commercial teams providing the security posture and the end-to-end security portfolio/capability roadmap to improve, identify, and remediate cyber security vulnerabilities.

You will manage and inspire 1 team member and work across a matrixed organization demonstrating authentic leadership, driving results, and showing dedication to our Credo. Your site scope includes global cyber security responsibility for 4 internal Manufacturing sites (IT/OT), 4 R&D sites and labs, Application Security of 300+ applications inclusive of Sarbanes-Oxley, and 3rd party vendors of 200+.

You will be responsible for:

  • Shape the E2E cybersecurity profile and portfolio from assessment to remediation through developing, influencing, and driving a financial and remediation plan both yearly and long term with strategic roadmaps and business value.

  • Provide early/proactive engagement through security by design with project teams to drive business understanding and execution of the security controls and capabilities needed for the project.

  • Perform cybersecurity risk assessments of IT/OT assets within the R&D & Manufacturing sites.

  • Drive cybersecurity capability adoption R&D, Supply Chain, and Commercial functions to secure assets and enable safe & secure reliability and innovation.

  • Provide tailored security guidance (based on risk and complexity) - Interpret & apply the internal security requirements and standards for unique IT & OT (Operational Technology) initiatives.

  • Lead the cyber operational portfolio from identification > driving remediation plan > completion partnering across ISRM, business, and technology teams.

  • Establish data analytics to provide security posture across EP & NV business units, functions, and sites.

  • Proactively promote the importance of cybersecurity shared responsibility across the sector and sites through advancing cyber awareness program.

  • Assist the Security Operations Center (SOC) with security incident investigation activities; work closely with business teams to support affected users and provide liaison with central investigation team.

  • Drive business understanding of critical cybersecurity regulations and ensuring solutions are compliant (NIST, NIS2, Safe Data, etc.).

  • Support the global deployment of security initiatives with awareness sessions, identify alternative ways of working to avoid business disruptions, and review exception requests.

  • Provide audit support as the liaison between audit, technology, and business functions from pre-work to remediation plans.

 

Qualifications and Requirements:

  • 8+ years of direct or supporting experience in cybersecurity leadership and execution roles, with a background in Research & Development and Commercial environments, required.

  • Bachelor’s degree in computer science, information technology, business administration, or another rigorous discipline required; MBA preferred.

  • 6+ years of hands-on experience delivering technology and cybersecurity design capabilities across IT and OT environments, including firewalls, network intrusion detection systems, backup, and recovery, required.

  • Experience with security standards such as ISO 27001, HITRUST, and NIST required.

  • Cybersecurity, audit, or risk management certifications such as CISM, CISSP, ISA/IEC 62443, CISA, or CRISC preferred.

  • Excellent communication and collaboration skills, with the ability to network, engage, and influence across all organizational levels, sectors, functions, and regions.

  • Strategic mindset to develop capability roadmaps that strengthen proactive reliability through data and automation.

  • Experience with cloud security platforms such as AWS, Azure, or Salesforce required.

  • Experience securing multiple layers of enterprise architecture, including data, applications, hosts, middleware, networks, and infrastructure.

  • Strong understanding of current security threats, mitigation strategies, and security vendors and technologies.

  • Strong understanding of security data protection and related capabilities in R&D labs, clinical, and regulatory environments required.

  • Direct or supporting experience with application security required; Sarbanes-Oxley compliance and audit experience required.

  • Understanding of ISA/IEC 62443, NIST 800-53, and NIST 800-82 required.

  • Experience leading diverse team members with varying cybersecurity expertise, including resource allocation and planning to meet business needs.

  • Ability to balance strategic perspective with attention to detail to align tactical and long-term security priorities.

  • Ability to collaborate, build networks, and influence globally across sectors, functions, and organizational levels while establishing credibility as an inspiring cybersecurity leader.


#LI-AB6#LI-Hybrid



Required Skills:



Preferred Skills:

Business Process Design, Collaboration, Crisis Management, Critical Thinking, Cyber Threat Intelligence, Developing Others, Inclusive Leadership, Information Security Auditing, Information Security Management System (ISMS), Information Technology (IT) Security Assessments, Information Technology Strategies, Leadership, Managing Managers, People Performance Management, Presentation Design, Process Optimization, Security Architecture Design, Security Policies

Similar Jobs

14 Hours Ago
Remote or Hybrid
Mid level
Mid level
HR Tech • Information Technology • Professional Services • Sales • Software
Lead complex technical escalations for APIs, integrations, webhooks and payroll; perform deep root-cause analysis using SQL, logs and tracing; drive high-severity incidents; build debugging frameworks, automation, and observability improvements; mentor CX team and improve escalation processes.
Top Skills: Ai ToolsAuthenticationLogsMonitoring SystemsRest ApisSQLTracingWebhooks
14 Hours Ago
Remote or Hybrid
Mid level
Mid level
HR Tech • Information Technology • Professional Services • Sales • Software
The MIS Developer will design and maintain NetSuite customizations, integrate systems using Workato, and implement automation across business teams.
Top Skills: BigQueryHTMLJavaScriptNetSuiteOpenai ApisSnowflakeSQLWorkato
14 Hours Ago
Easy Apply
In-Office or Remote
United States
Easy Apply
139K-196K Annually
Senior level
139K-196K Annually
Senior level
Cloud • Security • Software • Cybersecurity • Automation
Design, maintain, and extend abuse detection and prevention systems for GitLab's SaaS platform. Serve as a core maintainer of a Ruby on Rails monolith, build anomaly detection and agentic AI mitigations, automate abuse response, collaborate with peer engineering and security teams, and produce runbooks and operational documentation.
Top Skills: Agentic AiAWSGitlabGoogle Cloud Platform (Gcp)Large Language Models (Llms)RubyRuby On RailsSaaS

What you need to know about the Los Angeles Tech Scene

Los Angeles is a global leader in entertainment, so it’s no surprise that many of the biggest players in streaming, digital media and game development call the city home. But the city boasts plenty of non-entertainment innovation as well, with tech companies spanning verticals like AI, fintech, e-commerce and biotech. With major universities like Caltech, UCLA, USC and the nearby UC Irvine, the city has a steady supply of top-flight tech and engineering talent — not counting the graduates flocking to Los Angeles from across the world to enjoy its beaches, culture and year-round temperate climate.

Key Facts About Los Angeles Tech

  • Number of Tech Workers: 375,800; 5.5% of overall workforce (2024 CompTIA survey)
  • Major Tech Employers: Snap, Netflix, SpaceX, Disney, Google
  • Key Industries: Artificial intelligence, adtech, media, software, game development
  • Funding Landscape: $11.6 billion in venture capital funding in 2024 (Pitchbook)
  • Notable Investors: Strong Ventures, Fifth Wall, Upfront Ventures, Mucker Capital, Kittyhawk Ventures
  • Research Centers and Universities: California Institute of Technology, UCLA, University of Southern California, UC Irvine, Pepperdine, California Institute for Immunology and Immunotherapy, Center for Quantum Science and Engineering

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account