What are the responsibilities and job description for the Manager, Cybersecurity position at Johnson & Johnson?
Johnson & Johnson is currently seeking a Manager for Cardiovascular Supply Chain business units' part of Information Security & Risk Management (ISRM) organization. This role can be based out of a J&J site in the US or Mexico or fully remote on a case by case basis.
The candidate will have a diverse background with strong business acumen, technology, and security expertise. He/she will be a strategic thinker who leads with impact inclusively, driving intentional change proactively, and be result driven keeping up with industry trends in cybersecurity.
This role will embed directly with our J&J Technology and MedTech Supply Chain teams providing the security posture and the end-to-end security portfolio/capability roadmap to improve, identify, and remediate cyber security vulnerabilities.
Responsibilities:
- Provide early/proactive engagement with project teams to drive business understanding and execution of the security capabilities and services needed for the project; End to end support for large programs.
- Drive the OT capability and drive Cyber Security Risk Index (CSRI) security adoption across Surgery sites to secure IT/OT assets and enable safe & secure innovation.
- Provide tailored security guidance (based on risk and complexity) - Interpret & apply the IAPP requirements and standards for unique IT/OT (Operational Technology) initiatives and innovative or OT Specific technologies.
- Lead the cyber operational portfolio from identification > consulting remediation plan > completion partnering across ISRM, business, and technology teams.
- Establish data analytics to provide security posture across Surgery business units, functions, and sites.
- Proactively promote the importance of cybersecurity across the sector and sites.
- Assist the Security Operations Center (SOC) with security incident investigation activities; work closely with business teams to support affected users and provide liaison with central investigation team.
- Drive business understanding of critical cybersecurity regulations and ensuring solutions are compliant (NIST, NIS2, Safe Data, etc.).
- Support the global deployment of security initiatives with awareness sessions, identify alternative ways of working to avoid business disruptions, and review exception requests
- Provide audit support as the liaison between GAA/JJRC and JJT/Business from pre-work to consulting remediation plans.
Qualifications
6 years of related experience in leadership and execution roles within Cybersecurity or Risk Management with background in Supply Chain required.
Bachelor's degree in computer science, information technology, business administration, or another rigorous discipline is required. MBA preferred.
5 years of hands-on experience in delivering technology; and cybersecurity design and capabilities required.
Certifications in cybersecurity (CISM, CISSP, ISA-62443), audit (CISA), manufacturing or risk management (CRISC) are preferred.
Excellent communication and collaboration skills, able to network, interface and influence at all levels of the organization, cross sector, cross-functionally and globally.
Strategic mindset to develop capability roadmaps that will enable proactive reliability through data & automation.
Experience in working/securing various levels of the enterprise architecture (data, application, host, middleware, network, Infrastructure).
Solid understanding of current security threats, mitigation measures, and security vendors/technologies.
Strong understanding of security data protection and capabilities in a manufacturing and/or distribution site is highly preferred.
Direct working and/or supporting experience of Supply Chain applications and Sarbanes-Oxley compliance is required.
Understanding of IEC 62443, NIST 800-53 and 800-82 required.
Leading diverse team members with varying cybersecurity experience and proficient in resource allocation and planning to meet business needs.
Big picture perspective and attention to detail focus to align strategic and tactical security aspects.
Ability to collaborate, network and influence all levels of the organization, cross sector, cross-function and global and establish oneself as an inspiring leader with expertise in space.
Job Type: Full-time
Salary: $115,000-$197,800 per year
Benefits:
- Vacation – up to 120 hours per calendar year
- Sick time - up to 40 hours per calendar year; for employees who reside in the State of Washington – up to 56 hours per calendar year
- Holiday pay, including Floating Holidays – up to 13 days per calendar year of Work, Personal and Family Time - up to 40 hours per calendar year
Salary : $115,000 - $197,800