At Johnson Johnson, we believe health is everything. Our strength in healthcare innovation empowers us to build a world where complex diseases are prevented, treated, and cured, where treatments are more thoughtful and less invasive, and solutions are personal. Through our expertise in Innovative Medicine and MedTech, we are uniquely positioned to innovate across the full spectrum of healthcare solutions today to deliver the breakthroughs of tomorrow, and profoundly impact health for humanity. Learn more at https://www.jnj.com/.
When You Join Johnson Johnson, Your Move Could Mean Our Next Breakthrough
We are searching for the best talent for a Business Information Security Principal to partner with the Corporate Procurement business, located, in Raritan, New Jersey or remotely in the US.
As a part of the Information Security Risk Management (ISRM) organization, this role will advance the security program which covers Johnson and Johnson’s procurement and finance business critical operations. The lead will ensure strong controls are in place at our sites for applications, infrastructure, critical digital assets and for our third-party vendors.
The BIS Principal will play a meaningful role to:
Drive Cyber Trust and Security by Design through consulting, engagement, and assurance. Support the strategy for embedding cyber security into business initiatives, improving risk posture, secure critical intellectual property, protect critical assets, improve site security, and enhance business resiliency.
Provide cybersecurity assurance for the Technical Operations Risk organization with a focus on Procurement. The role will provide security consulting services with key partners on pivotal initiatives for the organization.
Major Duties Responsibilities
Drive the adoption of security industry best-practices, JJ security standards and capabilities to ensure that critical information and assets are protected from cyber threats.
Provide assurance leadership on the cybersecurity risk posture of capabilities; including, security consulting, design reviews, ranking risks, and thought leadership on remediation.
Plan and prioritize the integration of security measures in business projects during the design, development, and deployment phases. Enable ISRM capabilities for the business including awareness, business impact, exceptions handling (e.g., Safe Data, Entra).
Provide metrics and reporting to senior ISRM and Business leadership on status of compliance to cybersecurity IAPP requirements and risks, as well as support regulatory requirements e.g., SOX 404, internal and external audits.
Facilitate education and training to the organization on cybersecurity procedures and controls.
Partner on budget planning and provide financial recommendations to improve the security posture and drive critical risk management.
At Johnson Johnson, we believe health is everything. Our strength in healthcare innovation empowers us to build a world where complex diseases are prevented, treated, and cured, where treatments are more thoughtful and less invasive, and solutions are personal. Through our expertise in Innovative Medicine and MedTech, we are uniquely positioned to innovate across the full spectrum of healthcare solutions today to deliver the breakthroughs of tomorrow, and profoundly impact health for humanity. Learn more at https://www.jnj.com/.
When You Join Johnson Johnson, Your Move Could Mean Our Next Breakthrough
We are searching for the best talent for a Business Information Security Principal to partner with the Corporate Procurement business, located, in Raritan, New Jersey or remotely in the US.
As a part of the Information Security Risk Management (ISRM) organization, this role will advance the security program which covers Johnson and Johnson’s procurement and finance business critical operations. The lead will ensure strong controls are in place at our sites for applications, infrastructure, critical digital assets and for our third-party vendors.
The BIS Principal will play a meaningful role to:
Drive Cyber Trust and Security by Design through consulting, engagement, and assurance. Support the strategy for embedding cyber security into business initiatives, improving risk posture, secure critical intellectual property, protect critical assets, improve site security, and enhance business resiliency.
Provide cybersecurity assurance for the Technical Operations Risk organization with a focus on Procurement. The role will provide security consulting services with key partners on pivotal initiatives for the organization.
Major Duties Responsibilities
Drive the adoption of security industry best-practices, JJ security standards and capabilities to ensure that critical information and assets are protected from cyber threats.
Provide assurance leadership on the cybersecurity risk posture of capabilities; including, security consulting, design reviews, ranking risks, and thought leadership on remediation.
Plan and prioritize the integration of security measures in business projects during the design, development, and deployment phases. Enable ISRM capabilities for the business including awareness, business impact, exceptions handling (e.g., Safe Data, Entra).
Provide metrics and reporting to senior ISRM and Business leadership on status of compliance to cybersecurity IAPP requirements and risks, as well as support regulatory requirements e.g., SOX 404, internal and external audits.
Facilitate education and training to the organization on cybersecurity procedures and controls.
Partner on budget planning and provide financial recommendations to improve the security posture and drive critical risk management.
Required Knowledge, Skills and Abilities:
A bachelor’s degree in technology, cybersecurity or other technical subject area is highly preferred.
A minimum of 6-8 years of progressive experience in leadership roles within Security, Technology or relevant discipline is required.Experience managing cybersecurity in life sciences environments is preferred.Deep understanding of cybersecurity controls and concepts Solid grasp of current security threats, mitigation measures and security vendors/technologies are requiredAbility to influence different audiences and drive Adoption of Enterprise Secure Software Development Processes and ToolsAbility to prioritize activities to deliver Security by Design and Comprehensive, Effective Risk Management Experience working in a fast-paced environment is required.Experience with SOX 404 controls is preferred.Creative problem-solving skills and understanding of complex environments (data, application, middleware, network) is preferred.Previous experience developing effective and strong partnerships is required.Superb communication and partnership skills with the ability to network and influence all levels is required.Key Working Relationships:
Corporate Business Technology and business partners e.g. Procurement and Finance as well as leadership, compliance SMEs such as Quality, Privacy, and audit teams.
Third Party vendors supporting IT solutions in scope for the job. Minor interactions with regulatory bodies as needed.
Johnson Johnson is an Affirmative Action and Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, age, national origin, or protected veteran status and will not be discriminated against on the basis of disability.
For more information on how we support the whole health of our employees throughout their wellness, career and life journey, please visit www.careers.jnj.com.
The anticipated base pay range for this position is $100,000 to $172,500.
The Company maintains highly competitive, performance-based compensation programs. Under current guidelines, this position is eligible for an annual performance bonus in accordance with the terms of the applicable plan. The annual performance bonus is a cash bonus intended to provide an incentive to achieve annual targeted results by rewarding for individual and the corporation’s performance over a calendar/performance year. Bonuses are awarded at the Company’s discretion on an individual basis.
Employees and/or eligible dependents may be eligible to participate in the following Company sponsored employee benefit programs: medical, dental, vision, life insurance, short- and long-term disability, business accident insurance, and group legal insurance.
Employees may be eligible to participate in the Company’s consolidated retirement plan (pension) and savings plan (401(k)).Employees are eligible for the following time off benefits: Vacation – up to 120 hours per calendar yearSick time - up to 40 hours per calendar year; for employees who reside in the State of Washington – up to 56 hours per calendar yearHoliday pay, including Floating Holidays – up to 13 days per calendar year of Work, Personal and Family Time - up to 40 hours per calendar yearAdditional information can be found through the link below. https://www.careers.jnj.com/employee-benefits#JNJTech
Required Knowledge, Skills and Abilities:
A bachelor’s degree in technology, cybersecurity or other technical subject area is highly preferred.
A minimum of 6-8 years of progressive experience in leadership roles within Security, Technology or relevant discipline is required.Experience managing cybersecurity in life sciences environments is preferred.Deep understanding of cybersecurity controls and concepts Solid grasp of current security threats, mitigation measures and security vendors/technologies are requiredAbility to influence different audiences and drive Adoption of Enterprise Secure Software Development Processes and ToolsAbility to prioritize activities to deliver Security by Design and Comprehensive, Effective Risk Management Experience working in a fast-paced environment is required.Experience with SOX 404 controls is preferred.Creative problem-solving skills and understanding of complex environments (data, application, middleware, network) is preferred.Previous experience developing effective and strong partnerships is required.Superb communication and partnership skills with the ability to network and influence all levels is required.Key Working Relationships:
Corporate Business Technology and business partners e.g. Procurement and Finance as well as leadership, compliance SMEs such as Quality, Privacy, and audit teams.
Third Party vendors supporting IT solutions in scope for the job. Minor interactions with regulatory bodies as needed.
Johnson Johnson is an Affirmative Action and Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, age, national origin, or protected veteran status and will not be discriminated against on the basis of disability.
For more information on how we support the whole health of our employees throughout their wellness, career and life journey, please visit www.careers.jnj.com.
The anticipated base pay range for this position is $100,000 to $172,500.
The Company maintains highly competitive, performance-based compensation programs. Under current guidelines, this position is eligible for an annual performance bonus in accordance with the terms of the applicable plan. The annual performance bonus is a cash bonus intended to provide an incentive to achieve annual targeted results by rewarding for individual and the corporation’s performance over a calendar/performance year. Bonuses are awarded at the Company’s discretion on an individual basis.
Employees and/or eligible dependents may be eligible to participate in the following Company sponsored employee benefit programs: medical, dental, vision, life insurance, short- and long-term disability, business accident insurance, and group legal insurance.
Employees may be eligible to participate in the Company’s consolidated retirement plan (pension) and savings plan (401(k)).Employees are eligible for the following time off benefits: Vacation – up to 120 hours per calendar yearSick time - up to 40 hours per calendar year; for employees who reside in the State of Washington – up to 56 hours per calendar yearHoliday pay, including Floating Holidays – up to 13 days per calendar year of Work, Personal and Family Time - up to 40 hours per calendar yearAdditional information can be found through the link below. https://www.careers.jnj.com/employee-benefits#JNJTech