Director, Incident Response & Threat
PharmaMedTechRegulatory AffairsQuality Assurancecroraveinform
Job description
At Johnson & Johnson, we believe health is everything. Our strength in healthcare innovation empowers us to build a world where complex diseases are prevented, treated, and cured, where treatments are smarter and less invasive, and solutions are personal. Through our expertise in Innovative Medicine and MedTech, we are uniquely positioned to innovate across the full spectrum of healthcare solutions today to deliver the breakthroughs of tomorrow, and profoundly impact health for humanity. Learn more at jnj.com As guided by Our Credo, Johnson & Johnson is responsible to our employees who work with us throughout the world. We provide an inclusive work environment where each person is considered as an individual. At Johnson & Johnson, we respect the diversity and dignity of our employees and recognize their merit. Job Function: Technology Enterprise Strategy & Security Job Sub Function: Security & Controls Job Category: People Leader All Job Posting Locations: Palm Beach Gardens, Florida, United States of America, Raritan, New Jersey, United States of America, Raynham, Massachusetts, United States of America, Warsaw, Indiana, United States of America, West Chester, Pennsylvania, United States of America Job Description: DePuy Synthes is recruiting for a(n) Director, Incident Response & Threat; this Hybrid position will be in Raynham, MA (USA). Alternate Hybrid locations may be considered at Raritan, NJ (USA), West Chester, PA (USA), Warsaw, IN (USA), Palm Beach Gardens, FL (USA) OR Pune, India. Please note that this role is available across multiple countries and may be posted under different requisition numbers to comply with local requirements. While you are welcome to apply to any or all of the postings, we recommend focusing on the specific country(s) that align with your preferred location(s): Raynham, MA (USA) - Requisition Number: R-072535 Pune, India - Requisition Number: R-073281 Remember, whether you apply to one or all of these requisition numbers, your applications will be considered as a single submission. Johnson & Johnson announced plans to separate our Orthopedics business to establish a standalone orthopedics company, operating as DePuy Synthes. The process of the planned separation is anticipated to be completed within 18 to 24 months, subject to legal requirements, including consultation with works councils and other employee representative bodies, as may be required, regulatory approvals and other customary conditions and approvals. Should you accept this position, it is anticipated that, following conclusion of the transaction, you would be an employee of DePuy Synthes and your employment would be governed by DePuy Synthes employment processes, programs, policies, and benefit plans. In that case, details of any planned changes would be provided to you by DePuy Synthes at an appropriate time and subject to any necessary consultation processes. Job Overview The Director, Cyber Defense is a senior cybersecurity leadership role responsible for protecting DePuy Synthes’ digital environment, products, and operations from cyber threats. This leader will own the global incident response program and threat management strategy, ensuring rapid detection, containment, and remediation of security incidents. The role plays a critical part in safeguarding patient trust, business continuity, and regulatory compliance while shaping a resilient and forward‑looking security posture across the organization, and reports into the DePuy Synthes Technology organization. Key Responsibilities: Lead the global incident response, digital forensics, defense engineering, and cyber threat intelligence capabilities, with accountability for preparedness, detection, containment, response, recovery, and continuous improvement. Build and mature an automation- and AI-first global Security Operations Center operating model that integrates an MSSP, retained services, and an internal team spanning eDiscovery, investigations, threat intelligence, incident response, and defense engineering. Direct complex cybersecurity incident investigations, ensuring rapid containment, preservation of forensic evidence, rigorous root-cause analysis, coordinated remediation, and timely executive and post-incident reporting. Develop, automate, test, and continuously improve incident response playbooks, escalation paths, communications protocols, and crisis management procedures to enable consistent, timely, and coordinated action during cyber events. Partner with IT, Legal, Privacy, Quality, and Business leaders to manage cyber incidents and regulatory or compliance obligations. Oversee threat intelligence capabilities that identify and assess emerging threats and vulnerabilities relevant to the MedTech environment, translate intelligence into prioritized defensive actions, and deliver concise executive briefings on business implications and recommended responses. Lead tabletop exercises, simulations, and readiness assessments across technology and business functions; translate lessons learned into prioritized remediation plans that measurably improve response maturity. Establish and maintain an executive-ready metrics framework - including mean time to acknowledge (MTTA), respond (MTTR), and contain (MTTC) - to demonstrate operational effectiveness, expose performance gaps, enforce accountability, and drive measurable improvements in cyber resilience. Provide executive-level reporting and actionable recommendations on cyber risk, incident trends, defensive readiness, investment priorities, and remediation progress to support timely, risk-informed decisions. Enhance relationship with the business by promoting awareness, insights and opportunities to improve the company’s risk position Lead proactive research to identify relevant threats, develop and perform threat hunts based on that research Lead, mentor, and develop a high‑performing incident response and threat management team. Drive continuous improvement of tools, processes, and technologies supporting security operations and resilience. Qualifications: Education: Bachelor’s degree in Computer Science, Information Security, Engineering, or a related field (required). Master’s degree in Cybersecurity, Information Systems, or Business Administration (preferred). Experience and Skills: Required: 10-12 years of progressive experience in cybersecurity, information security, or IT risk management, including leadership roles. Proven experience leading enterprise‑scale incident response and threat management programs. Strong knowledge of cyber threat landscapes, attack techniques, and defensive strategies. Experience working in regulated environments (e.g., healthcare, life sciences, MedTech, or similarly regulated industries). Demonstrated ability
Stand out for this role
NoxPharm tailors your CV to this job description by aligning your experience with the role requirements and terminology. Built for pharma & life sciences.
Tailor my CV now — free to trySimilar Pharma jobs
Associate, Project Management (Pharmaceutical Labeling)
Open Scientific — Hauppauge, us
Maintenance Coordinator
Open Scientific — Bohemia, us
Manufacturing Operators - Pharmaceutical
Open Scientific — Melville, us
Pharmaceutical Mechanics - Packaging, Production, Maintanence
Open Scientific — Hauppauge, us
Warehouse - Pharmaceutical
Open Scientific — Hauppauge, us
Pharmaceutical Machine Operators
Open Scientific — Hauppauge, us