JJ

A&D Post-Close Security Director

Salary
$150K–$258.8K
Hiring from
United States
Work type
Remote
Posted
Is this job info correct?
Show job description

At Johnson & Johnson, we believe health is everything. Our strength in healthcare innovation empowers us to build a world where complex diseases are prevented, treated, and cured, where treatments are smarter and less invasive, and solutions are personal. Through our expertise in Innovative Medicine and MedTech, we are uniquely positioned to innovate across the full spectrum of healthcare solutions today to deliver the breakthroughs of tomorrow, and profoundly impact health for humanity. Learn more at jnj.com

As guided by Our Credo, Johnson & Johnson is responsible to our employees who work with us throughout the world. We provide an inclusive work environment where each person is considered as an individual. At Johnson & Johnson, we respect the diversity and dignity of our employees and recognize their merit.

Job Function:

Technology Enterprise Strategy & Security

Job Sub Function:

Security & Controls

Job Category:

People Leader

All Job Posting Locations:

Alabama (Any City), Alabama (Any City), Alaska (Any City), Arizona (Any City), Arkansas (Any City), California (Any City), Colorado (Any City), Connecticut (Any City), Delaware (Any City), Florida (Any City), Georgia (Any City), Hawaii (Any City), Idaho (Any City), Illinois (Any City), Indiana (Any City), Iowa (Any City), Kansas (Any City), Kentucky (Any City), Louisiana (Any City), Maine (Any City), Maryland (Any City), Massachusetts (Any City), Michigan (Any City), Minnesota (Any City), Mississippi (Any City) {+ 26 more}

Job Description:

The Director, Information Security Risk Management (ISRM) Acquisitions & Divestitures (A&D) Cybersecurity, Post-Close, serves as the strategic leader responsible for defining, governing, and continuously improving the enterprise cybersecurity approach for post-close acquisitions, divestitures, licensing arrangements, separations, integrations, minority investments, and strategic partnerships.


This role provides executive leadership and oversight for post-close mobilization, Day 1 stabilization, transition governance, risk remediation, integration and separation execution, TSA delivery and exit, and ongoing portfolio performance. The Director applies comprehensive regulatory and compliance insight together with broad technical expertise across cybersecurity and enterprise technology to troubleshoot complex delivery issues, challenge proposed solutions, make key risk-informed decisions, and preserve security-by-design principles throughout integration and separation.


The Director partners closely with Corporate Development, Legal, Privacy, Finance, Technology Services, ISRM capability and policy owners, business technology leaders, IMO/SMO teams, transaction sponsors, and senior executives to ensure enterprise policy requirements are reflected in technical solutions, transition decisions, integration and separation plans, and approved exception handling.


Key Responsibilities

  • Strategic Leadership, Policy Alignment & Governance: Define post-close cybersecurity strategy, governance, standards, operating rhythms, decision rights, and escalation paths. Partner with key ISRM policy, capability, architecture, risk, and control stakeholders to ensure enterprise requirements are embedded in integration and separation plans, technical designs, transition decisions, and approved exception processes.
  • Post-Close Mobilization & Day 1 Stabilization: Convert deal scope, due diligence findings, Day 1 requirements, regulatory obligations, TSA assumptions, milestones, risks, and dependencies into prioritized execution plans with clear ownership and measurable outcomes.
  • Integration, Separation & TSA Execution: Provide executive and technical oversight for identity, endpoints, infrastructure, cloud, applications, data protection, monitoring, incident response, third parties, regulatory obligations, and TSA delivery and exit.
  • Technical Decision Leadership & Security by Design: Troubleshoot complex cybersecurity and technology issues, challenge proposed architectures and exceptions, make key risk-informed decisions, and ensure security-by-design requirements remain intact through transition, integration, separation, and decommissioning.
  • Risk Remediation & Control Assurance: Ensure findings are prioritized, assigned, evidenced, escalated, and closed or formally accepted, with control validation and reporting that demonstrate progress and residual risk.
  • Portfolio & Delivery Management: Oversee concurrent deals, workstreams, vendors, transition services, budgets, milestones, and dependencies, maintaining clear portfolio-level visibility.
  • Automation & Process Transformation: Drive automation for intake, tracking, evidence, controls, notifications, dashboards, metrics, and reporting to improve traceability and scale delivery.
  • Executive Engagement & Communication: Communicate progress, regulatory implications, risks, decisions, dependencies, business impacts, and resource needs to executives and governance forums.
  • Operating Model & Continuous Improvement: Maintain playbooks, runbooks, templates, RACI models, capability standards, lessons learned, handoff criteria, and Definition of Done requirements.
  • Organizational Leadership: Lead and develop managers, cybersecurity professionals, deal leads, project managers, and cross-functional contributors while promoting accountability, mentoring, knowledge sharing, and consistent delivery practices.

Qualifications

Education

  • Bachelor's degree in Information Security, Computer Science, Engineering, Information Systems, Business, or a related discipline.
  • Advanced degree (MBA, MS, or equivalent) preferred.

Required Experience & Skills

  • 12+ years of progressive experience in cybersecurity, information risk management, technology leadership, M&A transaction support, integration or separation, or related disciplines.
  • Demonstrated experience leading cybersecurity programs supporting acquisitions, divestitures, licensing, minority investments, strategic partnerships, or other complex business transactions.
  • Comprehensive regulatory and compliance insight, including the ability to interpret applicable legal, privacy, industry, and enterprise obligations and translate them into practical transaction requirements, control decisions, and risk treatment.
  • Broad technical expertise across security architecture, identity and access management, cloud and infrastructure security, endpoint security, network security, application security, data protection, vulnerability management, security operations, incident response, third-party risk, privacy, and cyber resilience.
  • Demonstrated ability to troubleshoot complex cybersecurity and technology issues at a Director level, challenge technical assumptions and proposed solutions, make key risk-informed decisions, and preserve security-by-design principles throughout transaction planning and execution.
  • Proven ability to partner with ISRM policy, capability, architecture, risk, and control owners to reconcile enterprise security requirements with transaction constraints and keep integration and separation plans aligned with approved policies, standards, control objectives, and exception processes.
  • Experience influencing executives and driving cross-functional initiatives across highly matrixed, global environments.
  • Strong understanding of recognized cybersecurity frameworks and standards, including NIST Cybersecurity Framework, ISO 27001, NIST 800-series publications, GDPR, HIPAA, and other applicable requirements.
  • Experience managing portfolios involving concurrent deals, assessments or workstreams, vendors, senior stakeholders, dependencies, and time-sensitive decisions.
  • Exceptional executive communication and presentation skills, with the ability to articulate technical risk, regulatory implications, business impact, residual exposure, and decision needs to non-technical audiences.
  • Demonstrated ability to navigate ambiguity, protect transaction confidentiality, drive organizational change, and improve repeatability through data, tools, automation, and disciplined governance.

Preferred Experience

  • Experience developing or operating A&D cybersecurity playbooks, questionnaires, control libraries, risk-scoring methods, RACI models, handoff criteria, and phase-based transaction standards.
  • Experience designing automation for intake, evidence collection, risk reporting, workflow orchestration, dashboards, and portfolio governance.
  • Experience partnering with Corporate Development, Legal, Privacy, Finance, Technology Services, business technology teams, IMO/SMO functions, external advisors, and managed service providers.
  • Experience in regulated healthcare, pharmaceutical, MedTech, manufacturing, or similarly complex global environments.
  • Relevant certifications such as CISSP, CISM, CRISC, CISA, CCSK, or equivalent credentials preferred.

Leadership Expectations

  • Operates as an enterprise-minded cybersecurity leader who balances transaction speed, regulatory and enterprise obligations, technical risk, stakeholder expectations, operational continuity, and value realization.
  • Maintains security by design through clear technical direction, informed challenge, disciplined governance, and partnership with enterprise policy and capability owners.
  • Builds repeatable systems rather than one-time solutions, emphasizing scalability, measurable outcomes, traceability, and continuous improvement.
  • Drives accountability by defining ownership, escalation paths, decision rights, quality standards, and delivery expectations.
  • Creates an inclusive, collaborative environment that encourages mentoring, knowledge sharing, pragmatic risk management, and high-quality execution.

An internal pre-identified candidate for consideration has been identified. However, all applications will be considered.


Remote work options may be considered on a case-by-case basis and if approved by the Company.


Johnson & Johnson is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, age, national origin, disability, protected veteran status or other characteristics protected by federal, state or local law. We actively seek qualified candidates who are protected veterans and individuals with disabilities as defined under VEVRAA and Section 503 of the Rehabilitation Act.

Johnson & Johnson is committed to providing an interview process that is inclusive of our applicants’ needs. If you are an individual with a disability and would like to request an accommodation, please contact us via https://www.jnj.com/contact-us/careers or contact AskGS to be directed to your accommodation resource.

Required Skills:

Preferred Skills:

Business Process Design, Creating Purpose, Crisis Management, Critical Thinking, Cybersecurity, Developing Others, Inclusive Leadership, Information Security Auditing, Information Security Management System (ISMS), Information Technology (IT) Security Assessments, Information Technology Strategies, Leadership, Organizing, People Performance Management, Presentation Design, Process Optimization, Security Architecture Design, Security Policies

The anticipated base pay range for this position is :

$150,000.00 - $258,750.00

Additional Description for Pay Transparency:

Subject to the terms of their respective plans, employees are eligible to participate in the Company’s consolidated retirement plan (pension) and savings plan (401(k)).

This position is eligible to participate in the Company’s long-term incentive program.

Subject to the terms of their respective policies and date of hire, employees are eligible for the following time off benefits:

Vacation –120 hours per calendar year

Sick time - 40 hours per calendar year; for employees who reside in the State of Colorado –48 hours per calendar year; for employees who reside in the State of Washington –56 hours per calendar year

Holiday pay, including Floating Holidays –13 days per calendar year

Work, Personal and Family Time - up to 40 hours per calendar year

Parental Leave – 480 hours within one year of the birth/adoption/foster care of a child

Bereavement Leave – 240 hours for an immediate family member: 40 hours for an extended family member per calendar year

Caregiver Leave – 80 hours in a 52-week rolling period10 days

Volunteer Leave – 32 hours per calendar year

Military Spouse Time-Off – 80 hours per calendar year

For additional general information on Company benefits, please go to: - https://www.careers.jnj.com/employee-benefits

About Us

At Johnson & Johnson, we believe health is everything. Our strength in healthcare innovation empowers us to build a world where complex diseases are prevented, treated, and cured, where treatments are smarter and less invasive, and solutions are personal. Through our expertise in Innovative Medicine and MedTech, we are uniquely positioned to innovate across the full spectrum of healthcare solutions today to deliver the breakthroughs of tomorrow, and profoundly impact health for humanity. Learn more at https://www.jnj.com/.

Privacy

Do Not Sell or Share My Personal Information

Limit the Use of My Personal Information

Similar jobs

Apply for this job