At Johnson & Johnson, we believe health is everything. Our strength in healthcare innovation empowers us to build a world where complex diseases are prevented, treated, and cured, where treatments are smarter and less invasive, and solutions are personal. Through our expertise in Innovative Medicine and MedTech, we are uniquely positioned to innovate across the full spectrum of healthcare solutions today to deliver the breakthroughs of tomorrow, and profoundly impact health for humanity. Learn more at jnj.com . As guided by Our Credo, Johnson & Johnson is responsible to our employees who work with us throughout the world. We provide an inclusive work environment where each person is considered as an individual. At Johnson & Johnson, we respect the diversity and dignity of our employees and recognize their merit. Job Function: Technology Enterprise Strategy & Security Job Sub Function: Security & Controls Job Category: People Leader All Job Posting Locations: Irvine, California, United States of America, Yokneam, Haifa District, Israel Job Description: About Johnson & Johnson MedTech Cardiovascular: Fueled by innovation at the intersection of biology and technology, we’re developing the next generation of smarter, less invasive, more personalized treatments. Are you passionate about improving and expanding the possibilities of Cardiovascular? Ready to join a team that’s reimagining how we heal? Our Cardiovascular team develops leading solutions for heart recovery, electrophysiology, and stroke. You will join a proud heritage of continually elevating standards of care for stroke, heart failure and atrial fibrillation (AFib) patients. Your unique talents will help patients on their journey to wellness. Learn more at https://www.jnj.com/medtech We are searching for the best talent for a Senior Manager MedTech Cybersecurity role, to join our team located in Israel or US. Purpose: Johnson & Johnson is currently seeking a Sr. Manager for Electrophysiology (EP) and Neurovascular (NV) Cardiovascular business units’ part of Information Security & Risk Management (ISRM) organization. This position is preferred to be based in Yokneam, Haifa Israel or Irvine, California with an option for US. Remote work options may be considered on a case-by-case basis and if approved by the Company. This candidate will have a diverse background with strong business acumen, technology, and security expertise. He/she will be a strategic thinker who leads with impact inclusively, driving intentional change proactively, and be result driven keeping up with industry trends in cybersecurity. This role will embed directly with our J&J Technology and MedTech EP & NV teams across Research & Development, Supply Chain, and Commercial teams providing the security posture and the end-to-end security portfolio/capability roadmap to improve, identify, and remediate cyber security vulnerabilities. You will manage and inspire 1 team member and work across a matrixed organization demonstrating authentic leadership, driving results, and showing dedication to our Credo. Your site scope includes global cyber security responsibility for 4 internal Manufacturing sites (IT/OT), 4 R&D sites and labs, Application Security of 300+ applications inclusive of Sarbanes-Oxley, and 3rd party vendors of 200+. You will be responsible for: Shape the E2E cybersecurity profile and portfolio from assessment to remediation through developing, influencing, and driving a financial and remediation plan both yearly and long term with strategic roadmaps and business value. Provide early/proactive engagement through security by design with project teams to drive business understanding and execution of the security controls and capabilities needed for the project. Perform cybersecurity risk assessments of IT/OT assets within the R&D & Manufacturing sites. Drive cybersecurity capability adoption R&D, Supply Chain, and Commercial functions to secure assets and enable safe & secure reliability and innovation. Provide tailored security guidance (based on risk and complexity) - Interpret & apply the internal security requirements and standards for unique IT & OT (Operational Technology) initiatives. Lead the cyber operational portfolio from identification > driving remediation plan > completion partnering across ISRM, business, and technology teams. Establish data analytics to provide security posture across EP & NV business units, functions, and sites. Proactively promote the importance of cybersecurity shared responsibility across the sector and sites through advancing cyber awareness program. Assist the Security Operations Center (SOC) with security incident investigation activities; work closely with business teams to support affected users and provide liaison with central investigation team. Drive business understanding of critical cybersecurity regulations and ensuring solutions are compliant (NIST, NIS2, Safe Data, etc.). Support the global deployment of security initiatives with awareness sessions, identify alternative ways of working to avoid business disruptions, and review exception requests. Provide audit support as the liaison between audit, technology, and business functions from pre-work to remediation plans. Qualifications and Requirements: 8+ years of direct or supporting experience in cybersecurity leadership and execution roles, with a background in Research & Development and Commercial environments, required. Bachelor’s degree in computer science, information technology, business administration, or another rigorous discipline required; MBA preferred. 6+ years of hands-on experience delivering technology and cybersecurity design capabilities across IT and OT environments, including firewalls, network intrusion detection systems, backup, and recovery, required. Experience with security standards such as ISO 27001, HITRUST, and NIST required. Cybersecurity, audit, or risk management certifications such as CISM, CISSP, ISA/IEC 62443, CISA, or CRISC preferred. Excellent communication and collaboration skills, with the ability to network, engage, and influence across all organizational levels, sectors, functions, and regions. Strategic mindset to develop capability roadmaps that strengthen proactive reliability through data and automation. Experience with cloud security platforms such as AWS, Azure, or Salesforce required. Experience securing multiple layers of enterprise architecture, including data, applications, hosts, middleware, networks, and infrastructure. Strong understanding of current security threats, mitigation strategies, and security vendors and technologies. Strong understanding of security data protection and related capabilities in R&D labs, clinical, and regulatory environments required. Direct or supporting experience with application security required; Sarbanes-Oxley compliance and audit experience required. Understanding of ISA/IEC 62443, NIST 800-53, and NIST 800-82 required. Experience leading diverse team members with varying cybersecurity expertise, including resource allocation and planning to meet business needs. Ability to balance strategic perspective with attention to detail to align tactical and long-term security priorities. Ability to collaborate, build networks, and influence globally across sectors, functions, and organizational levels while establishing credibility as an inspiring cybersecurity leader. #LI-AB6 #LI-Hybrid Required Skills: Preferred Skills: Business Process Design, Collaboration, Crisis Management, Critical Thinking, Cyber Threat Intelligence, Developing Others, Inclusive Leadership, Information Security Auditing, Information Security Management System (ISMS), Information Technology (IT) Security Assessments, Information Technology Strategies, Leadership, Managing Managers, People Performance Management, Presentation Design, Process Optimization, Security Architecture Design, Security Policies
Application Security Engineer (Senior) ID71672
Agileengine
Manual Tester
Phoenix Oversight Group LLC
Embedded Software Engineer
Itw
Field Service Engineer
Itw
Information Security Analyst
Omnissa
Associate Software Engineer
Asure Software