Job Function:
Technology Enterprise Strategy & Security
Job Sub Function:
Security & Controls
Job Category:
People Leader
All Job Posting Locations:
Palm Beach Gardens, Florida, United States of America, Raritan, New Jersey, United States of America, Raynham, Massachusetts, United States of America, Warsaw, Indiana, United States of America, West Chester, Pennsylvania, United States of America
Job Description:
DePuy Synthes is recruiting for a(n) Sr. Director, GRC, IT Controls andCyberCulture.
Johnson & Johnson announced plans to separate our Orthopedics business toestablisha standalone orthopedics company, operatingasDePuy Synthes. The process of the planned separation isanticipatedto be completed within 18 to24 months, subject to legal requirements, including consultation with works councils and other employee representative bodies, as may berequired, regulatory approvals and other customary conditions and approvals. Should you accept this position, it isanticipatedthat, following conclusion of the transaction, you would be an employee of DePuySynthesand your employment would be governed by DePuy Synthes employment processes, programs, policies, and benefit plans. In that case, details of any planned changes would be provided to you by DePuy Synthes atan appropriate timeand subject to any necessary consultation processes.
Job Overview
This role serves as a senior cybersecurity leader reporting to the CISO, with enterprise accountability for building, maturing, and operationalizing the Governance, Risk & Compliance (GRC) function across DePuy Synthes. The Sr. Director will oversee the BISO manager organization,establishscalable risk governance practices, strengthen security awareness andbehavior basedculture programs, and drive implementation of IT controls and an enterprise assurance framework. The role will also oversee external cybersecurity assessments and disclosures, including cyber insurance, ESG-related cybersecurity inputs, and other third-party assurance activities. This highly visible leadership role will help ensure cybersecurity risk, compliance, control effectiveness, and cultural adoption are consistently managed across the enterprise in support of business priorities, regulatory expectations, and organizational resilience.
Key Responsibilities
- Build and mature the enterprise GRC function, including governance forums, risk management processes, compliance oversight, control monitoring, issue management, and executive reporting.
- Provide leadership and oversight for the BISO manager organization, ensuring consistent engagement with business leaders, effective cyber risk advisory support, and alignment of security priorities to businessobjectives.
- Lead enterprise cyber risk management activities, including risk identification, assessment, mitigation planning, escalation, and reporting to senior leadership and governance bodies.
- Own the enterprise cybersecurity policy and standards lifecycle - from creation and implementation to continuous review - ensuring clarity, compliance, and alignment with organizational goals.
- Oversee SOX cybersecurity and IT control activities, including implementation, operating effectiveness,evidencereadiness, remediation tracking, and partnership with Finance, Internal Audit, External Audit, and IT control owners.
- Establish and operationalize an enterprise IT controls and assurance framework that enables consistent control design, testing, monitoring, reporting, and continuous improvement across the organization.
- Lead oversight of external cybersecurity assessments and assurance requests, including cyber insurance questionnaires, ESG-related cybersecurity inputs, customer or partner assessments, and other third-party reviews requiring enterprise cyber risk and control representation.
- Drive cybersecurity compliance with applicable global regulations, standards, and frameworks, ensuring the organization candemonstratecontrol effectiveness and audit readiness.
- Lead security awareness, behavior, and culture initiatives that improve workforce accountability, reducehuman‑centricrisk, and embed secure practices intoday‑to‑daybusiness operations.
- Lead and develophigh‑performingcybersecurity leaders and teams, fostering a culture of accountability, collaboration, disciplined execution, and continuous improvement.
- Provideexecutive‑levelreporting on cybersecurity risk, compliance status, control effectiveness, assurance outcomes, and program maturity to senior leadership and governance bodies.
Qualifications
Education
- Required:Bachelor’s degree in Information Security, Computer Science, Engineering, ora relatedfield.
- Preferred: Master’s degree (MS, MBA, or equivalent) in Cybersecurity, Information Systems, or Business.
Experience and Skills
- Required:
- 12–14 years of progressive experience in cybersecurity, information security, technology risk management, IT controls, or GRC, including senior leadership roles.
- Demonstrated experience building or maturing enterprise GRC programs in a regulated, global, or complex operating environment.
- Experience leading BISO, cyber risk advisory, security governance, or business aligned cybersecurity teams.
- Deep knowledge of cybersecurity risk management, compliance frameworks, IT controls, SOX control expectations, assurance practices, and audit readiness.
- Experience overseeing external cybersecurity assessments, including cyber insurance, ESG-related cybersecurity reporting, customer or partner assessments, and third-party assurance requests.
- Experience building, mentoring, and leading senior level cybersecurity teams.
- Strong strategic, analytical, and communication skills, with the ability to translate technical risk, control gaps, and compliance obligations into business impact.
- Preferred:
- Experience implementing or transforming enterprise IT controls, SOX programs, control testing, remediation governance, and assurance frameworks.
- Experience driving cybersecurity awareness, behavior change, and culture programs across a large enterprise.
- Experienceoperatingin complex, global organizations undergoing transformation or separation.
- Demonstrated success improvingcybersecuritymaturity, control effectiveness, and risk accountability at scale.
- Proven ability to influence executive stakeholders andpartnereffectively across IT, Finance, Internal Audit, External Audit, Legal, Risk, Compliance, and business leadership functions.
Other:
- Language: English (fluent)
- Travel: Up to 20%, domestic and international
- Certifications (preferred): CISSP, CISM, CRISC, or equivalent