Data Security Manager - Information Security & Risk Management

Johnson & JohnsonRaritan, NJ
Hybrid

About The Position

Johnson and Johnson is recruiting a Data Security Manager - Information Security & Risk Management (ISRM). This position may be based in J&J office in Raritan, NJ or remote in the U.S. with the capability to periodically travel into the Raritan, NJ office. The role involves leading the enterprise Data Protection Program, including governance, operating processes, service oversight, metrics, reporting, and continuous improvement. It also includes owning Data Protection exception management processes and reducing exception volume through various strategies. The manager will partner with various teams to implement risk-based data protection controls, define and report program performance metrics, and maintain data protection policies and standards. Additionally, the role involves developing and implementing data security strategies, leading initiatives to protect critical information assets, conducting assessments of data security controls, and serving as a domain authority on emerging data security threats and technologies. The position also supports the implementation of new data security capabilities and collaborates across J&J teams for a coordinated approach to data protection.

Requirements

  • A BA/BS degree or equivalent is required for this position.
  • A minimum of 6 years of dynamic experience in roles within IT Security management and/or IT is preferred.
  • A minimum of 2 years experience in one of more aspects of data security (governance, deployment of data security measures, data labeling, etc.).
  • Advanced knowledge of information security processes and principles is preferred in explaining the business value of cybersecurity.
  • Experience in assessing current security threats, mitigation measures and security vendors/technologies is required.
  • Previous experience developing effective and strong partnerships along with relationship building skills with IT and business partners is required.
  • Results Orientation – ability to aim to timelines is required.
  • Superb communication and collaboration skills, able to network and influence at all levels of the organization, cross sector, multi-functionally and globally is required.
  • Demonstrable ability to influence/collaborate to get the desired result is required.

Nice To Haves

  • Graduate degree or equivalent experience preferred.
  • Certifications in cybersecurity (CISM, CISSP), audit (CISA), risk management (CRISC) or Data Security related are preferred.
  • Formal training and experience in developing or supporting a large-scale Data Security program is preferred.
  • Experience in performing Data Security and/or Data Protection project is preferred.

Responsibilities

  • Lead the enterprise Data Protection Program, including governance, operating processes, service oversight, metrics, reporting, and continuous improvement.
  • Own Data Protection exception management processes, including USB, webmail, file-sharing, Trusted Computing, Secure Data Transfer and other approved service exceptions.
  • Assess exception requests and coordinate risk reviews, approvals, remediation actions, and lifecycle management.
  • Reduce exception volume through secure alternatives, enhanced controls, user education, process optimization, and automation.
  • Partner with EUS, ISRM teams, Compliance, Privacy, Legal, HR, and business partners to design and implement risk-based data protection controls.
  • Define, monitor, and report program performance metrics, exception trends, risk themes, and executive-level insights.
  • Maintain data protection policies, standards, procedures, governance documentation, and accountability frameworks.
  • Develop and implement data security strategies to safeguard critical information assets and support enterprise data governance initiatives.
  • Lead initiatives to identify, classify, inventory, and protect critical information assets.
  • Conduct assessments of data security controls, processes, and capabilities to identify gaps, risks, and improvement opportunities.
  • Serve as a domain authority on emerging data security threats, technologies, and standard processes, providing recommendations for proactive risk mitigation.
  • Lead data security awareness, communications, change control, and training programs to drive adoption of security capabilities.
  • Support the implementation of new data security capabilities and collaborate across J&J teams to deliver a coordinated approach to data protection.

Benefits

  • medical
  • dental
  • vision
  • life insurance
  • short- and long-term disability
  • business accident insurance
  • group legal insurance
  • consolidated retirement plan (pension)
  • savings plan (401(k))
  • Vacation –120 hours per calendar year
  • Sick time - 40 hours per calendar year (or 56 hours for Washington State employees)
  • Holiday pay, including Floating Holidays –13 days per calendar year
  • Work, Personal and Family Time - up to 40 hours per calendar year
  • Parental Leave – 480 hours within one year of the birth/adoption/foster care of a child
  • Condolence Leave – 30 days for an immediate family member: 5 days for an extended family member
  • Caregiver Leave – 10 days
  • Volunteer Leave – 4 days
  • Military Spouse Time-Off – 80 hours
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service