Director, Incident Response & Threat

Johnson & Johnson Innovative MedicineWarsaw, IN
$150,000 - $258,750Hybrid

About The Position

The Director, Cyber Defense is a senior cybersecurity leadership role responsible for protecting DePuy Synthes’ digital environment, products, and operations from cyber threats. This leader will own the global incident response program and threat management strategy, ensuring rapid detection, containment, and remediation of security incidents. The role plays a critical part in safeguarding patient trust, business continuity, and regulatory compliance while shaping a resilient and forward‑looking security posture across the organization, and reports into the DePuy Synthes Technology organization.

Requirements

  • Bachelor’s degree in Computer Science, Information Security, Engineering, or a related field (required).
  • 10-12 years of progressive experience in cybersecurity, information security, or IT risk management, including leadership roles.
  • Proven experience leading enterprise‑scale incident response and threat management programs.
  • Strong knowledge of cyber threat landscapes, attack techniques, and defensive strategies.
  • Experience working in regulated environments (e.g., healthcare, life sciences, MedTech, or similarly regulated industries).
  • Demonstrated ability to lead cross‑functional teams during high‑pressure incidents.
  • Excellent executive communication, judgment, and decision‑making skills.
  • Language: English (fluent).

Nice To Haves

  • Master’s degree in Cybersecurity, Information Systems, or Business Administration (preferred).
  • Experience supporting global organizations with complex technology environments.
  • Familiarity with security frameworks such as NIST, ISO 27001, or similar standards.
  • Experience integrating threat intelligence into security operations and risk management.
  • Prior people leadership experience managing managers or senior individual contributors.
  • Experience with cloud, OT, and medical device security considerations.
  • CISSP, CISM, GIAC, or equivalent cybersecurity certifications.

Responsibilities

  • Lead the global incident response, digital forensics, defense engineering, and cyber threat intelligence capabilities, with accountability for preparedness, detection, containment, response, recovery, and continuous improvement.
  • Build and mature an automation- and AI-first global Security Operations Center operating model that integrates an MSSP, retained services, and an internal team spanning eDiscovery, investigations, threat intelligence, incident response, and defense engineering.
  • Direct complex cybersecurity incident investigations, ensuring rapid containment, preservation of forensic evidence, rigorous root-cause analysis, coordinated remediation, and timely executive and post-incident reporting.
  • Develop, automate, test, and continuously improve incident response playbooks, escalation paths, communications protocols, and crisis management procedures to enable consistent, timely, and coordinated action during cyber events.
  • Partner with IT, Legal, Privacy, Quality, and Business leaders to manage cyber incidents and regulatory or compliance obligations.
  • Oversee threat intelligence capabilities that identify and assess emerging threats and vulnerabilities relevant to the MedTech environment, translate intelligence into prioritized defensive actions, and deliver concise executive briefings on business implications and recommended responses.
  • Lead tabletop exercises, simulations, and readiness assessments across technology and business functions; translate lessons learned into prioritized remediation plans that measurably improve response maturity.
  • Establish and maintain an executive-ready metrics framework - including mean time to acknowledge (MTTA), respond (MTTR), and contain (MTTC) - to demonstrate operational effectiveness, expose performance gaps, enforce accountability, and drive measurable improvements in cyber resilience.
  • Provide executive-level reporting and actionable recommendations on cyber risk, incident trends, defensive readiness, investment priorities, and remediation progress to support timely, risk-informed decisions.
  • Enhance relationship with the business by promoting awareness, insights and opportunities to improve the company’s risk position
  • Lead proactive research to identify relevant threats, develop and perform threat hunts based on that research
  • Lead, mentor, and develop a high‑performing incident response and threat management team.
  • Drive continuous improvement of tools, processes, and technologies supporting security operations and resilience.

Benefits

  • Vacation –120 hours per calendar year
  • Sick time - 40 hours per calendar year; for employees who reside in the State of Colorado –48 hours per calendar year; for employees who reside in the State of Washington –56 hours per calendar year
  • Holiday pay, including Floating Holidays –13 days per calendar year
  • Work, Personal and Family Time - up to 40 hours per calendar year
  • Parental Leave – 480 hours within one year of the birth/adoption/foster care of a child
  • Bereavement Leave – 240 hours for an immediate family member: 40 hours for an extended family member per calendar year
  • Caregiver Leave – 80 hours in a 52-week rolling period10 days
  • Volunteer Leave – 32 hours per calendar year
  • Military Spouse Time-Off – 80 hours per calendar year
  • Consolidated retirement plan (pension)
  • Savings plan (401(k))
  • Long-term incentive program
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service