Senior Manager MedTech Cybersecurity

Johnson & Johnson Innovative MedicineIrvine, CA
Remote

About The Position

Johnson & Johnson is currently seeking a Sr. Manager for Electrophysiology (EP) and Neurovascular (NV) Cardiovascular business units’ part of Information Security & Risk Management (ISRM) organization. This position is preferred to be based in Yokneam, Haifa Israel or Irvine, California with an option for US. Remote work options may be considered on a case-by-case basis and if approved by the Company. This candidate will have a diverse background with strong business acumen, technology, and security expertise. He/she will be a strategic thinker who leads with impact inclusively, driving intentional change proactively, and be result driven keeping up with industry trends in cybersecurity. This role will embed directly with our J&J Technology and MedTech EP & NV teams across Research & Development, Supply Chain, and Commercial teams providing the security posture and the end-to-end security portfolio/capability roadmap to improve, identify, and remediate cyber security vulnerabilities. You will manage and inspire 1 team member and work across a matrixed organization demonstrating authentic leadership, driving results, and showing dedication to our Credo. Your site scope includes global cyber security responsibility for 4 internal Manufacturing sites (IT/OT), 4 R&D sites and labs, Application Security of 300+ applications inclusive of Sarbanes-Oxley, and 3rd party vendors of 200+.

Requirements

  • 8+ years of direct or supporting experience in cybersecurity leadership and execution roles, with a background in Research & Development and Commercial environments, required.
  • Bachelor’s degree in computer science, information technology, business administration, or another rigorous discipline required; MBA preferred.
  • 6+ years of hands-on experience delivering technology and cybersecurity design capabilities across IT and OT environments, including firewalls, network intrusion detection systems, backup, and recovery, required.
  • Experience with security standards such as ISO 27001, HITRUST, and NIST required.
  • Experience with cloud security platforms such as AWS, Azure, or Salesforce required.
  • Experience securing multiple layers of enterprise architecture, including data, applications, hosts, middleware, networks, and infrastructure.
  • Strong understanding of current security threats, mitigation strategies, and security vendors and technologies.
  • Strong understanding of security data protection and related capabilities in R&D labs, clinical, and regulatory environments required.
  • Direct or supporting experience with application security required; Sarbanes-Oxley compliance and audit experience required.
  • Understanding of ISA/IEC 62443, NIST 800-53, and NIST 800-82 required.
  • Experience leading diverse team members with varying cybersecurity expertise, including resource allocation and planning to meet business needs.
  • Ability to balance strategic perspective with attention to detail to align tactical and long-term security priorities.
  • Ability to collaborate, build networks, and influence globally across sectors, functions, and organizational levels while establishing credibility as an inspiring cybersecurity leader.

Nice To Haves

  • Cybersecurity, audit, or risk management certifications such as CISM, CISSP, ISA/IEC 62443, CISA, or CRISC preferred.
  • Business Process Design
  • Collaboration
  • Crisis Management
  • Critical Thinking
  • Cyber Threat Intelligence
  • Developing Others
  • Inclusive Leadership
  • Information Security Auditing
  • Information Security Management System (ISMS)
  • Information Technology (IT) Security Assessments
  • Information Technology Strategies
  • Leadership
  • Managing Managers
  • People Performance Management
  • Presentation Design
  • Process Optimization
  • Security Architecture Design
  • Security Policies

Responsibilities

  • Shape the E2E cybersecurity profile and portfolio from assessment to remediation through developing, influencing, and driving a financial and remediation plan both yearly and long term with strategic roadmaps and business value.
  • Provide early/proactive engagement through security by design with project teams to drive business understanding and execution of the security controls and capabilities needed for the project.
  • Perform cybersecurity risk assessments of IT/OT assets within the R&D & Manufacturing sites.
  • Drive cybersecurity capability adoption R&D, Supply Chain, and Commercial functions to secure assets and enable safe & secure reliability and innovation.
  • Provide tailored security guidance (based on risk and complexity) - Interpret & apply the internal security requirements and standards for unique IT & OT (Operational Technology) initiatives.
  • Lead the cyber operational portfolio from identification > driving remediation plan > completion partnering across ISRM, business, and technology teams.
  • Establish data analytics to provide security posture across EP & NV business units, functions, and sites.
  • Proactively promote the importance of cybersecurity shared responsibility across the sector and sites through advancing cyber awareness program.
  • Assist the Security Operations Center (SOC) with security incident investigation activities; work closely with business teams to support affected users and provide liaison with central investigation team.
  • Drive business understanding of critical cybersecurity regulations and ensuring solutions are compliant (NIST, NIS2, Safe Data, etc.).
  • Support the global deployment of security initiatives with awareness sessions, identify alternative ways of working to avoid business disruptions, and review exception requests.
  • Provide audit support as the liaison between audit, technology, and business functions from pre-work to remediation plans.
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service