Skip to main content

IM Cyber Security Director – Patient Experience and Customer Solutions

Apply now
Share
JJ Photo Colleagues Working On A Project Together

This job posting is anticipated to close on Oct 17 2026. We may however extend this time period, in which case the posting will remain available on www.careers.jnj.com to accept additional applications.

Description

At Johnson & Johnson, we believe health is everything. Our strength in healthcare innovation empowers us to build a world where complex diseases are prevented, treated, and cured, where treatments are smarter and less invasive, and solutions are personal. Through our expertise in Innovative Medicine and MedTech, we are uniquely positioned to innovate across the full spectrum of healthcare solutions today to deliver the breakthroughs of tomorrow, and profoundly impact health for humanity. Learn more at jnj.com

As guided by Our Credo, Johnson & Johnson is responsible to our employees who work with us throughout the world. We provide an inclusive work environment where each person is considered as an individual. At Johnson & Johnson, we respect the diversity and dignity of our employees and recognize their merit.

Job Function:

Technology Enterprise Strategy & Security

Job Sub Function:

Multi-Family Technology Enterprise Strategy & Security

Job Category:

People Leader

All Job Posting Locations:

Raritan, New Jersey, United States of America, Titusville, New Jersey, United States of America

Job Description:

J&J ISRM is seeking an IM Cyber Security Director – Patient Experience and Customer Solutions (PECS) to serve as the senior Information Security & Risk Management (ISRM) leader supporting PECS. This role will define and operationalize a forward-looking, risk-based security strategy that enables PECS growth and innovation while protecting patient health information, personal data, and other sensitive information across patient support programs, digital capabilities, data platforms, and third-party ecosystems.

The Director will act as a trusted cyber security advisor to PECS business and technology leaders and will partner closely with Legal, Privacy, Compliance, Digital Product and Solution teams, Cyber Defense, and other enterprise functions. The role will translate business strategy, evolving threats, patient expectations, and applicable legal and regulatory requirements into practical security priorities and enabling solutions. Based in Titusville, NJ this role will collaborate with Johnson & Johnson IM Business and Business Technology partners.

Key Responsibilities

  • Own the ISRM partnership with PECS, serving as the accountable cybersecurity leader and trusted advisor to senior business, technology, product, data, Legal, Privacy, Compliance, and operational stakeholders.
  • Define and execute a multi-year, risk-based security and patient data protection strategy aligned with PECS growth priorities, patient support models, enterprise ISRM strategy, risk appetite, and applicable legal and regulatory requirements, including the HIPAA Security Rule.
  • Embed security-by-design across the PECS capability lifecycle and translate cybersecurity and data protection requirements into practical solutions that enable innovation while protecting patient trust and sensitive information.
  • Lead risk-based security reviews and guide the implementation and remediation of controls across patient support programs, applications, cloud services, data platforms, integrations, analytics, artificial intelligence use cases, and digital patient and provider experiences.
  • Establish effective cybersecurity governance across PECS, including decision rights, risk acceptance and escalation, control ownership, issue management, incident readiness and response, third-party oversight, and integration with enterprise ISRM processes.
  • Develop executive-ready risk insights and metrics, communicate material risks and remediation progress, and influence business planning and investment so cybersecurity capabilities scale appropriately with PECS.
  • Lead, coach, and develop a high-performing team; set clear priorities and performance expectations, provide ongoing feedback and development opportunities, support succession planning, and foster an inclusive, purpose-driven culture aligned with Our Credo and J&J leadership expectations.

Leadership Expectations

  • Operate as a strategic business partner who enables secure, patient-centered innovation.
  • Keep patient and provider experience in view when shaping security solutions, avoiding unnecessary friction while maintaining appropriate protection and accountability.
  • Influence across organizational boundaries and resolve ambiguity by establishing clear ownership, priorities, decision rights, and expected outcomes.
  • Balance patient trust, regulatory expectations, business value, user experience, and technical feasibility in security decisions.
  • Communicate complex cybersecurity and patient data protection matters in concise business language, with clear options, recommendations, and accountability.
  • Anticipate emerging risks and regulatory or market changes, adapting the strategy before they become barriers to patient support or business execution.
  • Model Credo-based, ethical leadership and demonstrate empathy for the patients and providers served by PECS.
  • Build and lead a high-performing, diverse, and inclusive team by setting clear priorities and performance expectations, coaching and developing talent, enabling meaningful career and succession planning, recognizing contributions, and fostering accountability, collaboration, continuous learning, and a purpose-driven culture aligned with Our Credo and J&J leadership expectations.

Qualifications

  • Bachelor's degree in cybersecurity, computer science, information technology, risk management, or a related field; an advanced degree such as an MBA, JD, or relevant master's degree is preferred.
  • Ten or more years of progressive experience in cybersecurity, information security, technology risk, data protection, healthcare technology, or related disciplines, including leadership in a complex enterprise environment.
  • Demonstrated experience advising senior leaders and directing cybersecurity strategy, risk governance, and security assurance for business-critical or regulated capabilities.
  • Strong knowledge of security architecture, cloud and application security, identity and access management, data protection, security monitoring, vulnerability management, incident response, resilience, third-party risk, and data retention and deletion practices.
  • Experience protecting health information, patient data, personal data, or similarly sensitive regulated information across complex data flows and external partner ecosystems.
  • Working expertise with the HIPAA Security Rule and related healthcare security expectations; familiarity with relevant state and federal privacy requirements and broader security or privacy-aligned control frameworks is strongly preferred.
  • Proven ability to translate complex requirements into practical strategies, controls, services, and business decisions that support user-centered solutions.
  • Proven ability to lead cross-functional initiatives, influence without direct authority, overcome resistance, and drive risk decisions and remediation to measurable outcomes.
  • Experience building, leading, and developing high-performing teams, including globally distributed and matrixed resources.
  • Excellent executive communication, stakeholder management, negotiation, collaboration, and decision-making skills.
  • Demonstrated agility, resourcefulness, accountability, and persistence in a complex and rapidly changing environment.
  • Relevant professional certifications such as CISSP, CISM, CRISC, CCSP, or equivalent are preferred.

Preferred Experience

  • Cybersecurity leadership supporting patient services, patient support programs, digital health, commercial operations, customer engagement, access and affordability services, or related healthcare technology ecosystems.
  • Experience securing cloud platforms, data and analytics environments, APIs and integrations, software-as-a-service solutions, and emerging technologies.
  • Experience working with regulators, auditors, Legal, Privacy, Compliance, and third parties in a global healthcare or life sciences environment.
  • Demonstrated success establishing risk metrics, improving control maturity, reducing material exposure, and enabling secure business transformation.

#JNJTECH

#LI-Hybrid

Johnson & Johnson is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, age, national origin, disability, protected veteran status or other characteristics protected by federal, state or local law. We actively seek qualified candidates who are protected veterans and individuals with disabilities as defined under VEVRAA and Section 503 of the Rehabilitation Act.

Johnson & Johnson is committed to providing an interview process that is inclusive of our applicants’ needs. If you are an individual with a disability and would like to request an accommodation, please contact us via https://www.jnj.com/contact-us/careers or contact AskGS to be directed to your accommodation resource.

Required Skills:

Preferred Skills:

Business Process Design, Creating Purpose, Crisis Management, Critical Thinking, Cybersecurity, Developing Others, Inclusive Leadership, Information Security Auditing, Information Security Management System (ISMS), Information Technology (IT) Security Assessments, Information Technology Strategies, Leadership, Organizing, People Performance Management, Presentation Design, Process Optimization, Security Architecture Design, Security Policies

The anticipated base pay range for this position is :

The anticipated base pay range for this position is: $164,000- $282,900

Additional Description for Pay Transparency:

Subject to the terms of their respective plans, employees and/or eligible dependents are eligible to participate in the following Company sponsored employee benefit programs: medical, dental, vision, life insurance, short- and long-term disability, business accident insurance, and group legal insurance. Subject to the terms of their respective plans, employees are eligible to participate in the Company’s consolidated retirement plan (pension) and savings plan (401(k)). This position is eligible to participate in the Company’s long-term incentive program. Subject to the terms of their respective policies and date of hire, Employees are eligible for the following time off benefits: Vacation –120 hours per calendar year Sick time - 40 hours per calendar year; for employees who reside in the State of Washington –56 hours per calendar year Holiday pay, including Floating Holidays –13 days per calendar year Work, Personal and Family Time - up to 40 hours per calendar year Parental Leave – 480 hours within one year of the birth/adoption/foster care of a child Condolence Leave – 30 days for an immediate family member: 5 days for an extended family member Caregiver Leave – 10 days Volunteer Leave – 4 days Military Spouse Time-Off – 80 hours Additional information can be found through the link below. https://www.careers.jnj.com/employee-benefits

IM Cyber Security Director – Patient Experience and Customer Solutions

Apply now
Share

Not ready for a new role right now?

No worries. Join our talent community. We’ll reach out when we post new jobs that match your interests and skills so you can apply when the time is right.

A man looking down at his mobile device