Skip to content

Open nowPosted yesterday

A&D Post-Close Security Director

jj111 open roles

Where
Raritan New Jersey United States of America
Work mode
Remote
Get the CV for this job

From $25 per CV, paid once. No subscription.

Your applicationOpen nowA&D Post-Close Security Directorjj · Raritan New Jersey United States of America
  1. YouYes, apply to this one.

  2. CV RocketCV written for this posting.

  3. 25 readersRecruiter, hiring manager, skeptic. Round after round.

  4. CV RocketApplied on jj's own form.

The reply lands in your private mailbox

3×more interviews than doing it yourself with ChatGPT.

The clock on this job

Early applications get read.

8.0% of postings close within 7 days. Measured by our own scanner across the market. jj postings stay open a median of 2 days.

Share of postings closed within
  1. 1.6%1 day
  2. 3.6%3 days
  3. 8.0%7 days
  4. 15.0%14 days
  5. 34.2%30 days
This job: posted yesterday

jj median: 2 days open

The posting

At Johnson & Johnson, we believe health is everything. Our strength in healthcare innovation empowers us to build a world where complex diseases are prevented, treated, and cured, where treatments are smarter and less invasive, and solutions are personal. Through our expertise in Innovative Medicine and MedTech, we are uniquely positioned to innovate across the full spectrum of healthcare solutions today to deliver the breakthroughs of tomorrow, and profoundly impact health for humanity. Learn more at jnj.com

As guided by Our Credo, Johnson & Johnson is responsible to our employees who work with us throughout the world. We provide an inclusive work environment where each person is considered as an individual. At Johnson & Johnson, we respect the diversity and dignity of our employees and recognize their merit.

Job Function:

Technology Enterprise Strategy & Security

Job Sub Function:

Security & Controls

Job Category:

People Leader

All Job Posting Locations:

Alabama (Any City), Alabama (Any City), Alaska (Any City), Arizona (Any City), Arkansas (Any City), California (Any City), Colorado (Any City), Connecticut (Any City), Delaware (Any City), Florida (Any City), Georgia (Any City), Hawaii (Any City), Idaho (Any City), Illinois (Any City), Indiana (Any City), Iowa (Any City), Kansas (Any City), Kentucky (Any City), Louisiana (Any City), Maine (Any City), Maryland (Any City), Massachusetts (Any City), Michigan (Any City), Minnesota (Any City), Mississippi (Any City) {+ 26 more}

Job Description:

The Director, Information Security Risk Management (ISRM) Acquisitions & Divestitures (A&D) Cybersecurity, Post-Close, serves as the strategic leader responsible for defining, governing, and continuously improving the enterprise cybersecurity approach for post-close acquisitions, divestitures, licensing arrangements, separations, integrations, minority investments, and strategic partnerships.

This role provides executive leadership and oversight for post-close mobilization, Day 1 stabilization, transition governance, risk remediation, integration and separation execution, TSA delivery and exit, and ongoing portfolio performance. The Director applies comprehensive regulatory and compliance insight together with broad technical expertise across cybersecurity and enterprise technology to troubleshoot complex delivery issues, challenge proposed solutions, make key risk-informed decisions, and preserve security-by-design principles throughout integration and separation.

The Director partners closely with Corporate Development, Legal, Privacy, Finance, Technology Services, ISRM capability and policy owners, business technology leaders, IMO/SMO teams, transaction sponsors, and senior executives to ensure enterprise policy requirements are reflected in technical solutions, transition decisions, integration and separation plans, and approved exception handling.

Key Responsibilities

  • Strategic Leadership, Policy Alignment & Governance: Define post-close cybersecurity strategy, governance, standards, operating rhythms, decision rights, and escalation paths. Partner with key ISRM policy, capability, architecture, risk, and control stakeholders to ensure enterprise requirements are embedded in integration and separation plans, technical designs, transition decisions, and approved exception processes.
  • Post-Close Mobilization & Day 1 Stabilization: Convert deal scope, due diligence findings, Day 1 requirements, regulatory obligations, TSA assumptions, milestones, risks, and dependencies into prioritized execution plans with clear ownership and measurable outcomes.
  • Integration, Separation & TSA Execution: Provide executive and technical oversight for identity, endpoints, infrastructure, cloud, applications, data protection, monitoring, incident response, third parties, regulatory obligations, and TSA delivery and exit.
  • Technical Decision Leadership & Security by Design: Troubleshoot complex cybersecurity and technology issues, challenge proposed architectures and exceptions, make key risk-informed decisions, and ensure security-by-design requirements remain intact through transition, integration, separation, and decommissioning.
  • Risk Remediation & Control Assurance: Ensure findings are prioritized, assigned, evidenced, escalated, and closed or formally accepted, with control validation and reporting that demonstrate progress and residual risk.
  • Portfolio & Delivery Management: Oversee concurrent deals, workstreams, vendors, transition services, budgets, milestones, and dependencies, maintaining clear portfolio-level visibility.
  • Automation & Process Transformation: Drive automation for intake, tracking, evidence, controls, notifications, dashboards, metrics, and reporting to improve traceability and scale delivery.
  • Executive Engagement & Communication: Communicate progress, regulatory implications, risks, decisions, dependencies, business impacts, and resource needs to executives and governance forums.
  • Operating Model & Continuous Improvement: Maintain playbooks, runbooks, templates, RACI models, capability standards, lessons learned, handoff criteria, and Definition of Done requirements.
  • Organizational Leadership: Lead and develop managers, cybersecurity professionals, deal leads, project managers, and cross-functional contributors while promoting accountability, mentoring, knowledge sharing, and consistent delivery practices.

Qualifications

Education

  • Bachelor's degree in Information Security, Computer Science, Engineering, Information Systems, Business, or a related discipline.
  • Advanced degree (MBA, MS, or equivalent) preferred.

Required Experience & Skills

  • 12+ years of progressive experience in cybersecurity, information risk management, technology leadership, M&A transaction support, integration or separation, or related disciplines.
  • Demonstrated experience leading cybersecurity programs supporting acquisitions, divestitures, licensing, minority investments, strategic partnerships, or other complex business transactions.
  • Comprehensive regulatory and compliance insight, including the ability to interpret applicable legal, privacy, industry, and enterprise obligations and translate them into practical transaction requirements, control decisions, and risk treatment.
  • Broad technical expertise across security architecture, identity and access management, cloud and infrastructure security, endpoint security, network security, application security, data protection, vulnerability management, security operations, incident response, third-party risk, privacy, and cyber resilience.
  • Demonstrated ability to troubleshoot complex cybersecurity and technology issues at a Director level, challenge technical assumptions and proposed solutions, make key risk-informed decisions, and preserve security-by-design principles throughout transaction planning and execution.
  • Proven ability to partner with ISRM policy, capability, architecture, risk, and control owners to reconcile enterprise security requirements with transaction constraints and keep integration and separation plans aligned with approved policies, standards, control objectives, and exception processes.
  • Experience influencing executives and driving cross-functional initiatives across highly matrixed, global environments.
  • Strong understanding of recognized cybersecurity frameworks and standards, including NIST Cybersecurity Framework, ISO 27001, NIST 800-series publications, GDPR, HIPAA, and other applicable requirements.
  • Experience managing portfolios involving concurrent deals, assessments or workstreams, vendors, senior stakeholders, dependencies, and time-sensitive decisions.
  • Exceptional executive communication and presentation skills, with the ability to articulate technical risk, regulatory implications, business impact, residual exposure, and decision needs to non-technical audiences.
  • Demonstrated ability to navigate ambiguity, protect transaction confidentiality, drive organizational change, and improve repeatability through data, tools, automation, and disciplined governance.

Preferred Experience

  • Experience developing or operating A&D cybersecurity playbooks, questionnaires, control libraries, risk-scoring methods, RACI models, handoff criteria, and phase-based transaction standards.
  • Experience designing automation for intake, evidence collection, risk reporting, workflow orchestration, dashboards, and portfolio governance.
  • Experience partnering with Corporate Development, Legal, Privacy, Finance, Technology Services, business technology teams, IMO/SMO functions, external advisors, and managed service providers.
  • Experience in regulated healthcare, pharmaceutical, MedTech, manufacturing, or similarly complex global environments.
  • Relevant certifications such as CISSP, CISM, CRISC, CISA, CCSK, or equivalent credentials preferred.

Leadership Expectations

  • Operates as an enterprise-minded cybersecurity leader who balances transaction speed, regulatory and enterprise obligations, technical risk, stakeholder expectations, operational continuity, and value realization.
  • Maintains security by design through clear technical direction, informed challenge, disciplined governance, and partnership with enterprise policy and capability owners.
  • Builds repeatable systems rather than one-time solutions, emphasizing scalability, measurable outcomes, traceability, and continuous improvement.
  • Drives accountability by defining ownership, escalation paths, decision rights, quality standards, and delivery expectations.
  • Creates an inclusive, collaborative environment that encourages mentoring, knowledge sharing, pragmatic risk management, and high-quality execution.

An internal pre-identified candidate for consideration has been identified. However, all applications will be considered.

Remote work options may be considered on a case-by-case basis and if approved by the Company.

Johnson & Johnson is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, age, national origin, disability, protected veteran status or other characteristics protected by federal, state or local law. We actively seek qualified candidates who are protected veterans and individuals with disabilities as defined under VEVRAA and Section 503 of the Rehabilitation Act.

Johnson & Johnson is committed to providing an interview process that is inclusive of our applicants’ needs. If you are an individual with a disability and would like to request an accommodation, please contact us via https://www.jnj.com/contact-us/careers or contact AskGS to be directed to your accommodation resource.

Required Skills:

Preferred Skills:

Business Process Design, Creating Purpose, Crisis Management, Critical Thinking, Cybersecurity, Developing Others, Inclusive Leadership, Information Security Auditing, Information Security Management System (ISMS), Information Technology (IT) Security Assessments, Information Technology Strategies, Leadership, Organizing, People Performance Management, Presentation Design, Process Optimization, Security Architecture Design, Security Policies

The anticipated base pay range for this position is :

$150,000.00 - $258,750.00

Additional Description for Pay Transparency:

Subject to the terms of their respective plans, employees are eligible to participate in the Company’s consolidated retirement plan (pension) and savings plan (401(k)).

This position is eligible to participate in the Company’s long-term incentive program.

Subject to the terms of their respective policies and date of hire, employees are eligible for the following time off benefits:

Vacation –120 hours per calendar year

Sick time - 40 hours per calendar year; for employees who reside in the State of Colorado –48 hours per calendar year; for employees who reside in the State of Washington –56 hours per calendar year

Holiday pay, including Floating Holidays –13 days per calendar year

Work, Personal and Family Time - up to 40 hours per calendar year

Parental Leave – 480 hours within one year of the birth/adoption/foster care of a child

Bereavement Leave – 240 hours for an immediate family member: 40 hours for an extended family member per calendar year

Caregiver Leave – 80 hours in a 52-week rolling period10 days

Volunteer Leave – 32 hours per calendar year

Military Spouse Time-Off – 80 hours per calendar year

For additional general information on Company benefits, please go to: - https://www.careers.jnj.com/employee-benefits

From $25, paid onceGet the CV for this job

What happens when you press

One press. We do the rest.

  1. A CV for this posting

    Written against jj's own wording, from every piece of relevant proof in your profile.

  2. 25 readers review it

    Recruiter, hiring manager, skeptic and more read every draft, round after round. You get the best round.

    The review screen in CV Rocket: how each CV was read, round by round.
  3. We apply on jj's form

    Our application engine gets through the hardest forms there are. Where a question needs you, AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

    An application in CV Rocket: every answer filled in on the employer's form.
  4. Every reply, sorted

    jj's answer lands in your private mailbox, and we classify it on arrival: interview, question, rejection.

    The CV Rocket inbox: each employer reply classified as an interview, an action or a rejection.
  5. Reply with AI

    AI helps you write the email, checks it and sends it. We show you whether the recruiter read it.

  6. The interview in your calendar

    Full integration with your calendar. The invitation goes straight in.

    An interview invitation in the CV Rocket inbox, added to the candidate's calendar.
Get the CV for this job

From $25 per CV, paid once. No subscription.

Why it works

3×

more interviews than doing it yourself with ChatGPT.

ChatGPT writes a CV and never learns what happened to it. We see every reply. For each CV we know:

  • How it was written, and how the review scored it
  • When we applied, and how long after the posting went up
  • Which posting, which company, which city
  • Who got the interview, and who heard nothing

That is how we know which CVs get called.

Get the CV for this job

From $25 per CV, paid once. No subscription.

The numbers game

More applications. More interviews.

Every application goes out with its own CV, written for that posting and paid once. Send enough of them and the law of large numbers finds you the job.

By hand5–10
With CV Rocket100
applications a day

Nearby

Live postings like this one

Same employer first, then the same role elsewhere.

Before you press

Straight answers

Get the CV for this job

From $25 per CV, paid once. No subscription.

What if my background isn't good enough?

We make the most of the background you have. The CV uses every piece of relevant proof your profile holds, and one of the 25 readers reads your whole profile and flags what the CV left out.

Do you really apply for me?

Yes, on the employer's own form, the hardest ones included. Where a question needs you, you answer it right there and AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

Is it a subscription?

No. You pay once per CV, from $25. Every application goes out with its own CV, written for that posting.

One job. One CV.
Paid once.

Pick the posting you want. We write for it, apply for you and catch the reply.

Get the CV for this job

From $25 per CV, paid once. No subscription.