The posting
At Johnson & Johnson, we believe health is everything. Our strength in healthcare innovation empowers us to build a world where complex diseases are prevented, treated, and cured, where treatments are smarter and less invasive, and solutions are personal. Through our expertise in Innovative Medicine and MedTech, we are uniquely positioned to innovate across the full spectrum of healthcare solutions today to deliver the breakthroughs of tomorrow, and profoundly impact health for humanity. Learn more at jnj.com
As guided by Our Credo, Johnson & Johnson is responsible to our employees who work with us throughout the world. We provide an inclusive work environment where each person is considered as an individual. At Johnson & Johnson, we respect the diversity and dignity of our employees and recognize their merit.
Job Function:
Technology Enterprise Strategy & Security
Job Sub Function:
Security & Controls
Job Category:
Scientific/Technology
All Job Posting Locations:
Raritan, New Jersey, United States of America
Job Description:
This is a durational based role that will last 13 months and is open to remote work or work in Raritan, NJ
We are looking for the best possible talent for a Manager, Business Info Security-13-month duration based role
An internal pre-identified candidate for consideration has been identified. However, all applications will be considered.
Business Information Security Manager – ISRM Osprey Program
Orthopedics Business Separation (NewCo Formation)
Role Purpose
Lead cybersecurity governance, risk management, and remediation support for the security aspects of the Osprey Program and the Orthopedics business separation. The Cybersecurity Manager will provide dedicated capacity to manage the expanding DMAB exception portfolio and enterprise data-segregation and least-privilege risks, while maintaining clear accountability with application owners and business leadership. The role will coordinate risk analysis, treatment planning, executive decisions, and sustained tracking so that separation milestones are achieved without weakening J&J base-business security outcomes.
Scope of Accountability
Accountable for supporting the cybersecurity management of Osprey-related governance and risk activities across affected applications. The role coordinates Business Information Security engagement for exception intake, IPT creation, risk analysis, S-RAAP development, mitigation planning, executive signoffs, and lifecycle tracking. Scope includes the current inventory of at least 156 Type 2 and 35 Type 3 DMAB exceptions, with responsibility to scale processes as demand grows; assess commingled-data and access risks; obtain validation from application owners on data segregation and least-privilege requirements; and support application owners in defining practical remediation approaches. The manager maintains governance discipline by ensuring operational remediation, evidence production, and exception accountability remain with the appropriate application owners and business leaders, while BIS provides security oversight, challenge, escalation, and advisory support.
- Portfolio governance: Establish a prioritized, risk-based operating cadence for Osprey exceptions, application reviews, remediation dependencies, approvals, and executive escalations.
- Risk leadership: Direct consistent assessment of data commingling, access, segregation, monitoring, and residual-risk concerns across Osprey and retained J&J operations.
- Ownership and escalation: Define clear RACI expectations, hold application and business owners accountable for execution, and escalate delayed actions or risk-acceptance decisions through the appropriate governance forums.
- Capacity Support: Provide expanded BIS capability support coverage for a limited-duration to fill a gap in capacity across ISRM teams for the Osprey program.
Deliverables Ownership
The Business Information Security Manager owns the quality, timeliness, transparency, and governance of the following deliverables:
- DMAB exception portfolio: Accurate inventory, triage, prioritization, aging analysis, decision records, approvals, and closure evidence for Type 2 and Type 3 exceptions.
- Risk artifacts: Complete and decision-ready IPTs, risk analyses, S-RAAPs, mitigation plans, residual-risk statements, and executive-signoff packages.
- Application remediation plans: Documented treatment strategies for commingled data, data segregation, least privilege, monitoring, and access-control gaps, with named owners and committed milestones.
- Governance reporting: Regular dashboards and leadership communications covering volume, severity, aging, blockers, overdue actions, capacity constraints, and impacts to Osprey and base-business security.
- Operating model and RACI: Defined intake, review, escalation, approval, tracking, and closure processes that distinguish BIS oversight from application-owner and business-leader execution responsibility.
- Resource transition plan: Onboarding and direction for temporary support, documented procedures, knowledge transfer, and a sustainable handoff model for long-term governance and remediation ownership.
Measures of Success
- Exception control: Identified Osprey exceptions are recorded, risk-tiered, assigned to accountable owners, and supported by required artifacts and decision evidence.
- Remediation progress: High-risk data-segregation and least-privilege gaps have approved treatment plans, measurable milestones, and verified closure evidence; unresolved residual risk is explicitly accepted by authorized leadership.
- Program and business protection: Cybersecurity dependencies do not become blockers to Osprey milestones.
#LI-Remote
#LI-Hybrid
#JNJTECH
Johnson & Johnson is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, age, national origin, disability, protected veteran status or other characteristics protected by federal, state or local law. We actively seek qualified candidates who are protected veterans and individuals with disabilities as defined under VEVRAA and Section 503 of the Rehabilitation Act.
Johnson & Johnson is committed to providing an interview process that is inclusive of our applicants’ needs. If you are an individual with a disability and would like to request an accommodation, external applicants please contact us via https://www.jnj.com/contact-us/careers , internal employees contact AskGS to be directed to your accommodation resource.
Required Skills:
Preferred Skills:
Business Process Design, Crisis Management, Critical Thinking, Information Security Auditing, Information Security Management System (ISMS), Information Technology (IT) Security Assessments, Information Technology Strategies, Mentorship, Organizing, Presentation Design, Process Optimization, Root Cause Analysis (RCA), Security Architecture Design, Security Policies, Technical Credibility, Vulnerability Management
The anticipated base pay range for this position is :
$102,000 - $175,950
Additional Description for Pay Transparency:
Subject to the terms of their respective plans, employees and/or eligible dependents are eligible to participate in the following Company sponsored employee benefit programs: medical, dental, vision, life insurance, short- and long-term disability, business accident insurance, and group legal insurance. Subject to the terms of their respective plans, employees are eligible to participate in the Company’s consolidated retirement plan (pension) and savings plan (401(k)). Subject to the terms of their respective policies and date of hire, Employees are eligible for the following time off benefits: Vacation –120 hours per calendar year Sick time - 40 hours per calendar year; for employees who reside in the State of Washington –56 hours per calendar year Holiday pay, including Floating Holidays –13 days per calendar year Work, Personal and Family Time - up to 40 hours per calendar year Parental Leave – 480 hours within one year of the birth/adoption/foster care of a child Condolence Leave – 30 days for an immediate family member: 5 days for an extended family member Caregiver Leave – 10 days Volunteer Leave – 4 days Military Spouse Time-Off – 80 hours Additional information can be found through the link below. https://www.careers.jnj.com/employee-benefits



