Director, Incident Response & Threat
At Johnson & Johnson, we believe health is everything. Our strength in healthcare innovation empowers us to build a world where complex diseases are prevented, treated, and cured, where treatments are smarter and less invasive, and solutions are personal. Through our expertise in Innovative Medicine and MedTech, we are uniquely positioned to innovate across the full spectrum of healthcare solutions today to deliver the breakthroughs of tomorrow.
DePuy Synthes is recruiting for a Director, Incident Response & Threat. This hybrid position is available in Raynham, MA (USA), with alternate hybrid locations in Raritan, NJ (USA), West Chester, PA (USA), Warsaw, IN (USA), Palm Beach Gardens, FL (USA), or Pune, India.
Johnson & Johnson announced plans to separate our Orthopedics business to establish a standalone orthopedics company, operating as DePuy Synthes. The process of the planned separation is anticipated to be completed within 18 to 24 months. Should you accept this position, it is anticipated that, following conclusion of the transaction, you would be an employee of DePuy Synthes.
About the role
The Director, Incident Response & Threat is a senior cybersecurity leadership role responsible for protecting DePuy Synthes’ digital environment, products, and operations from cyber threats. This leader will own the global incident response program and threat management strategy, ensuring rapid detection, containment, and remediation of security incidents. The role plays a critical part in safeguarding patient trust, business continuity, and regulatory compliance while shaping a resilient and forward-looking security posture across the organization.
Responsibilities
- Lead the global incident response and threat management program, including preparation, detection, response, and recovery activities.
- Direct investigations of cybersecurity incidents, ensuring timely containment, root-cause analysis, and post-incident reporting.
- Develop and maintain incident response playbooks, escalation paths, and crisis management procedures.
- Partner with IT, Legal, Privacy, Quality, and Business leaders to manage cyber incidents and regulatory or compliance obligations.
- Oversee threat intelligence capabilities to proactively identify emerging threats and vulnerabilities relevant to the MedTech environment.
- Guide tabletop exercises, simulations, and readiness testing to strengthen organizational response maturity.
- Provide executive-level reporting and recommendations on cyber risk, incident trends, and remediation priorities.
- Lead, mentor, and develop a high-performing incident response and threat management team.
- Drive continuous improvement of tools, processes, and technologies supporting security operations and resilience.
Qualifications
- Education: Bachelor’s degree in Computer Science, Information Security, Engineering, or a related field (required). Master’s degree in Cybersecurity, Information Systems, or Business Administration (preferred).
- Required Experience and Skills:
- 10-12 years of progressive experience in cybersecurity, information security, or IT risk management, including leadership roles.
- Proven experience leading enterprise-scale incident response and threat management programs.
- Strong knowledge of cyber threat landscapes, attack techniques, and defensive strategies.
- Experience working in regulated environments (e.g., healthcare, life sciences, MedTech, or similarly regulated industries).
- Demonstrated ability to lead cross-functional teams during high-pressure incidents.
- Excellent executive communication, judgment, and decision-making skills.
- Preferred Experience:
- Supporting global organizations with complex technology environments.
- Familiarity with security frameworks such as NIST, ISO 27001, or similar standards.
- Integrating threat intelligence into security operations and risk management.
- People leadership experience managing managers or senior individual contributors.
- Experience with cloud, OT, and medical device security considerations.
- Other: Fluent in English. Travel up to 10–15%, primarily domestic with occasional international.
- Certifications (preferred): CISSP, CISM, GIAC, or equivalent cybersecurity certifications.
Pay
The anticipated base pay range for this position is $150,000.00 - $258,750.00.
Benefits
- Retirement & Savings: Eligible to participate in the Company’s consolidated retirement plan (pension) and savings plan (401(k)).
- Time Off:
- Vacation – 120 hours per calendar year
- Sick time – 40 hours per calendar year (48 hours for Colorado residents, 56 hours for Washington residents)
- Holiday pay, including Floating Holidays – 13 days per calendar year
- Work, Personal and Family Time – up to 40 hours per calendar year
- Parental Leave – 480 hours within one year of the birth/adoption/foster care of a child
- Bereavement Leave – 240 hours for an immediate family member; 40 hours for an extended family member per calendar year
- Caregiver Leave – 80 hours in a 52-week rolling period
- Volunteer Leave – 32 hours per calendar year
- Military Spouse Time-Off – 80 hours per calendar year