Professional, Compliance Lead

Johnson & Johnson

Confirmed live today High trust
Closes in 5 days Hybrid

Quick summary

Work type
Hybrid
Location
New Brunswick, NJRaritan, NJWest Chester, PAPalm Beach Gardens, FLRaynham, MAWarsaw, IN
Posted
2 days ago
Freshness
Confirmed live today
Closes
Sep 29, 2026 (soon)

Market check

Salary context

How this pay compares to similar roles

Similar $170k
$114k most similar roles pay here $215k

This listing doesn't post a salary. Most similar roles pay $149,375–$190,350.

Based on 240 similar postings.

Employer

About Johnson & Johnson

Johnson & Johnson is a multinational corporation operating in three main segments: consumer health products, pharmaceuticals, and medical devices, known for brands like Tylenol, Band-Aid, and Janssen. Industry: Pharmaceuticals & Medical Devices

Johnson & Johnson currently has 73 open roles on FindRole.

Listed pay typically runs $109,000–$177,100 across 68 roles with salary data.

Most-posted roles

View all roles at Johnson & Johnson

At a glance

TL;DR · Professional, Compliance Lead

Professional, Compliance Lead serves as a seasoned individual contributor within the Cybersecurity function, specifically focused on GRC, IT Controls, and Cyber Culture. This role is responsible for leading the cybersecurity compliance and governance agenda across DePuy Synthes by owning the policy and standards framework, establishing enterprise cyber risk methodologies, and managing risk assessment programs. The candidate will develop executive reporting models, manage third-party risk oversight, and maintain a regulatory mapping library including NIST CSF, ISO 27001, HIPAA, GDPR, and FDA cybersecurity guidance. Key responsibilities include coordinating with internal audit and external regulators while driving cyber culture initiatives. Required expertise includes GRC frameworks, risk assessment methodologies, and experience with tools like ServiceNow IRM or Archer. The role addresses the complex regulatory requirements inherent in the MedTech and life sciences industries.

What you'll do

  • Manage the end-to-end cybersecurity policy and standards program including lifecycle management, annual reviews, and risk acceptances.
  • Define and maintain the enterprise cyber risk framework, including taxonomy, scoring models, and risk appetite statements.
  • Direct the cyber risk assessment program for applications, infrastructure, business processes, and major change initiatives.
  • Oversee the enterprise cyber risk register to ensure data quality, ownership accountability, and timely escalation of risks.
  • Develop executive reporting models that translate complex risk and compliance data into actionable narratives for senior leadership.
  • Establish and monitor cyber risk metrics and Key Risk Indicators (KRIs) to drive proactive program interventions.
  • Lead third-party risk oversight by setting vendor tiering models, assessment standards, and contractual security requirements.
  • Serve as the primary point of contact for internal audits, external regulators, and customer security assessments.

What we're looking for

  • Must have 6 years of experience in cybersecurity governance, IT risk management, technology compliance, or a related GRC discipline.
  • Must demonstrate ownership of a security policy and standards framework including authorship, lifecycle management, and exception handling.
  • Must possess advanced knowledge of NIST CSF, NIST 800-53, ISO 27001/27002, and COBIT frameworks.
  • Must have experience designing and operating cyber risk assessment methodologies and enterprise risk registers at scale.
  • Must have experience defining KRIs and building executive-level risk reporting to drive leadership decisions.
  • Must have experience leading third-party cyber risk programs including assessment standards and contract security requirements.
  • CISP, CRISC, CISM, or CISA certifications are required or in progress.
  • MedTech/Life Sciences background and knowledge of HIPAA, GDPR, and FDA regulations are preferred.

More like this

Similar roles

Principal Risk Specialist, Compliance Governance Analyst

Capital One Financial

McLean, VA +1 26 days ago $120,800–$137,900
Risk Management Compliance Audit Data Visualization Tableau Google Workspace Gemini NotebookLM AI Tools Project Management Process Management Reporting Analytics Business Continuity Planning Quality Assurance Change Management
4+ yrs exp

Vice President, Cybersecurity Controls & Compliance

TransUnion

Chicago, IL +2 23 days ago $193,500–$406,500
PCI DSS SOX NIST CSF ISO 27001 GRC Platforms AI-enabled Governance Cybersecurity Audit Risk Management Control Assurance Information Security Automation
10+ yrs exp Hybrid

AI and Automation Lead for Cyber Application Compliance, VP

State Street

Quincy, MA +3 36 days ago $120,000–$202,500
Artificial Intelligence Machine Learning Generative AI Large Language Models (LLMs) Python Java C# JavaScript ServiceNow Archer AWS Azure Cloud Platform Data Pipelines NIST Cybersecurity Framework Predictive Analytics Cybersecurity Governance
7+ yrs exp

Data Governance & Compliance Lead

USAA

San Antonio, TX +4 48 days ago $143,320–$273,930
Data Governance Information Management Data Engineering Risk Management Audit Information Architecture Compliance Data Management Strategy CIMP IGP CDMP
8+ yrs exp Hybrid

Lead, Information Security Regulatory & Compliance

Prudential Financial

Newark, NJ 29 days ago $114,500–$188,900
ISO 27001 NIST SOC 1 NYDFS 23 NYCRR 500 FFIEC GRC Platforms Jira ServiceNow IAM ASM CDR Cloud Security Data Protection Information Security Governance
Hybrid

SOX Compliance Lead

HP Inc.

Vancouver, WA 134 days ago $105,050–$161,800
SOX ITGC SDLC ICOFR SOC2 ISO 27001 NIST CSF NIST AI RMF Agentic AI GitHub GDPR NIS2 DORA CISA CISM CRISC CISSP Risk Management
8+ yrs exp