Senior Legal Director, Cyber & Data Risk
Johnson & Johnson
- Location
- New Brunswick New Jersey United States of America
- Work model
- On-Site
- Level
- Staff
- H-1B history
- 2 approvals (FY2023)
- Posted
- 16h ago
Skills
About this role
At Johnson & Johnson, we believe health is everything. Our strength in healthcare innovation empowers us to build a world where complex diseases are prevented, treated, and cured, where treatments are smarter and less invasive, and solutions are personal. Through our expertise in Innovative Medicine and MedTech, we are uniquely positioned to innovate across the full spectrum of healthcare solutions today to deliver the breakthroughs of tomorrow, and profoundly impact health for humanity. Learn more at jnj.com As guided by Our Credo, Johnson & Johnson is responsible to our employees who work with us throughout the world. We provide an inclusive work environment where each person is considered as an individual. At Johnson & Johnson, we respect the diversity and dignity of our employees and recognize their merit. Job Function: Legal & Compliance Job Sub Function: Law Business Partners Job Category: People Leader All Job Posting Locations: New Brunswick, New Jersey, United States of America, Raritan, New Jersey, United States of America, Titusville, New Jersey, United States of America Job Description: Johnson & Johnson is transforming healthcare with technology, data, and AI. Across the enterprise, we are scaling AI, modernizing digital platforms, advancing connected healthcare technologies, strengthening cybersecurity capabilities, and investing in the data and technology foundations that support Research & Development, Technical Operations, Commercial, and Corporate Functions. To support this transformation, the Global Legal Organization (GLO) is establishing a dedicated Technology Advisory Legal team. This newly created team will partner directly with Enterprise Technology leaders to help shape the legal frameworks that enable innovation while managing cybersecurity, data, AI, and technology risk. As the Senior Legal Director, Cyber & Data Risk, you will serve as the principal legal advisor to the Chief Information Security Officer (CISO) and Information Security & Risk Management (ISRM) organization, along with the broader enterprise technology leaders. As a member of the ISRM Leadership Team, you will advise on the organization's most complex cybersecurity, technology, and data risk legal matters while helping define how legal supports enterprise technology at global scale. The responsibilities of the Senior Director, Cyber, Data Risk, & Privacy are: Strategic Advisor to the CISO Serve as the principal legal advisor to the Chief Information Security Officer (CISO) and Information Security & Risk Management (ISRM) Leadership Team, providing strategic counsel on cybersecurity, enterprise technology risk, data risk, and complex legal matters requiring significant judgment. Advise executive leadership on legal implications of strategic business decisions, emerging risks, and evolving regulatory requirements affecting the organization's cybersecurity strategy. Technology Strategy & Business Partnership Partner with the CISO, ISRM Leadership Team, and Enterprise Technology leaders to embed legal guidance into strategic technology initiatives and operational decision making. Advise on the cyber and data risk implications of emerging technologies, including AI, cloud, enterprise platforms, and evolving digital capabilities, enabling informed business decisions. Provide practical, risk based legal counsel that enables innovation while balancing cybersecurity, regulatory, and business objectives. Develop governance frameworks, policies, and controls that align with global legal and regulatory requirements, with a particular focus on cybersecurity considerations related to AI. Interpret evolving cybersecurity, AI, critical infrastructure, and technology regulations, translating legal requirements into practical business guidance. Partner with Government Affairs, Privacy, and other stakeholders to monitor and assess emerging legal and regulatory developments affecting cybersecurity and enterprise technology. Cyber