Shire Veteran Jobs

Job Information

J&J Family of Companies OT Cybersecurity Senior Manager in Warsaw, Poland

At Johnson & Johnson, we believe health is everything. Our strength in healthcare innovation empowers us to build a world where complex diseases are prevented, treated, and cured, where treatments are smarter and less invasive, and solutions are personal. Through our expertise in Innovative Medicine and MedTech, we are uniquely positioned to innovate across the full spectrum of healthcare solutions today to deliver the breakthroughs of tomorrow, and profoundly impact health for humanity. Learn more at https://www.jnj.com

Job Function:

Technology Enterprise Strategy & Security

Job Sub Function:

Security & Controls

Job Category:

People Leader

All Job Posting Locations:

Warsaw, Masovian, Poland

Job Description:

Johnson & Johnson is recruiting for an Operational Technology (OT) Cybersecurity Senior Manager, located in Warsaw, Poland.

As a part of the Information Security Risk Management (ISRM) organization, the cybersecurity senior manager will advance the security program which covers Johnson and Johnson’s supply chain and research and development environments to protect our patients and critical operations. The lead will ensure strong controls are in place at our sites for applications, infrastructure, industrial IoT, automation equipment, site security and third-party vendor risk.

The cybersecurity senior manager will play a significant role to:

  • Drive the advancement of the cyber security strategy for the J&J (Johnson & Johnson) global R&D and supply chain.

  • Develop the OT security framework to ensure controls are implemented and matured across our sites.

  • Develop the security services needed to ensure consistent and sustained controls across our industrial environment.

  • Measure and lead the teams implementing necessary capabilities and partner with business and technology team members to deploy and drive adoption.

  • Enhance security capabilities and build training material for team members to strengthen risk and vulnerability management, cybersecurity controls and governance.

  • Incorporate insights on emerging threats, technologies, and capabilities from the industry landscape into the OT cybersecurity program

Key Responsibilities include:

Work with the broader security team to design and deploy risk sensing, automation, and analytics solutions for critical security controls to advance vulnerability management and improve the risk posture of the OT environment.

Provide requirements to the engineering teams to advance critical capabilities in the industrial security stack.

Strengthen and accelerate the governance framework, including technical standards, training materials, and implementation guidelines to provide transparency of risk posture and improvements.

Continuously improve the OT cyber security framework by enhancing the coverage and integration security tools and design patterns (e.g., ICE (Isolated Computing Environment) firewall deployments, IDR, AV, SIEM, deception technology).

Actively monitor new threats and vulnerabilities, engaging IT (Information Technology) and Engineering teams on appropriate actions to address them.

Ensure achievement of team goals within established timelines and budgets, and integrates Johnson & Johnson’s Credo and Leadership Imperatives into team goals and decision making.

Qualifications

Education:

  • BA/BS or comparable security experience, certifications, or military security experience.

Required Experience and Skills:

  • Consistent record in IT and/or Engineering with a security focus is required with 10 or more years of experience of demonstrated experience.

  • Demonstrated ability with Operational Technology environments, security technologies and controls (e.g., remote access, access control, firewalls, IDS/IPS, anti-malware, patch management, encryption technologies, forensics etc.) is required.

  • Knowledge of the security landscape including trends in process, tooling and threats is required. Understanding of cloud, virtualized environments and emerging digital capabilities is required.

  • Results orientation with ability to handle timelines required.

Preferred Experience and Skills:

  • Experience performing security audits and assessments based on technical security frameworks such as NIST (National Institute of Standards and Technology) 800-53/800-82, ISO 27001, IEC (International Electrotechnical Commission) 62443, etc..

  • Experience analyzing IT and Operational Technology architecture to identify security gaps and designing solutions.

  • Understanding penetration testing and penetration testing tools.

  • Experience working within an incident response team.

  • Experience working in a manufacturing or lab environment, or with automation control systems

  • Strong interpersonal and creative problem-solving skills, with a focus on (internal and external) customers are desirable.

  • Self-starter, eager to learn and develop new skills, while demonstrating the ability to work independently .

Other:

  • 10% domestic and international travel

  • CISSP, CISM, etc. preferred

Johnson & Johnson is an Affirmative Action and Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, age, national origin, or protected veteran status and will not be discriminated against on the basis of disability.

DirectEmployers