OT Cybersecurity Manager
PL002 Iłżecka, Poland
Johnson & Johnson
We’re building a world where complex diseases are prevented and cured, treatments are smarter and less invasive—and solutions are personal.At Johnson & Johnson, we believe health is everything. Our strength in healthcare innovation empowers us to build a world where complex diseases are prevented, treated, and cured, where treatments are smarter and less invasive, and solutions are personal. Through our expertise in Innovative Medicine and MedTech, we are uniquely positioned to innovate across the full spectrum of healthcare solutions today to deliver the breakthroughs of tomorrow, and profoundly impact health for humanity. Learn more at https://www.jnj.com
Job Function:
Technology Enterprise Strategy & SecurityJob Sub Function:
Security & ControlsJob Category:
Scientific/TechnologyAll Job Posting Locations:
São José dos Campos, São Paulo, Brazil, São Paulo, Brazil, Warsaw, Masovian, PolandJob Description:
The cybersecurity manager will advance the security program which covers Johnson and Johnson’s supply chain and research and development environments to protect our patients and critical operations. The person in this role will ensure strong controls are in place at our sites for applications, infrastructure, industrial IoT, automation equipment, site security and third-party vendor risk.
This position will play a meaningful role to:
- Develop the OT security framework to ensure controls are implemented across our sites.
- Build training material for security team members and support partners to strengthen risk and vulnerability management, cybersecurity controls and governance.
- Implement security capabilities needed, partner with business partners to deploy and assist with adoption.
- Drive the advancement of the cyber security strategy for the J&J (Johnson & Johnson) global R&D and supply chain.
- Incorporate insights on emerging threats, technologies, and capabilities from the industry landscape into the OT cybersecurity program
Key Responsibilities include:
- Working with the broader security team to design and deploy risk sensing, automation, and analytics solutions for critical security controls to advance vulnerability management and improve the risk posture of the OT environment.
- Providing requirements to the engineering teams to advance threat monitoring and detection.
- Strengthening the governance framework, including technical standards, training materials, and implementation guidelines to provide visibility of risk posture and improvements.
- Continuously improve the OT cyber security framework by enhancing the coverage and integration security tools and design patterns (e.g., ICE (Isolated Computing Environment) firewall deployments, IDR, AV, SIEM, deception technology).
- Actively monitor new threats and vulnerabilities, engaging IT (Information Technology) and Engineering teams on appropriate actions to address them.
Education:
- BA/BS or comparable security experience, certifications, or military security experience.
Required Experience and Skills:
- Consistent record in IT and/or Engineering with a security focus is required with 8 or more years of experience.
- Demonstrated ability with Operational Technology environments, security technologies and controls (e.g., remote access, access control, firewalls, IDP/IDR, anti-malware, patch management, encryption technologies, forensics etc.) is required.
- Knowledge of the security landscape including trends in process, tooling and threats is required. Understanding of cloud, virtualized environments and emerging digital capabilities is required.
- Results orientation with ability to handle timelines required.
Preferred Experience and Skills:
- Experience performing security audits and assessments based on technical security frameworks such as NIST (National Institute of Standards and Technology) 800-53/800-82, ISO 27001, IEC (International Electrotechnical Commission) 62443, etc..
- Experience analyzing IT and Operational Technology architecture to identify security gaps and designing solutions.
- Understanding penetration testing and penetration testing tools.
- Experience working within an incident response team.
- Strong interpersonal and creative problem-solving skills, with a focus on (internal and external) customers are desirable.
- Self-starter, eager to learn and develop new skills, while demonstrating the ability to work independently .
Other:
- 10% domestic and international travel
- CISSP, CISM, etc. preferred
Johnson & Johnson is an Affirmative Action and Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, age, national origin, or protected veteran status and will not be discriminated against on the basis of disability.
* Salary range is an estimate based on our InfoSec / Cybersecurity Salary Index 💰
Tags: Analytics Audits Automation CISM CISSP Cloud Encryption Firewalls Forensics Governance Incident response Industrial IoT ISO 27001 Malware Monitoring NIST NIST 800-53 Pentesting R&D Security strategy SIEM Strategy Vulnerabilities Vulnerability management
Perks/benefits: Career development
More jobs like this
Explore more career opportunities
Find even more open roles below ordered by popularity of job title or skills/products/technologies used.