Sr. Manager, Supply Chain Cybersecurity
Johnson & Johnson Ver todas as vagas
- São José dos Campos - SP
- Permanente
- Período integral
- Provide early/proactive engagement with project teams to drive business understanding and execution of the security capabilities and services needed for the project; End to end support for large programs.
- Perform cybersecurity risk assessments of IT/OT assets within the manufacturing sites.
- Drive cybersecurity capability adoption across Surgery sites to secure IT/OT assets and enable safe & secure innovation.
- Provide tailored security guidance (based on risk and complexity) - Interpret & apply the internal security requirements and standards for unique IT/OT (Operational Technology) initiatives and innovative or OT Specific technologies.
- Lead the cyber operational portfolio from identification > consulting remediation plan > completion partnering across ISRM, business, and technology teams.
- Establish data analytics to provide security posture across Surgery business units, functions, and sites.
- Proactively promote the importance of cybersecurity across the sector and sites.
- Assist the Security Operations Center (SOC) with security incident investigation activities; work closely with business teams to support affected users and provide liaison with central investigation team.
- Drive business understanding of critical cybersecurity regulations and ensuring solutions are compliant (NIST, NIS2, Safe Data, etc.).
- Support the global deployment of security initiatives with awareness sessions, identify alternative ways of working to avoid business disruptions, and review exception requests
- Provide audit support as the liaison between audit, technology, and business functions from pre-work to consulting remediation plans.
- 8+ years of related experience in leadership and execution roles within Cybersecurity with background in Supply Chain required.
- Bachelor’s degree in computer science, information technology, business administration, or another rigorous discipline is required. MBA preferred.
- 6+ years of hands-on experience in delivering technology; and cybersecurity design and capabilities required.
- Certifications in cybersecurity (CISM, CISSP, ISA-62443), audit (CISA), manufacturing or risk management (CRISC) are preferred.
- Excellent communication and collaboration skills, able to network, interface and influence at all levels of the organization, cross sector, cross-functionally and globally.
- Strategic mindset to develop capability roadmaps that will enable proactive reliability through data & automation.
- Experience in working/securing various levels of the enterprise architecture (data, application, host, middleware, network, Infrastructure).
- Solid understanding of current security threats, mitigation measures, and security vendors/technologies.
- Strong understanding of security data protection and capabilities in a manufacturing and/or distribution site is required.
- Direct working and/or supporting experience of Supply Chain applications is required; Sarbanes-Oxley compliance and audit is preferred.
- Understanding of ISA/IEC 62443, NIST 800-53, and NIST 800-82 required
- Leading diverse team members with varying cybersecurity experience and proficient in resource allocation and planning to meet business needs.
- Big picture perspective and attention to detail focus to align strategic and tactical security aspects.
- Ability to collaborate, network and influence all levels of the organization, cross sector, cross-function and global and establish oneself as an inspiring leader with expertise in space.
- AI Fluency and background In AI use cases preferred