- Company Name
- Johnson & Johnson
- Job Title
- Manager- Cybersecurity Investigations
- Job Description
-
**Job Title:** Manager – Cybersecurity Investigations
**Role Summary:**
Lead the Insider Risk Investigation team within Information Security & Risk Management, driving the detection, investigation, and remediation of data exfiltration incidents. Coordinate across HR, Legal, Audit, Physical Security, and Cyberforensic departments to protect enterprise data assets and uphold compliance standards.
**Expectations:**
- Manage a high‑volume investigation workload, ensuring timely, accurate case completion and reporting.
- Champion continuous improvement of investigative processes, playbooks, and SOPs.
- Maintain strict confidentiality and professional judgment while interfacing with senior leadership, legal counsel, and law enforcement.
**Key Responsibilities:**
- Partner with cross‑functional stakeholders (HR, Audit, Legal, Physical Security, Cyberforensics) to execute insider risk investigations.
- Assess data exfiltration events, determine business impact, and recommend corrective actions.
- Conduct interviews with subjects and witnesses, identifying intent, credibility, and motives.
- Collect, analyze, and interpret digital forensics, DLP alerts, and other security data.
- Maintain case management records, producing status updates, metrics, and final reports.
- Develop and update investigative playbooks and SOPs for repeatable, defensible procedures.
- Advise subject–matter experts on technical remediation and secure data handling.
- Escalate high‑risk events to leadership and coordinate with 3rd‑party forensic vendors.
- Deliver case debriefs to technical and non‑technical audiences, including legal counsel and law enforcement.
**Required Skills:**
- 5+ years of experience in insider risk, cybersecurity, or technical investigations.
- Strong knowledge of data security, data egress concepts, and DLP systems.
- Proven interview and subject inquiry skills (minimum 3 years).
- Expertise in interpreting cyber‑forensic reports from end‑user devices and network systems.
- Ability to manage or work with external forensic providers and data‑sanitization vendors.
- Excellent listening, questioning, and analytical abilities.
- Adaptability to dynamic risk‑based task prioritization.
- Familiarity with U.S. statutes 18 U.S.C. § 1831 & § 1832.
- Commitment to confidentiality and secure communication of sensitive information.
**Required Education & Certifications:**
- Bachelor’s degree (BA/BS) in Computer Science, Information Security, Criminal Justice, or related field.
---