Senior Legal Director, Cyber & Data Risk
Johnson & Johnson
August 25, 2026
Remote friendly (Washington, DC)
United States
Corporate Functions
Senior Legal Director, Cyber & Data Risk (Technology Advisory Legal)
Responsibilities:
- Principal legal advisor to CISO and ISRM leadership on cybersecurity, enterprise technology risk, data risk, and complex legal matters.
- Advise executive leadership on legal implications of strategic decisions, emerging risks, and regulatory requirements for the organizationβs cybersecurity strategy.
- Partner with enterprise technology to embed legal guidance into technology initiatives; advise on AI, cloud, and platform risk; translate regulations into business guidance.
- Lead legal support for significant cybersecurity incidents, vulnerabilities, crisis response, and regulatory matters; advise on SEC/other disclosure obligations and government/law-enforcement interactions.
- Counsel on asset protection, insider risk, IP misappropriation, employee data theft, and related investigations.
- Advise on enterprise data protection, information governance, cross-border data flows, and data risk; align practices with privacy and ethical standards.
- Advise on cybersecurity/product security provisions in technology agreements; counsel on risks in M&A, divestitures, partnerships, and sourcing; manage outside counsel as needed.
- Lead/develop cybersecurity legal team; collaborate across legal and business functions.
Qualifications:
- JD required; admitted to practice and in good standing in at least one US jurisdiction.
- 12+ years relevant legal experience with significant cybersecurity experience.
- Experience advising senior executives; leading crisis/incident/regulatory support.
- Deep knowledge of global cybersecurity/data/critical infrastructure/technology/AI governance.
- Experience drafting/negotiating cybersecurity/technology/product security contracts; M&A cybersecurity risk experience.
- Leadership, executive communication, stakeholder management, digital fluency; travel ~10%.
- Preferred: law firm cybersecurity investigations/enforcement/regulatory support; preferred in-house global experience.
Skills (Required/Preferred):
- Negotiation, risk management, compliance/corporate governance, strategic thinking, lawyering, dispute resolution, vendor management, leadership/developing others, inclusive leadership, legal document preparation, legal services, representing.
Benefits (time off):
- Vacation 120h/yr; Sick 40h/yr (CO 48h; WA 56h); Holiday 13 days/yr; Work/Personal/Family up to 40h/yr; Parental leave 480h; Bereavement 240h (immediate) / 40h extended; Caregiver leave 80h; Volunteer 32h; Military spouse time-off 80h.
Responsibilities:
- Principal legal advisor to CISO and ISRM leadership on cybersecurity, enterprise technology risk, data risk, and complex legal matters.
- Advise executive leadership on legal implications of strategic decisions, emerging risks, and regulatory requirements for the organizationβs cybersecurity strategy.
- Partner with enterprise technology to embed legal guidance into technology initiatives; advise on AI, cloud, and platform risk; translate regulations into business guidance.
- Lead legal support for significant cybersecurity incidents, vulnerabilities, crisis response, and regulatory matters; advise on SEC/other disclosure obligations and government/law-enforcement interactions.
- Counsel on asset protection, insider risk, IP misappropriation, employee data theft, and related investigations.
- Advise on enterprise data protection, information governance, cross-border data flows, and data risk; align practices with privacy and ethical standards.
- Advise on cybersecurity/product security provisions in technology agreements; counsel on risks in M&A, divestitures, partnerships, and sourcing; manage outside counsel as needed.
- Lead/develop cybersecurity legal team; collaborate across legal and business functions.
Qualifications:
- JD required; admitted to practice and in good standing in at least one US jurisdiction.
- 12+ years relevant legal experience with significant cybersecurity experience.
- Experience advising senior executives; leading crisis/incident/regulatory support.
- Deep knowledge of global cybersecurity/data/critical infrastructure/technology/AI governance.
- Experience drafting/negotiating cybersecurity/technology/product security contracts; M&A cybersecurity risk experience.
- Leadership, executive communication, stakeholder management, digital fluency; travel ~10%.
- Preferred: law firm cybersecurity investigations/enforcement/regulatory support; preferred in-house global experience.
Skills (Required/Preferred):
- Negotiation, risk management, compliance/corporate governance, strategic thinking, lawyering, dispute resolution, vendor management, leadership/developing others, inclusive leadership, legal document preparation, legal services, representing.
Benefits (time off):
- Vacation 120h/yr; Sick 40h/yr (CO 48h; WA 56h); Holiday 13 days/yr; Work/Personal/Family up to 40h/yr; Parental leave 480h; Bereavement 240h (immediate) / 40h extended; Caregiver leave 80h; Volunteer 32h; Military spouse time-off 80h.