Cyber Governance Lead: Policy, Risk & Compliance

Johnson & Johnson MedTech

New Brunswick (NJ)

On-site

USD 140,000 - 190,000

Full time

2 days ago
Be an early applicant
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Job summary

Johnson & Johnson's DePuy Synthes is recruiting a Professional, Compliance Lead to lead cybersecurity governance and risk across the enterprise. The role sits in the Cybersecurity function and interfaces with Internal Audit, Legal, Privacy, Quality, and regulators.

You will own policy, risk methodology, KRIs, third-party risk oversight, and executive reporting to CIO/CISO and senior leadership. This position supports cloud, ERP, and major platform changes while advancing cyber culture

Qualifications

  • 6 years of progressive experience in cybersecurity governance, IT risk management, or a GRC discipline.
  • Ownership of a security policy and standards framework with governance lifecycle and approvals.
  • Advanced knowledge of NIST CSF, NIST 800-53, ISO 27001/27002, COBIT; cross-framework rationalization.

Responsibilities

  • Lead end-to-end cybersecurity policy and standards program; govern content, attestations, and exceptions.
  • Define and maintain enterprise cyber risk framework, scoring model, risk appetite, and escalation thresholds.
  • Direct the cyber risk assessment program across applications, infrastructure, and major changes; ensure method consistency.

Skills

GRC governance
Policy ownership
NIST CSF knowledge
Risk reporting
Third-party risk
Facilitation

Education

Security certifications

Tools

ServiceNow IRM
Archer
OneTrust
AuditBoard
Power BI
SQL

Job description

Johnson & Johnson's DePuy Synthes is recruiting a Professional, Compliance Lead to lead cybersecurity governance and risk across the enterprise. The role sits in the Cybersecurity function and interfaces with Internal Audit, Legal, Privacy, Quality, and regulators.

You will own policy, risk methodology, KRIs, third-party risk oversight, and executive reporting to CIO/CISO and senior leadership. This position supports cloud, ERP, and major platform changes while advancing cyber culture

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Cyber GRC Lead - Policy, Risk & Exec Reporting
Cyber GRC Lead - Policy, Risk & Exec Reporting

Antler Co • New Brunswick (NJ)

On-site
USD 140,000 - 190,000
Senior Cybersecurity GRC Lead
Senior Cybersecurity GRC Lead

Johnson Johnson • New Brunswick (NJ)

On-site
USD 120,000 - 180,000
Cyber Governance & Policy Analyst
Cyber Governance & Policy Analyst

Johnson & Johnson MedTech • Raynham (MA)

On-site
USD 79,000 - 142,000
Cyber GRC & Policy Lead | Enterprise Risk & Compliance
Cyber GRC & Policy Lead | Enterprise Risk & Compliance

Johnson & Johnson Co. • New Brunswick (NJ)

On-site
USD 140,000 - 180,000
Cyber GRC Policy Strategist & Risk Lead
Cyber GRC Policy Strategist & Risk Lead

Johnson & Johnson MedTech • Raritan (NJ)

On-site
USD 79,000 - 142,000
Cyber Governance & Policy Analyst
Cyber Governance & Policy Analyst

Johnson & Johnson MedTech • Warsaw (IN)

On-site
USD 79,000 - 142,000
Strategic Cyber Governance & Policy Analyst
Strategic Cyber Governance & Policy Analyst

Johnson & Johnson Co. • New Brunswick (NJ)

On-site
USD 79,000 - 142,000
Strategic Cyber GRC Analyst
Strategic Cyber GRC Analyst

6090-Johnson & Johnson Services Inc. Legal Entity • New Brunswick (NJ)

Hybrid
USD 79,000 - 142,000
Professional, Compliance Lead
Professional, Compliance Lead

Johnson Johnson • New Brunswick (NJ)

On-site
USD 120,000 - 180,000
Professional Governance & Policy Analyst
Professional Governance & Policy Analyst

Johnson Johnson • New Brunswick (NJ)

On-site
USD 110,000 - 170,000