Cyber Governance & Policy Analyst

Johnson Johnson

New Brunswick (NJ)

On-site

USD 110,000 - 170,000

Full time

3 days ago
Be an early applicant
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Job summary

Johnson & Johnson is seeking a Professional, Governance & Policy Analyst within Cybersecurity, GRC, IT Controls & Cyber Culture. The role designs and maintains the policy framework, risk methodology, and governance reporting, partnering with IT, Legal, Privacy, Quality, Procurement, and business functions to inform risk-aware decisions.

The analyst supports audit, regulatory inquiries, and third‑party assessments, driving automation and consistent evidence collection across the enterprise.

Qualifications

  • Bachelor's degree in Informat or related field.
  • Experience applying GRC frameworks to translate regulatory expectations into standards.
  • Strong collaboration with IT, Legal, Privacy, Quality, Procurement, and business functions.

Responsibilities

  • Own the cybersecurity policy and standards library and maintain lifecycle documents.
  • Manage cyber risk assessments across apps, infra, and processes; update enterprise risk register.
  • Coordinate governance forums and produce executive reporting for CIO/CISO and leadership.
  • Develop cyber risk KPIs and KRIs with thresholds and trend analysis.
  • Support third-party risk oversight, including vendor risk and evidence evaluation.
  • Map policy requirements to frameworks like NIST CSF, ISO 27001, HIPAA, GDPR; maintain crosswalks.

Education

Bachelor's degree in Informat

Job description

Johnson & Johnson is seeking a Professional, Governance & Policy Analyst within Cybersecurity, GRC, IT Controls & Cyber Culture. The role designs and maintains the policy framework, risk methodology, and governance reporting, partnering with IT, Legal, Privacy, Quality, Procurement, and business functions to inform risk-aware decisions.

The analyst supports audit, regulatory inquiries, and third‑party assessments, driving automation and consistent evidence collection across the enterprise.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Cyber GRC Policy Strategist & Risk Lead
Cyber GRC Policy Strategist & Risk Lead

Johnson & Johnson MedTech • Raritan (NJ)

On-site
USD 79,000 - 142,000
Cyber Governance & Policy Analyst
Cyber Governance & Policy Analyst

Johnson & Johnson MedTech • Raynham (MA)

On-site
USD 79,000 - 142,000
Strategic Cyber GRC Analyst
Strategic Cyber GRC Analyst

6090-Johnson & Johnson Services Inc. Legal Entity • New Brunswick (NJ)

Hybrid
USD 79,000 - 142,000
Cyber Governance & Policy Analyst
Cyber Governance & Policy Analyst

Johnson & Johnson MedTech • Warsaw (IN)

On-site
USD 79,000 - 142,000
Professional Governance & Policy Analyst
Professional Governance & Policy Analyst

Johnson Johnson • New Brunswick (NJ)

On-site
USD 110,000 - 170,000
Cyber Risk & Compliance Leader
Cyber Risk & Compliance Leader

6090-Johnson & Johnson Services Inc. Legal Entity • New Brunswick (NJ)

On-site
USD 140,000 - 200,000
Cyber GRC Lead - Policy, Risk & Exec Reporting
Cyber GRC Lead - Policy, Risk & Exec Reporting

Antler Co • New Brunswick (NJ)

On-site
USD 140,000 - 190,000
Senior Cybersecurity GRC Lead
Senior Cybersecurity GRC Lead

Johnson Johnson • New Brunswick (NJ)

On-site
USD 120,000 - 180,000
Strategic Cyber Governance & Policy Analyst
Strategic Cyber Governance & Policy Analyst

Johnson & Johnson Co. • New Brunswick (NJ)

On-site
USD 79,000 - 142,000
Cyber GRC & Policy Lead | Enterprise Risk & Compliance
Cyber GRC & Policy Lead | Enterprise Risk & Compliance

Johnson & Johnson Co. • New Brunswick (NJ)

On-site
USD 140,000 - 180,000