Cyber Governance & Policy Analyst

Johnson & Johnson MedTech

Warsaw (IN)

On-site

USD 79,000 - 142,000

Full time

25 hours ago
Be an early applicant
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Job summary

DePuy Synthes, part of Johnson & Johnson, is seeking a Professional, Governance & Policy Analyst to design, maintain, and operationalize the cybersecurity policy framework, risk methodology, and governance reporting across IT and business functions.

The role involves translating regulatory expectations into actionable standards, partnering with IT, Legal, Privacy, Quality, and Procurement, and supporting third-party risk oversight to strengthen a risk-informed culture.

Qualifications

  • Bachelor's degree in Information Technology, Cybersecurity, Information Systems, Risk Management, Business, or related discipline.
  • Master's degree in Cybersecurity, Information Systems, or Business Administration preferred
  • 4+ years of experience in cybersecurity governance, IT risk management, technology compliance, or a related GRC discipline.

Responsibilities

  • Own the cybersecurity policy and standards library — authoring, reviewing, and maintaining policies, standards, procedures, and guidelines on a defined lifecycle, including annual attestation and exception management.
  • Maintain and continuously improve the cyber risk management framework and methodology, including risk taxonomy, scoring criteria, risk appetite thresholds, and treatment/acceptance workflows.
  • Facilitate and document cyber risk assessments across applications, infrastructure, business processes, and change initiatives; capture outcomes in the enterprise risk register and track remediation to closure.
  • Administer the risk register as the single source of truth — ensuring completeness, accuracy, ownership assignment, aging analysis, and timely escalation of overdue or elevated risks.
  • Coordinate cybersecurity governance forums (e.g., Cyber Risk Council, steering committees), including agenda development, materials preparation, decision logging, and action item follow-through.
  • Develop and publish executive and operational reporting packages that translate technical risk data into clear business impact narratives for CIO, CISO, and leadership audiences.
  • Design, baseline, and report on cyber risk metrics and Key Risk Indicators (KRIs), establishing thresholds and trend analysis to drive proactive risk management.
  • Support third-party and vendor cyber risk oversight — including risk tiering, security questionnaire review, SOC 2 / ISO 27001 evidence evaluation, contractual security requirements, and ongoing monitoring of critical suppliers.

Skills

GRC governance
Policy drafting
Risk assessment
Security frameworks
Vendor risk

Education

Bachelor's degree in IT/Cybersecurity/Info Sys
Master's preferred

Tools

ServiceNow IRM
Archer
OneTrust
AuditBoard
Power BI
Tableau

Job description

DePuy Synthes, part of Johnson & Johnson, is seeking a Professional, Governance & Policy Analyst to design, maintain, and operationalize the cybersecurity policy framework, risk methodology, and governance reporting across IT and business functions.

The role involves translating regulatory expectations into actionable standards, partnering with IT, Legal, Privacy, Quality, and Procurement, and supporting third-party risk oversight to strengthen a risk-informed culture.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Cyber Governance & Policy Analyst
Cyber Governance & Policy Analyst

Johnson & Johnson MedTech • Raynham (MA)

On-site
USD 79,000 - 142,000
Strategic Cyber Governance & Policy Analyst
Strategic Cyber Governance & Policy Analyst

Johnson & Johnson Co. • New Brunswick (NJ)

On-site
USD 79,000 - 142,000
Cyber GRC Policy Strategist & Risk Lead
Cyber GRC Policy Strategist & Risk Lead

Johnson & Johnson MedTech • Raritan (NJ)

On-site
USD 79,000 - 142,000
Cyber Governance Lead: Policy, Risk & Compliance
Cyber Governance Lead: Policy, Risk & Compliance

Johnson & Johnson MedTech • New Brunswick (NJ)

On-site
USD 140,000 - 190,000
Strategic Cyber GRC Analyst
Strategic Cyber GRC Analyst

6090-Johnson & Johnson Services Inc. Legal Entity • New Brunswick (NJ)

Hybrid
USD 79,000 - 142,000
Professional Governance & Policy Analyst
Professional Governance & Policy Analyst

Johnson Johnson • New Brunswick (NJ)

On-site
USD 110,000 - 170,000
Cyber GRC Lead - Policy, Risk & Exec Reporting
Cyber GRC Lead - Policy, Risk & Exec Reporting

Antler Co • New Brunswick (NJ)

On-site
USD 140,000 - 190,000
Senior Cybersecurity GRC Lead
Senior Cybersecurity GRC Lead

Johnson Johnson • New Brunswick (NJ)

On-site
USD 120,000 - 180,000
Cyber Governance & Policy Analyst
Cyber Governance & Policy Analyst

Johnson Johnson • New Brunswick (NJ)

On-site
USD 110,000 - 170,000
Cyber GRC & Policy Lead | Enterprise Risk & Compliance
Cyber GRC & Policy Lead | Enterprise Risk & Compliance

Johnson & Johnson Co. • New Brunswick (NJ)

On-site
USD 140,000 - 180,000