Cyber Governance & Policy Analyst — Risk & Compliance

Antler Co

Raritan (NJ)

On-site

USD 79,000 - 142,000

Full time

5 days ago
Be an early applicant
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Job summary

Johnson & Johnson, a leader in healthcare, seeks a Professional, Governance & Policy Analyst to design and operationalize the cybersecurity policy framework and risk management processes. You will own the policy library, govern risk assessments, and produce leadership-ready reporting across IT, Legal, Privacy, Quality, and Procurement.

The role partners with multiple functions to strengthen risk-informed decisions and cyber culture.

Qualifications

  • Bachelor's degree in IT, Cybersecurity, Information Systems or related field.
  • Master's degree in Cybersecurity, Information Systems, or MBA preferred.
  • 4+ years of experience in cybersecurity governance, IT risk management, technology compliance, or related GRC.
  • Experience authoring and maintaining security policies within a formal governance lifecycle.
  • Knowledge of NIST CSF, NIST 800-53, ISO 27001/27002, and COBIT.
  • Experience supporting governance forums and producing leadership-ready reporting.
  • Proficiency with GRC platforms (ServiceNow IRM, Archer, OneTrust, AuditBoard) and workflow configuration.

Responsibilities

  • Own the cybersecurity policy and standards library: authoring, reviewing, and maintaining policies and procedures.
  • Maintain and improve the cyber risk management framework and methodology.
  • Facilitate and document cyber risk assessments across applications and processes.
  • Administer the risk register as the single source of truth.
  • Coordinate cybersecurity governance forums and document decisions.
  • Develop executive reporting packages translating risk data for leadership.
  • Design and report cyber risk metrics and KRIs.
  • Support third-party/vendor risk oversight and evidence evaluation.
  • Map policy requirements to external frameworks and maintain crosswalks.
  • Collaborate with IT Controls and SOX to align governance with control design.
  • Drive cyber culture through policy communications and training.
  • Assess governance impact of tech changes and go-live requirements.
  • Support audits, regulatory inquiries, and customer security assessments.
  • Identify opportunities to automate GRC workflows and evidence collection.

Skills

Cybersecurity governance
IT risk management
Technology compliance
GRC discipline
Policy drafting
Security frameworks
Risk assessments
Leadership-ready reporting

Education

Bachelor's degree in IT / Cybersecurity / Information Systems
Master's degree in Cybersecurity / Information Systems / MBA (preferred)

Tools

ServiceNow IRM
Archer
OneTrust
AuditBoard
Power BI
Tableau
AWS
Azure

Job description

Johnson & Johnson, a leader in healthcare, seeks a Professional, Governance & Policy Analyst to design and operationalize the cybersecurity policy framework and risk management processes. You will own the policy library, govern risk assessments, and produce leadership-ready reporting across IT, Legal, Privacy, Quality, and Procurement.

The role partners with multiple functions to strengthen risk-informed decisions and cyber culture.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Cyber Governance & Policy Strategist
Cyber Governance & Policy Strategist

Johnson & Johnson MedTech • New Brunswick (NJ)

On-site
USD 79,000 - 142,000
Cyber Governance & Policy Analyst
Cyber Governance & Policy Analyst

Johnson & Johnson MedTech • Raynham (MA)

On-site
USD 79,000 - 142,000
Cyber GRC Policy Analyst — Drive Risk & Compliance
Cyber GRC Policy Analyst — Drive Risk & Compliance

Johnson & Johnson MedTech • West Chester

On-site
USD 79,000 - 142,000
Cyber Governance & Policy Analyst
Cyber Governance & Policy Analyst

Antler Co • Warsaw (IN)

On-site
USD 79,000 - 142,000
Travel up to 15% domestically
Cyber Governance & Policy Analyst
Cyber Governance & Policy Analyst

Johnson & Johnson MedTech • Town of Florida (NY)

On-site
USD 79,000 - 142,000
Cyber GRC Policy Analyst: Risk, Policy & Reporting
Cyber GRC Policy Analyst: Risk, Policy & Reporting

Antler Co • Town of Florida (NY)

On-site
USD 79,000 - 142,000
Cyber GRC Policy Strategist & Risk Lead
Cyber GRC Policy Strategist & Risk Lead

Johnson & Johnson MedTech • Raritan (NJ)

On-site
USD 79,000 - 142,000
Senior Cyber GRC Policy Analyst
Senior Cyber GRC Policy Analyst

Antler Co • Raynham (MA)

On-site
USD 79,000 - 142,000
Cyber GRC Policy & Risk Analyst
Cyber GRC Policy & Risk Analyst

Antler Co • New Brunswick (NJ)

On-site
USD 79,000 - 142,000
Travel up to 15% domestic travel
Strategic Cyber GRC Analyst
Strategic Cyber GRC Analyst

6090-Johnson & Johnson Services Inc. Legal Entity • New Brunswick (NJ)

Hybrid
USD 79,000 - 142,000