Cyber Governance & Policy Strategist

Johnson & Johnson MedTech

New Brunswick (NJ)

On-site

USD 79,000 - 142,000

Full time

2 days ago
Be an early applicant
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Job summary

Johnson & Johnson, via DePuy Synthes, seeks a governance & policy Analyst to design and operationalize the cybersecurity policy framework. You will manage the policy library, risk assessments, and executive reporting for CIO/CISO audiences.

With 4+ years in cybersecurity governance, you will partner across IT, Legal, Privacy, and Quality to strengthen risk-informed decision-making and cyber culture.

Qualifications

  • Bachelor's degree in IT, Cybersecurity, or related field.
  • 4+ years in cybersecurity governance or IT risk management.
  • Experience drafting and maintaining security policies within governance lifecycle.
  • Knowledge of NIST CSF, NIST 800-53, ISO 27001/27002, COBIT.
  • Strong written communication; ability to translate risk for leadership.

Responsibilities

  • Own cybersecurity policy and standards library with lifecycle management.
  • Maintain cyber risk management framework, scoring, and workflows.
  • Run risk assessments across applications, infrastructure, and processes.
  • Administer enterprise risk register and remediation tracking.
  • Coordinate governance forums and executive reporting.
  • Develop policy communications and cyber culture initiatives.
  • Support third-party risk oversight including SOC 2 / ISO reviews.
  • Map policy controls to NIST/ISO/HIPAA/GDPR guidance.

Skills

Analytical reasoning
Communication
Risk assessments
Cybersecurity governance
Policy drafting
Leadership without authority

Education

Bachelor's in IT/Cybersecurity/Info Systems
Master's in Cybersecurity/Business Administration (preferred)

Tools

Power BI
Tableau
SOC 2 / ISO 27001 evidence tools
OneTrust / Archer (GRC tools)

Job description

Johnson & Johnson, via DePuy Synthes, seeks a governance & policy Analyst to design and operationalize the cybersecurity policy framework. You will manage the policy library, risk assessments, and executive reporting for CIO/CISO audiences.

With 4+ years in cybersecurity governance, you will partner across IT, Legal, Privacy, and Quality to strengthen risk-informed decision-making and cyber culture.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Cyber Governance & Policy Analyst
Cyber Governance & Policy Analyst

Johnson & Johnson MedTech • Raynham (MA)

On-site
USD 79,000 - 142,000
Cyber Governance & Policy Analyst
Cyber Governance & Policy Analyst

Antler Co • Warsaw (IN)

On-site
USD 79,000 - 142,000
Travel up to 15% domestically
Cyber Governance & Policy Analyst
Cyber Governance & Policy Analyst

Johnson & Johnson MedTech • Warsaw (IN)

On-site
USD 79,000 - 142,000
Strategic Cyber GRC Analyst
Strategic Cyber GRC Analyst

6090-Johnson & Johnson Services Inc. Legal Entity • New Brunswick (NJ)

Hybrid
USD 79,000 - 142,000
Cyber Governance & Policy Analyst — Risk & Compliance
Cyber Governance & Policy Analyst — Risk & Compliance

Antler Co • Raritan (NJ)

On-site
USD 79,000 - 142,000
Cyber Governance & Policy Analyst
Cyber Governance & Policy Analyst

Johnson & Johnson MedTech • Town of Florida (NY)

On-site
USD 79,000 - 142,000
Senior Cyber GRC Policy Analyst
Senior Cyber GRC Policy Analyst

Antler Co • Raynham (MA)

On-site
USD 79,000 - 142,000
Cyber GRC Policy Strategist & Risk Lead
Cyber GRC Policy Strategist & Risk Lead

Johnson & Johnson MedTech • Raritan (NJ)

On-site
USD 79,000 - 142,000
Cyber GRC Policy Analyst — Drive Risk & Compliance
Cyber GRC Policy Analyst — Drive Risk & Compliance

Johnson & Johnson MedTech • West Chester

On-site
USD 79,000 - 142,000
Cyber GRC Policy Analyst: Risk, Policy & Reporting
Cyber GRC Policy Analyst: Risk, Policy & Reporting

Antler Co • Town of Florida (NY)

On-site
USD 79,000 - 142,000