Cyber GRC Lead - Policy, Risk & Exec Reporting

Antler Co

New Brunswick (NJ)

On-site

USD 140,000 - 190,000

Full time

4 days ago
Be an early applicant
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Job summary

Johnson & Johnson's DePuy Synthes unit seeks a seasoned Professional, Compliance Lead to steer cybersecurity governance and risk across the org. Lead policy, risk frameworks, and third-party oversight while coordinating with internal audit and regulators.

The role requires expertise in GRC, frameworks like NIST/ISO, and strong stakeholder engagement to ensure robust controls and executive reporting.

Qualifications

  • 6 years of progressive experience in cybersecurity governance or related GRC discipline.
  • Owns security policy and standards framework with lifecycle governance.
  • Experience designing and operating enterprise risk registers and KRIs.
  • Strong working knowledge of NIST CSF, NIST 800-53, ISO 27001/27002, COBIT.
  • Proven ability to lead third-party cyber risk programs and audits.
  • Proficiency with data visualization tools for executive risk reporting.
  • Hands-on experience with GRC platforms and cloud governance.
  • Experience liaising with Internal Audit, Legal, Privacy, QA and regulators.

Responsibilities

  • Lead cybersecurity policy and standards program from design to review and attestation.
  • Define enterprise cyber risk framework, scoring, appetite, and escalation thresholds.
  • Run cyber risk assessments across applications, infra, and change programs.
  • Maintain enterprise cyber risk register with data quality and timely escalation.
  • Chair governance forums and document decisions and actions.
  • Develop executive risk reporting for CIO, CISO, and leaders.
  • Define KRIs and predictive signals for proactive intervention.
  • Oversee third-party cyber risk using vendor tiering and security requirements.
  • Maintain regulatory mapping (HIPAA, GDPR, FDA guidance, SOX ITGC).
  • Collaborate with IT Controls and SOX teams for coherent assurance.
  • Coordinate with Internal Audit, regulators, and customer assessments.
  • Assess impact of cloud migrations and platform changes pre-go-live.
  • Drive cyber culture through policy communications and training.
  • Identify automation opportunities in GRC workflows and reporting.

Skills

NIST CSF
NIST 800-53
ISO 27001/27002
COBIT
Vendor risk management
GRC governance
Power BI
Tableau
SQL
cloud governance
ISMS
Security policies

Tools

ServiceNow IRM
Archer
OneTrust
AuditBoard

Job description

Johnson & Johnson's DePuy Synthes unit seeks a seasoned Professional, Compliance Lead to steer cybersecurity governance and risk across the org. Lead policy, risk frameworks, and third-party oversight while coordinating with internal audit and regulators.

The role requires expertise in GRC, frameworks like NIST/ISO, and strong stakeholder engagement to ensure robust controls and executive reporting.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Senior Cybersecurity GRC Lead
Senior Cybersecurity GRC Lead

Johnson Johnson • New Brunswick (NJ)

On-site
USD 120,000 - 180,000
Cyber GRC & Policy Lead | Enterprise Risk & Compliance
Cyber GRC & Policy Lead | Enterprise Risk & Compliance

Johnson & Johnson Co. • New Brunswick (NJ)

On-site
USD 140,000 - 180,000
Cyber Governance Lead: Policy, Risk & Compliance
Cyber Governance Lead: Policy, Risk & Compliance

Johnson & Johnson MedTech • New Brunswick (NJ)

On-site
USD 140,000 - 190,000
Cyber GRC Policy Strategist & Risk Lead
Cyber GRC Policy Strategist & Risk Lead

Johnson & Johnson MedTech • Raritan (NJ)

On-site
USD 79,000 - 142,000
Strategic Cyber GRC Analyst
Strategic Cyber GRC Analyst

6090-Johnson & Johnson Services Inc. Legal Entity • New Brunswick (NJ)

Hybrid
USD 79,000 - 142,000
Cyber Governance & Policy Analyst
Cyber Governance & Policy Analyst

Johnson & Johnson MedTech • Raynham (MA)

On-site
USD 79,000 - 142,000
Professional, Compliance Lead
Professional, Compliance Lead

Johnson Johnson • New Brunswick (NJ)

On-site
USD 120,000 - 180,000
Strategic Cyber Governance & Policy Analyst
Strategic Cyber Governance & Policy Analyst

Johnson & Johnson Co. • New Brunswick (NJ)

On-site
USD 79,000 - 142,000
Cyber Risk & Compliance Leader
Cyber Risk & Compliance Leader

6090-Johnson & Johnson Services Inc. Legal Entity • New Brunswick (NJ)

On-site
USD 140,000 - 200,000
Cyber Governance & Policy Analyst
Cyber Governance & Policy Analyst

Johnson & Johnson MedTech • Warsaw (IN)

On-site
USD 79,000 - 142,000