Cyber GRC Policy Analyst — Drive Risk & Compliance

Johnson & Johnson MedTech

West Chester (Chester County)

On-site

USD 79,000 - 142,000

Full time

2 days ago
Be an early applicant
Application generator

Stand out for this role — generate a tailored resume and cover letter in about a minute.

Get past ATS filters

Job summary

Johnson & Johnson is seeking a Professional, Governance & Policy Analyst within DePuy Synthes to design, maintain, and operationalize the cybersecurity policy framework and risk governance model. This individual contributor role partners with IT, Legal, Privacy, Quality, Procurement, and business units to strengthen risk-informed decisions and cyber culture.

Responsibilities include managing the policy library, risk register, and executive reporting, while aligning controls with NIST, ISO,

Qualifications

  • 4+ years of experience in cybersecurity governance, IT risk management, technology compliance, or a related GRC discipline.
  • Demonstrated experience authoring and maintaining security policies, standards, and procedures within a formal governance lifecycle.
  • Working knowledge of leading frameworks including NIST CSF, NIST 800-53, ISO 27001/27002, and COBIT.
  • Hands-on experience conducting risk assessments and maintaining a risk register, including risk scoring, treatment planning, and remediation tracking.
  • Experience supporting governance forums and producing leadership-ready reporting, metrics, and dashboards.

Responsibilities

  • Own the cybersecurity policy and standards library — authoring, reviewing, and maintaining policies, standards, procedures, and guidelines on a defined lifecycle, including annual attestation and exception management.
  • Maintain the cyber risk management framework and methodology, including risk taxonomy, scoring criteria, risk appetite thresholds, and treatment/acceptance workflows.
  • Facilitate and document cyber risk assessments across applications, infrastructure, business processes, and change initiatives; capture outcomes in the enterprise risk register and track remediation to closure.
  • Administer the risk register as the single source of truth — ensuring completeness, accuracy, ownership assignment, aging analysis, and timely escalation of overdue or elevated risks.
  • Coordinate cybersecurity governance forums (e.g., Cyber Risk Council, steering committees), including agenda development, materials preparation, decision logging, and action item follow-through.
  • Develop and publish executive and operational reporting packages that translate technical risk data into clear business impact narratives for CIO, CISO, and leadership audiences.
  • Map policy and control requirements to external frameworks and regulations (NIST CSF, ISO 27001, HIPAA, GDPR, FDA premarket/postmarket cybersecurity guidance) and maintain crosswalk documentation.

Skills

Cybersecurity governance
IT risk management
Policy writing
GRC frameworks
Third-party risk
Security reporting

Education

Bachelor's degree in Information Technology/Cybersecurity
Master's degree in Cybersecurity/Information Systems

Tools

Power BI

Job description

Johnson & Johnson is seeking a Professional, Governance & Policy Analyst within DePuy Synthes to design, maintain, and operationalize the cybersecurity policy framework and risk governance model. This individual contributor role partners with IT, Legal, Privacy, Quality, Procurement, and business units to strengthen risk-informed decisions and cyber culture.

Responsibilities include managing the policy library, risk register, and executive reporting, while aligning controls with NIST, ISO,

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Cyber GRC Policy Analyst: Risk, Policy & Reporting
Cyber GRC Policy Analyst: Risk, Policy & Reporting

Antler Co • Town of Florida (NY)

On-site
USD 79,000 - 142,000
Cyber GRC Policy & Risk Analyst
Cyber GRC Policy & Risk Analyst

Antler Co • New Brunswick (NJ)

On-site
USD 79,000 - 142,000
Travel up to 15% domestic travel
Cyber GRC Policy Strategist & Risk Lead
Cyber GRC Policy Strategist & Risk Lead

Johnson & Johnson MedTech • Raritan (NJ)

On-site
USD 79,000 - 142,000
Senior Cyber GRC Policy Analyst
Senior Cyber GRC Policy Analyst

Antler Co • Raynham (MA)

On-site
USD 79,000 - 142,000
Cyber Governance & Policy Analyst
Cyber Governance & Policy Analyst

Johnson & Johnson MedTech • Town of Florida (NY)

On-site
USD 79,000 - 142,000
Cyber Governance & Policy Analyst
Cyber Governance & Policy Analyst

Johnson & Johnson MedTech • Raynham (MA)

On-site
USD 79,000 - 142,000
Strategic Cyber GRC Analyst
Strategic Cyber GRC Analyst

6090-Johnson & Johnson Services Inc. Legal Entity • New Brunswick (NJ)

Hybrid
USD 79,000 - 142,000
Cyber GRC Lead - Policy, Risk & Exec Reporting
Cyber GRC Lead - Policy, Risk & Exec Reporting

Antler Co • New Brunswick (NJ)

On-site
USD 140,000 - 190,000
Cyber Governance & Policy Analyst
Cyber Governance & Policy Analyst

Antler Co • Warsaw (IN)

On-site
USD 79,000 - 142,000
Travel up to 15% domestically
Cyber Governance & Policy Analyst
Cyber Governance & Policy Analyst

Johnson & Johnson MedTech • Warsaw (IN)

On-site
USD 79,000 - 142,000