Cyber GRC Policy Analyst: Risk, Policy & Reporting

Antler Co

Town of Florida (NY)

On-site

USD 79,000 - 142,000

Full time

6 days ago
Be an early applicant
Application generator

A complete application in a minute — tailored resume and cover letter, ready to send.

Get past ATS filters

Job summary

Johnson & Johnson is recruiting a Professional, Governance & Policy Analyst within DePuy Synthes to design, maintain, and operationalize cyber policy, risk methodology, and governance reporting. You will manage policy libraries, risk registers, and executive reporting while partnering across IT, Legal, Privacy, and Quality functions to strengthen risk-informed decisions.

The role focuses on aligning controls with frameworks (NIST, ISO, HIPAA, GDPR) and maturing cyber culture across the

Qualifications

  • Bachelor’s degree in Information Technology, Cybersecurity, Information Systems, Risk Management, Business, or related discipline.
  • Master’s degree in Cybersecurity, Information Systems, or Business Administration preferred.
  • 4+ years of experience in cybersecurity governance, IT risk management, technology compliance, or a related GRC discipline.
  • Strong written communication skills, with ability to translate technical risk into business language.
  • Familiarity with NIST CSF, NIST 800-53, ISO 27001/27002, COBIT.

Responsibilities

  • Own the cybersecurity policy and standards library, authoring, reviewing, and maintaining policies, standards, procedures, and guidelines on a defined lifecycle.
  • Maintain and improve the cyber risk management framework and methodology, including risk taxonomy and scoring.
  • Facilitate and document cyber risk assessments across applications, infrastructure, and processes.
  • Administer the risk register as the single source of truth with ownership and aging analysis.
  • Coordinate cybersecurity governance forums and prepare decision materials for leadership.

Skills

GRC governance
Policy drafting
Cybersecurity risk
Regulatory awareness
Communication skills

Education

Bachelor's degree in Information Technology, Cybersecurity, Information Systems, Risk Management, Business, or a related discipline
Master's degree in Cybersecurity, Information Systems, or Business Administration preferred

Tools

ServiceNow IRM
Archer
OneTrust
AuditBoard
Power BI
Tableau
AWS

Job description

Johnson & Johnson is recruiting a Professional, Governance & Policy Analyst within DePuy Synthes to design, maintain, and operationalize cyber policy, risk methodology, and governance reporting. You will manage policy libraries, risk registers, and executive reporting while partnering across IT, Legal, Privacy, and Quality functions to strengthen risk-informed decisions.

The role focuses on aligning controls with frameworks (NIST, ISO, HIPAA, GDPR) and maturing cyber culture across the

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Cyber GRC Policy Analyst — Drive Risk & Compliance
Cyber GRC Policy Analyst — Drive Risk & Compliance

Johnson & Johnson MedTech • West Chester

On-site
USD 79,000 - 142,000
Cyber GRC Policy & Risk Analyst
Cyber GRC Policy & Risk Analyst

Antler Co • New Brunswick (NJ)

On-site
USD 79,000 - 142,000
Travel up to 15% domestic travel
Senior Cyber GRC Policy Analyst
Senior Cyber GRC Policy Analyst

Antler Co • Raynham (MA)

On-site
USD 79,000 - 142,000
Cyber GRC Policy Strategist & Risk Lead
Cyber GRC Policy Strategist & Risk Lead

Johnson & Johnson MedTech • Raritan (NJ)

On-site
USD 79,000 - 142,000
Cyber Governance & Policy Analyst
Cyber Governance & Policy Analyst

Johnson & Johnson MedTech • Town of Florida (NY)

On-site
USD 79,000 - 142,000
Cyber Governance & Policy Analyst
Cyber Governance & Policy Analyst

Johnson & Johnson MedTech • Raynham (MA)

On-site
USD 79,000 - 142,000
Strategic Cyber GRC Analyst
Strategic Cyber GRC Analyst

6090-Johnson & Johnson Services Inc. Legal Entity • New Brunswick (NJ)

Hybrid
USD 79,000 - 142,000
Cyber Governance & Policy Analyst
Cyber Governance & Policy Analyst

Antler Co • Warsaw (IN)

On-site
USD 79,000 - 142,000
Travel up to 15% domestically
Cyber GRC Lead - Policy, Risk & Exec Reporting
Cyber GRC Lead - Policy, Risk & Exec Reporting

Antler Co • New Brunswick (NJ)

On-site
USD 140,000 - 190,000
Cyber Governance & Policy Analyst
Cyber Governance & Policy Analyst

Johnson & Johnson MedTech • Warsaw (IN)

On-site
USD 79,000 - 142,000