Professional Governance & Policy Analyst

Johnson Johnson

New Brunswick (NJ)

On-site

USD 110,000 - 170,000

Full time

2 days ago
Be an early applicant
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Job summary

Johnson & Johnson is seeking a Professional, Governance & Policy Analyst within Cybersecurity, GRC, IT Controls & Cyber Culture. The role designs and maintains the policy framework, risk methodology, and governance reporting, partnering with IT, Legal, Privacy, Quality, Procurement, and business functions to inform risk-aware decisions.

The analyst supports audit, regulatory inquiries, and third‑party assessments, driving automation and consistent evidence collection across the enterprise.

Qualifications

  • Bachelor's degree in Informat or related field.
  • Experience applying GRC frameworks to translate regulatory expectations into standards.
  • Strong collaboration with IT, Legal, Privacy, Quality, Procurement, and business functions.

Responsibilities

  • Own the cybersecurity policy and standards library and maintain lifecycle documents.
  • Manage cyber risk assessments across apps, infra, and processes; update enterprise risk register.
  • Coordinate governance forums and produce executive reporting for CIO/CISO and leadership.
  • Develop cyber risk KPIs and KRIs with thresholds and trend analysis.
  • Support third-party risk oversight, including vendor risk and evidence evaluation.
  • Map policy requirements to frameworks like NIST CSF, ISO 27001, HIPAA, GDPR; maintain crosswalks.

Education

Bachelor's degree in Informat

Job description

At Johnson & Johnson, we believe health is everything. Our strength in healthcare innovation empowers us to build a world where complex diseases are prevented, treated, and cured, where treatments are smarter and less invasive, and solutions are personal. Through our expertise in Innovative Medicine and MedTech, we are uniquely positioned to innovate across the full spectrum of healthcare solutions today to deliver the breakthroughs of tomorrow, and profoundly impact health for humanity. Learn more at jnj.com

As guided by Our Credo, Johnson & Johnson is responsible to our employees who work with us throughout the world. We provide an inclusive work environment where each person is considered as an individual. At Johnson & Johnson, we respect the diversity and dignity of our employees and recognize their merit.

Job Function:

Technology Enterprise Strategy & Security

Job Sub Function:

Security & Controls

Job Category:

Scientific/Technology

All Job Posting Locations:

New Brunswick, New Jersey, United States of America, Palm Beach Gardens, Florida, United States of America, Raritan, New Jersey, United States of America, Raynham, Massachusetts, United States of America, Warsaw, Indiana, United States of America, West Chester, Pennsylvania, United States of America

Job Description:

DePuy Synthes is recruiting for a(n) Professional, Governance & Policy Analyst.

The Professional, Governance & Policy Analyst is an established and productive individual contributor within the Cybersecurity function, GRC, IT Controls & Cyber Culture sub-function, accountable for the design, maintenance, and operationalization of the cybersecurity policy framework, risk methodology, and governance reporting model for DePuy Synthes. This role owns the cyber policy and standards library, administers the enterprise cyber risk register and assessment lifecycle, coordinates governance forums and executive reporting, and supports third-party risk oversight. Working under moderate supervision, the analyst applies practical knowledge of GRC frameworks to translate regulatory expectations into clear, actionable standards, and partners across IT, Legal, Privacy, Quality, Procurement, and business functions to strengthen risk-informed decision-making and a strong cyber culture.

Key Responsibilities
  • Own the cybersecurity policy and standards library - authoring, reviewing, and maintaining policies, standards, procedures, and guidelines on a defined lifecycle, including annual attestation and exception management.
  • Maintain and continuously improve the cyber risk management framework and methodology, including risk taxonomy, scoring criteria, risk appetite thresholds, and treatment/acceptance workflows.
  • Facilitate and document cyber risk assessments across applications, infrastructure, business processes, and change initiatives; capture outcomes in the enterprise risk register and track remediation to closure.
  • Administer the risk register as the single source of truth - ensuring completeness, accuracy, ownership assignment, aging analysis, and timely escalation of overdue or elevated risks.
  • Coordinate cybersecurity governance forums (e.g., Cyber Risk Council, steering committees), including agenda development, materials preparation, decision logging, and action item follow-through.
  • Develop and publish executive and operational reporting packages that translate technical risk data into clear business impact narratives for CIO, CISO, and leadership audiences.
  • Design, baseline, and report on cyber risk metrics and Key Risk Indicators (KRIs), establishing thresholds and trend analysis to drive proactive risk management.
  • Support third-party and vendor cyber risk oversight - including risk tiering, security questionnaire review, SOC 2 / ISO 27001 evidence evaluation, contractual security requirements, and ongoing monitoring of critical suppliers.
  • Map policy and control requirements to external frameworks and regulations (NIST CSF, ISO 27001, HIPAA, GDPR, FDA premarket/postmarket cybersecurity guidance) and maintain crosswalk documentation to reduce duplicative control effort.
  • Partner with the IT Controls and SOX teams to align governance requirements with control design, avoiding gaps and redundancy across the assurance landscape.
  • Drive cyber culture and awareness initiatives - developing policy communications, training content, and targeted enablement to increase understanding and adoption across the enterprise.
  • Assess the governance impact of technology change, including system implementations, cloud migrations, and separation/carve-out activity, and define policy and risk requirements ahead of go-live.
  • Support internal and external audit, regulatory inquiries, and customer security assessments by providing governance documentation, evidence, and coordinated responses.
  • Identify opportunities to automate GRC workflows, reporting, and evidence collection to improve efficiency and data quality.
Qualifications
Education

Bachelor's degree in Informat

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Professional, Compliance Lead
Professional, Compliance Lead

Johnson Johnson • New Brunswick (NJ)

On-site
USD 120,000 - 180,000
Professional Governance & Policy Analyst
Professional Governance & Policy Analyst

Johnson & Johnson Co. • New Brunswick (NJ)

On-site
USD 79,000 - 142,000
Professional, Compliance Lead
Professional, Compliance Lead

Johnson & Johnson MedTech • New Brunswick (NJ)

On-site
USD 140,000 - 190,000
Professional, Compliance Lead
Professional, Compliance Lead

Antler Co • New Brunswick (NJ)

On-site
USD 140,000 - 190,000
Professional, Compliance Lead
Professional, Compliance Lead

Johnson & Johnson Co. • New Brunswick (NJ)

On-site
USD 140,000 - 180,000
Cyber Governance & Policy Analyst
Cyber Governance & Policy Analyst

Johnson & Johnson MedTech • Raynham (MA)

On-site
USD 79,000 - 142,000
Cyber Governance & Policy Analyst
Cyber Governance & Policy Analyst

Johnson & Johnson MedTech • Warsaw (IN)

On-site
USD 79,000 - 142,000
Cyber GRC Policy Strategist & Risk Lead
Cyber GRC Policy Strategist & Risk Lead

Johnson & Johnson MedTech • Raritan (NJ)

On-site
USD 79,000 - 142,000
Professional, Compliance Lead
Professional, Compliance Lead

6090-Johnson & Johnson Services Inc. Legal Entity • New Brunswick (NJ)

On-site
USD 140,000 - 200,000
Cyber GRC & Policy Lead | Enterprise Risk & Compliance
Cyber GRC & Policy Lead | Enterprise Risk & Compliance

Johnson & Johnson Co. • New Brunswick (NJ)

On-site
USD 140,000 - 180,000