Professional Governance & Policy Analyst

Johnson & Johnson Co.

New Brunswick (NJ)

On-site

USD 79,000 - 142,000

Full time

2 days ago
Be an early applicant
Application generator

Stand out for this role — generate a tailored resume and cover letter in about a minute.

Get past ATS filters

Job summary

DePuy Synthes, a Johnson & Johnson company, is recruiting a Professional, Governance & Policy Analyst to lead cybersecurity policy, risk methods, and governance reporting. The role partners across IT, Legal, Privacy, Quality, Procurement, and business functions to strengthen risk-informed decision-making and cyber culture.

The analyst applies GRC frameworks, maintains the policy library, and supports third‑party risk oversight.

Qualifications

  • 4+ years in cybersecurity governance, IT risk, or a related GRC discipline.
  • Experience authoring and maintaining security policies, standards, and procedures within a governance lifecycle.
  • Knowledge of NIST CSF, NIST 800-53, ISO 27001/27002, and COBIT.
  • Experience supporting governance forums and producing leadership-ready reporting, metrics, and dashboards.
  • Strong written communication skills and ability to influence stakeholders without direct authority.

Responsibilities

  • Own the cybersecurity policy and standards library — authoring, reviewing, and maintaining policies, standards, procedures, and guidelines with lifecycle management.
  • Maintain and improve cyber risk management framework and methodology including risk taxonomy and scoring criteria.
  • Facilitate and document cyber risk assessments; track outcomes in the enterprise risk register and remediation activities.
  • Administer the risk register as the single source of truth with ownership, aging analysis, and escalation.
  • Coordinate governance forums (e.g., Cyber Risk Council) and prepare decision-ready materials.

Skills

GRC governance
IT risk management
Security policies
Risk assessments
Third-party risk
Regulatory/frameworks (NIST, ISO, COBn
Stakeholder communication

Education

Bachelor's degree in Information Technology / Cybersecurity / Information Systems
Master's degree in Cybersecurity / Information Systems / MBA preferred

Tools

ServiceNow IRM
Archer
OneTrust
AuditBoard
Power BI
Tableau

Job description

At Johnson & Johnson, we believe health is everything. Our strength in healthcare innovation empowers us to build a world where complex diseases are prevented, treated, and cured, where treatments are smarter and less invasive, and solutions are personal. Through our expertise in Innovative Medicine and MedTech, we are uniquely positioned to innovate across the full spectrum of healthcare solutions today to deliver the breakthroughs of tomorrow, and profoundly impact health for humanity. Learn more at jnj.com

As guided by Our Credo, Johnson & Johnson is responsible to our employees who work with us throughout the world. We provide an inclusive work environment where each person is considered as an individual. At Johnson & Johnson, we respect the diversity and dignity of our employees and recognize their merit.

Job Function

Technology Enterprise Strategy & Security

Job Sub Function

Security & Controls

Job Category

Scientific/Technology

All Job Posting Locations

New Brunswick, New Jersey, United States of America, Palm Beach Gardens, Florida, United States of America, Raritan, New Jersey, United States of America, Raynham, Massachusetts, United States of America, Warsaw, Indiana, United States of America, West Chester, Pennsylvania, United States of America

Job Description

DePuy Synthes is recruiting for a(n) Professional, Governance & Policy Analyst.

The Professional, Governance & Policy Analyst is an established and productive individual contributor within the Cybersecurity function, GRC, IT Controls & Cyber Culture sub-function, accountable for the design, maintenance, and operationalization of the cybersecurity policy framework, risk methodology, and governance reporting model for DePuy Synthes. This role owns the cyber policy and standards library, administers the enterprise cyber risk register and assessment lifecycle, coordinates governance forums and executive reporting, and supports third-party risk oversight. Working under moderate supervision, the analyst applies practical knowledge of GRC frameworks to translate regulatory expectations into clear, actionable standards, and partners across IT, Legal, Privacy, Quality, Procurement, and business functions to strengthen risk-informed decision-making and a strong cyber culture.

Key Responsibilities
  • Own the cybersecurity policy and standards library — authoring, reviewing, and maintaining policies, standards, procedures, and guidelines on a defined lifecycle, including annual attestation and exception management.
  • Maintain and continuously improve the cyber risk management framework and methodology, including risk taxonomy, scoring criteria, risk appetite thresholds, and treatment/acceptance workflows.
  • Facilitate and document cyber risk assessments across applications, infrastructure, business processes, and change initiatives; capture outcomes in the enterprise risk register and track remediation to closure.
  • Administer the risk register as the single source of truth — ensuring completeness, accuracy, ownership assignment, aging analysis, and timely escalation of overdue or elevated risks.
  • Coordinate cybersecurity governance forums (e.g., Cyber Risk Council, steering committees), including agenda development, materials preparation, decision logging, and action item follow-through.
  • Develop and publish executive and operational reporting packages that translate technical risk data into clear business impact narratives for CIO, CISO, and leadership audiences.
  • Design, baseline, and report on cyber risk metrics and Key Risk Indicators (KRIs), establishing thresholds and trend analysis to drive proactive risk management.
  • Support third-party and vendor cyber risk oversight — including risk tiering, security questionnaire review, SOC 2 / ISO 27001 evidence evaluation, contractual security requirements, and ongoing monitoring of critical suppliers.
  • Map policy and control requirements to external frameworks and regulations (NIST CSF, ISO 27001, HIPAA, GDPR, FDA premarket/postmarket cybersecurity guidance) and maintain crosswalk documentation to reduce duplicative control effort.
  • Partner with the IT Controls and SOX teams to align governance requirements with control design, avoiding gaps and redundancy across the assurance landscape.
  • Drive cyber culture and awareness initiatives — developing policy communications, training content, and targeted enablement to increase understanding and adoption across the enterprise.
  • Assess the governance impact of technology change, including system implementations, cloud migrations, and separation/carve‑out activity, and define policy and risk requirements ahead of go‑live.
  • Support internal and external audit, regulatory inquiries, and customer security assessments by providing governance documentation, evidence, and coordinated responses.
  • Identify opportunities to automate GRC workflows, reporting, and evidence collection to improve efficiency and data quality.
Qualifications
Education
  • Bachelor's degree in Information Technology, Cybersecurity, Information Systems, Risk Management, Business, or a related discipline.
  • Master's degree in Cybersecurity, Information Systems, or Business Administration preferred
Experience and Skills
Required
  • 4+ years of experience in cybersecurity governance, IT risk management, technology compliance, or a related GRC discipline.
  • Demonstrated experience authoring and maintaining security policies, standards, and procedures within a formal governance lifecycle.
  • Working knowledge of leading frameworks including NIST CSF, NIST 800-53, ISO 27001/27002, and COBIT.
  • Hands‑on experience conducting risk assessments and maintaining a risk register, including risk scoring, treatment planning, and remediation tracking.
  • Experience supporting governance forums and producing leadership‑ready reporting, metrics, and dashboards.
  • Familiarity with third‑party/vendor risk assessment processes and review of SOC 2 / ISO certifications.
  • Strong written communication skills, with the ability to translate technical risk into clear business language and influence stakeholders without direct authority.
Preferred
  • MedTech, Life Sciences, or other regulated industry experience; familiarity with HIPAA, GDPR, and FDA medical device cybersecurity expectations.
  • Experience establishing or maturing a GRC function within a divestiture, carve‑out, spin‑off, or standalone entity stand‑up.
  • Hands‑on experience with GRC platforms (e.g., ServiceNow IRM, Archer, OneTrust, AuditBoard) and workflow configuration.
  • Experience defining and operationalizing KRIs and risk appetite statements at an enterprise level.
  • Exposure to cloud governance (AWS, Azure) and control expectations for SaaS and cloud‑hosted environments.
  • Proficiency with data visualization and reporting tools (Power BI, Tableau) for risk metrics and executive dashboards.
  • Experience applying Generative AI / LLM‑enabled tooling to accelerate policy drafting, control mapping, and third‑party questionnaire review.
  • Experience developing security awareness and cyber culture programs.
Other
  • Travel: Up to 15% domestic travel expected across DePuy Synthes sites.
  • Language: English proficiency required.
  • Certifications: CISSP, CRISC, CISM, CISA, CGRC (formerly CAP), or ISO 27001 Lead Implementer/Auditor preferred.
Additional Description for Pay Transparency

Subject to the terms of their respective plans, employees are eligible to participate in the Company’s consolidated retirement plan (pension) and savings plan (401(k)).

Subject to the terms of their respective policies and date of hire, employees are eligible for the following time off benefits:

  • Vacation –120 hours per calendar year
  • Sick time - 40 hours per calendar year; for employees who reside in the State of Colorado –48 hours per calendar year; for employees who reside in the State of Washington –56 hours per calendar year
  • Holiday pay, including Floating Holidays –13 days per calendar year
  • Work, Personal and Family Time - up to 40 hours per calendar year
  • Parental Leave – 480 hours within one year of the birth/adoption/foster care of a child
  • Bereavement Leave – 240 hours for an immediate family member: 40 hours for an extended family member per calendar year
  • Caregiver Leave – 80 hours in a 52‑week rolling period10 days
  • Volunteer Leave – 32 hours per calendar year
  • Military Spouse Time‑Off – 80 hours per calendar year

For additional general information on Company benefits, please go to: https://www.careers.jnj.com/employee-benefits

Base Pay Range

The anticipated base pay range for this position is :

79,000.00 - 142,000.00 USD Annual

Analytical Reasoning, Communication, Corrective and Preventive Action (CAPA), Industry Analysis, Information Security Auditing, Information Security Management System (ISMS), Information Technology (IT) Security Assessments, Information Technology Strategies, Mentorship, Process Oriented, Risk Assessments, Root Cause Analysis (RCA), Security Policies, Solution Architecture, Technologically Savvy, Vulnerability Assessments

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Professional Governance & Policy Analyst
Professional Governance & Policy Analyst

Johnson & Johnson MedTech • Raritan (NJ)

On-site
USD 79,000 - 142,000
Professional, Compliance Lead
Professional, Compliance Lead

Johnson & Johnson MedTech • New Brunswick (NJ)

On-site
USD 140,000 - 190,000
Professional, Compliance Lead
Professional, Compliance Lead

Johnson & Johnson Co. • New Brunswick (NJ)

On-site
USD 140,000 - 180,000
Professional Governance & Policy Analyst
Professional Governance & Policy Analyst

Johnson & Johnson MedTech • Warsaw (IN)

On-site
USD 79,000 - 142,000
Professional Governance & Policy Analyst
Professional Governance & Policy Analyst

Johnson & Johnson MedTech • Raynham (MA)

On-site
USD 79,000 - 142,000
Director, Incident Response & Threat
Director, Incident Response & Threat

Antler Co • Raritan (NJ)

Hybrid
USD 150,000 - 259,000
Vacation 120 hours per year
Long-term incentive program
401(k) plan
Director, Incident Response & Threat
Director, Incident Response & Threat

Antler Co • Warsaw (IN)

Hybrid
USD 150,000 - 259,000
Vacation –120 hours per calendar year
Director, Incident Response & Threat
Director, Incident Response & Threat

Antler Co • Raynham (MA)

Hybrid
USD 150,000 - 259,000
Vacation –120 hours/year
Pension plan
401(k) plan
Director, Incident Response & Threat
Director, Incident Response & Threat

Antler Co • Town of Florida (NY)

Hybrid
USD 150,000 - 259,000
Vacation 120 hours/year
Sick time
Director, Incident Response & Threat
Director, Incident Response & Threat

Antler Co • West Chester

Hybrid
USD 150,000 - 259,000
Vacation –120 hours per calendar year