Senior Cyber GRC Policy Analyst

Antler Co

Raynham (MA)

On-site

USD 79,000 - 142,000

Full time

6 days ago
Be an early applicant
Application generator

A complete application in a minute — tailored resume and cover letter, ready to send.

Get past ATS filters

Job summary

Johnson & Johnson is seeking a Professional, Governance & Policy Analyst in DePuy Synthes, focused on cyber risk, policy, and governance across IT. You will design and operate the cybersecurity policy framework, administer risk registers, and drive risk reporting to CIO/CISO and leadership.

The role requires 4+ years in cybersecurity governance, with strong knowledge of NIST CSF, ISO 27001, HIPAA, GDPR, and FDA guidance, plus collaboration with Legal, Privacy, Quality, and Procurement.

Qualifications

  • Bachelor’s degree in IT, Cybersecurity, IS, Risk Management or related field.
  • 4+ years in cybersecurity governance, IT risk management or GRC.
  • Experience drafting security policies within a governance lifecycle.

Responsibilities

  • Own the cybersecurity policy and standards library — author, review, maintain.
  • Maintain and improve the cyber risk management framework and taxonomy.
  • Coordinate cyber risk assessments across applications, infra, and processes.
  • Administer the risk register and track remediation to closure.
  • Coordinate governance forums and prepare leadership reporting packages.
  • Design and report cyber risk metrics and KRIs with thresholds.
  • Support third‑party risk oversight including SOC 2 / ISO evidence review.
  • Map policy requirements to NIST CSF, ISO 27001, HIPAA, GDPR, FDA guidance.
  • Partner with IT Controls and SOX to align governance with control design.
  • Drive cyber culture through policy communications and awareness programs.
  • Assess policy impact of technology changes and cloud migrations.
  • Support audits and regulatory inquiries with governance documentation.
  • Identify opportunities to automate GRC workflows and evidence collection.

Skills

Cybersecurity governance
GRC frameworks
Policy drafting
Risk assessment
Vendor risk

Education

Bachelor's degree in IT, Cybersecurity, Information Systems, Risk Management, Business
Master's degree preferred

Tools

ServiceNow IRM
Archer
OneTrust
AuditBoard
Power BI

Job description

Johnson & Johnson is seeking a Professional, Governance & Policy Analyst in DePuy Synthes, focused on cyber risk, policy, and governance across IT. You will design and operate the cybersecurity policy framework, administer risk registers, and drive risk reporting to CIO/CISO and leadership.

The role requires 4+ years in cybersecurity governance, with strong knowledge of NIST CSF, ISO 27001, HIPAA, GDPR, and FDA guidance, plus collaboration with Legal, Privacy, Quality, and Procurement.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Strategic Cyber GRC Analyst
Strategic Cyber GRC Analyst

6090-Johnson & Johnson Services Inc. Legal Entity • New Brunswick (NJ)

Hybrid
USD 79,000 - 142,000
Cyber GRC Policy Analyst: Risk, Policy & Reporting
Cyber GRC Policy Analyst: Risk, Policy & Reporting

Antler Co • Town of Florida (NY)

On-site
USD 79,000 - 142,000
Cyber GRC Policy Strategist & Risk Lead
Cyber GRC Policy Strategist & Risk Lead

Johnson & Johnson MedTech • Raritan (NJ)

On-site
USD 79,000 - 142,000
Cyber GRC Policy & Risk Analyst
Cyber GRC Policy & Risk Analyst

Antler Co • New Brunswick (NJ)

On-site
USD 79,000 - 142,000
Travel up to 15% domestic travel
Cyber GRC Policy Analyst — Drive Risk & Compliance
Cyber GRC Policy Analyst — Drive Risk & Compliance

Johnson & Johnson MedTech • West Chester

On-site
USD 79,000 - 142,000
Cyber Governance & Policy Analyst
Cyber Governance & Policy Analyst

Johnson & Johnson MedTech • Town of Florida (NY)

On-site
USD 79,000 - 142,000
Cyber Governance & Policy Analyst
Cyber Governance & Policy Analyst

Johnson & Johnson MedTech • Raynham (MA)

On-site
USD 79,000 - 142,000
Cyber Governance & Policy Analyst
Cyber Governance & Policy Analyst

Antler Co • Warsaw (IN)

On-site
USD 79,000 - 142,000
Travel up to 15% domestically
Cyber GRC Lead - Policy, Risk & Exec Reporting
Cyber GRC Lead - Policy, Risk & Exec Reporting

Antler Co • New Brunswick (NJ)

On-site
USD 140,000 - 190,000
Cyber Governance & Policy Analyst
Cyber Governance & Policy Analyst

Johnson & Johnson MedTech • Warsaw (IN)

On-site
USD 79,000 - 142,000