Strategic Cyber Governance & Policy Analyst

Johnson & Johnson Co.

New Brunswick (NJ)

On-site

USD 79,000 - 142,000

Full time

3 days ago
Be an early applicant
Application generator

A complete application in a minute — tailored resume and cover letter, ready to send.

Get past ATS filters

Job summary

DePuy Synthes, a Johnson & Johnson company, is recruiting a Professional, Governance & Policy Analyst to lead cybersecurity policy, risk methods, and governance reporting. The role partners across IT, Legal, Privacy, Quality, Procurement, and business functions to strengthen risk-informed decision-making and cyber culture.

The analyst applies GRC frameworks, maintains the policy library, and supports third‑party risk oversight.

Qualifications

  • 4+ years in cybersecurity governance, IT risk, or a related GRC discipline.
  • Experience authoring and maintaining security policies, standards, and procedures within a governance lifecycle.
  • Knowledge of NIST CSF, NIST 800-53, ISO 27001/27002, and COBIT.
  • Experience supporting governance forums and producing leadership-ready reporting, metrics, and dashboards.
  • Strong written communication skills and ability to influence stakeholders without direct authority.

Responsibilities

  • Own the cybersecurity policy and standards library — authoring, reviewing, and maintaining policies, standards, procedures, and guidelines with lifecycle management.
  • Maintain and improve cyber risk management framework and methodology including risk taxonomy and scoring criteria.
  • Facilitate and document cyber risk assessments; track outcomes in the enterprise risk register and remediation activities.
  • Administer the risk register as the single source of truth with ownership, aging analysis, and escalation.
  • Coordinate governance forums (e.g., Cyber Risk Council) and prepare decision-ready materials.

Skills

GRC governance
IT risk management
Security policies
Risk assessments
Third-party risk
Regulatory/frameworks (NIST, ISO, COBn
Stakeholder communication

Education

Bachelor's degree in Information Technology / Cybersecurity / Information Systems
Master's degree in Cybersecurity / Information Systems / MBA preferred

Tools

ServiceNow IRM
Archer
OneTrust
AuditBoard
Power BI
Tableau

Job description

DePuy Synthes, a Johnson & Johnson company, is recruiting a Professional, Governance & Policy Analyst to lead cybersecurity policy, risk methods, and governance reporting. The role partners across IT, Legal, Privacy, Quality, Procurement, and business functions to strengthen risk-informed decision-making and cyber culture.

The analyst applies GRC frameworks, maintains the policy library, and supports third‑party risk oversight.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Cyber Governance & Policy Analyst
Cyber Governance & Policy Analyst

Johnson & Johnson MedTech • Warsaw (IN)

On-site
USD 79,000 - 142,000
Strategic Cyber GRC Analyst
Strategic Cyber GRC Analyst

6090-Johnson & Johnson Services Inc. Legal Entity • New Brunswick (NJ)

Hybrid
USD 79,000 - 142,000
Cyber Governance & Policy Analyst
Cyber Governance & Policy Analyst

Johnson & Johnson MedTech • Raynham (MA)

On-site
USD 79,000 - 142,000
Cyber GRC Policy Strategist & Risk Lead
Cyber GRC Policy Strategist & Risk Lead

Johnson & Johnson MedTech • Raritan (NJ)

On-site
USD 79,000 - 142,000
Cyber Governance Lead: Policy, Risk & Compliance
Cyber Governance Lead: Policy, Risk & Compliance

Johnson & Johnson MedTech • New Brunswick (NJ)

On-site
USD 140,000 - 190,000
Cyber GRC Lead - Policy, Risk & Exec Reporting
Cyber GRC Lead - Policy, Risk & Exec Reporting

Antler Co • New Brunswick (NJ)

On-site
USD 140,000 - 190,000
Professional Governance & Policy Analyst
Professional Governance & Policy Analyst

Johnson Johnson • New Brunswick (NJ)

On-site
USD 110,000 - 170,000
Senior Cybersecurity GRC Lead
Senior Cybersecurity GRC Lead

Johnson Johnson • New Brunswick (NJ)

On-site
USD 120,000 - 180,000
Cyber GRC & Policy Lead | Enterprise Risk & Compliance
Cyber GRC & Policy Lead | Enterprise Risk & Compliance

Johnson & Johnson Co. • New Brunswick (NJ)

On-site
USD 140,000 - 180,000
Cyber Governance & Policy Analyst
Cyber Governance & Policy Analyst

Johnson Johnson • New Brunswick (NJ)

On-site
USD 110,000 - 170,000