Johnson & Johnson

Professional Governance & Policy Analyst

Johnson & Johnson • $79K — $142K *
Information Technology
Less than 5 years of experience
Job Overview by Ladders

Qualifications

  • Bachelor's degree in Information Technology, Cybersecurity, Information Systems, Risk Management, Business, or a related discipline.
  • 4+ years of experience in cybersecurity governance, IT risk management, technology compliance, or a related GRC discipline.
  • Experience authoring and maintaining security policies within a formal governance lifecycle.
  • Working knowledge of frameworks including NIST CSF, NIST 800-53, and ISO 27001.
  • Hands-on experience with risk assessments and maintaining a risk register.

Responsibilities

  • Own and maintain the cybersecurity policy and standards library.
  • Continuously improve the cyber risk management framework and methodology.
  • Facilitate and document cyber risk assessments across various domains.
  • Administer the risk register to ensure accuracy and timely risk management.
  • Coordinate governance forums and document meeting outcomes.

Benefits

  • 401(k) with company match and consolidated retirement plan.
  • 120 hours of vacation and up to 40 hours of sick time.
  • 13 paid holidays and personal time off.
  • Generous parental leave and caregiver leave policies.
  • Volunteer leave to encourage community involvement.
Full Job Description
Job Function:
Technology Enterprise Strategy & Security

Job Sub Function:
Security & Controls

Job Category:
Scientific/Technology

All Job Posting Locations:
New Brunswick, New Jersey, United States of America, Palm Beach Gardens, Florida, United States of America, Raritan, New Jersey, United States of America, Raynham, Massachusetts, United States of America, Warsaw, Indiana, United States of America, West Chester, Pennsylvania, United States of America

Job Description:

DePuy Synthes is recruiting for a(n) Professional, Governance & Policy Analyst.

The Professional, Governance & Policy Analyst is an established and productive individual contributor within the Cybersecurity function, GRC, IT Controls & Cyber Culture sub-function, accountable for the design, maintenance, and operationalization of the cybersecurity policy framework, risk methodology, and governance reporting model for DePuy Synthes. This role owns the cyber policy and standards library, administers the enterprise cyber risk register and assessment lifecycle, coordinates governance forums and executive reporting, and supports third-party risk oversight. Working under moderate supervision, the analyst applies practical knowledge of GRC frameworks to translate regulatory expectations into clear, actionable standards, and partners across IT, Legal, Privacy, Quality, Procurement, and business functions to strengthen risk-informed decision-making and a strong cyber culture.

Key Responsibilities
  • Own the cybersecurity policy and standards library - authoring, reviewing, and maintaining policies, standards, procedures, and guidelines on a defined lifecycle, including annual attestation and exception management.
  • Maintain and continuously improve the cyber risk management framework and methodology, including risk taxonomy, scoring criteria, risk appetite thresholds, and treatment/acceptance workflows.
  • Facilitate and document cyber risk assessments across applications, infrastructure, business processes, and change initiatives; capture outcomes in the enterprise risk register and track remediation to closure.
  • Administer the risk register as the single source of truth - ensuring completeness, accuracy, ownership assignment, aging analysis, and timely escalation of overdue or elevated risks.
  • Coordinate cybersecurity governance forums (e.g., Cyber Risk Council, steering committees), including agenda development, materials preparation, decision logging, and action item follow-through.
  • Develop and publish executive and operational reporting packages that translate technical risk data into clear business impact narratives for CIO, CISO, and leadership audiences.
  • Design, baseline, and report on cyber risk metrics and Key Risk Indicators (KRIs), establishing thresholds and trend analysis to drive proactive risk management.
  • Support third-party and vendor cyber risk oversight - including risk tiering, security questionnaire review, SOC 2 / ISO 27001 evidence evaluation, contractual security requirements, and ongoing monitoring of critical suppliers.
  • Map policy and control requirements to external frameworks and regulations (NIST CSF, ISO 27001, HIPAA, GDPR, FDA premarket/postmarket cybersecurity guidance) and maintain crosswalk documentation to reduce duplicative control effort.
  • Partner with the IT Controls and SOX teams to align governance requirements with control design, avoiding gaps and redundancy across the assurance landscape.
  • Drive cyber culture and awareness initiatives - developing policy communications, training content, and targeted enablement to increase understanding and adoption across the enterprise.
  • Assess the governance impact of technology change, including system implementations, cloud migrations, and separation/carve-out activity, and define policy and risk requirements ahead of go-live.
  • Support internal and external audit, regulatory inquiries, and customer security assessments by providing governance documentation, evidence, and coordinated responses.
  • Identify opportunities to automate GRC workflows, reporting, and evidence collection to improve efficiency and data quality.


Qualifications

Education
  • Bachelor's degree in Information Technology, Cybersecurity, Information Systems, Risk Management, Business, or a related discipline.
  • Master's degree in Cybersecurity, Information Systems, or Business Administration preferred

Experience and Skills

Required
  • 4+ years of experience in cybersecurity governance, IT risk management, technology compliance, or a related GRC discipline.
  • Demonstrated experience authoring and maintaining security policies, standards, and procedures within a formal governance lifecycle.
  • Working knowledge of leading frameworks including NIST CSF, NIST 800-53, ISO 27001/27002, and COBIT.
  • Hands-on experience conducting risk assessments and maintaining a risk register, including risk scoring, treatment planning, and remediation tracking.
  • Experience supporting governance forums and producing leadership-ready reporting, metrics, and dashboards.
  • Familiarity with third-party/vendor risk assessment processes and review of SOC 2 / ISO certifications.
  • Strong written communication skills, with the ability to translate technical risk into clear business language and influence stakeholders without direct authority.

Preferred
  • MedTech, Life Sciences, or other regulated industry experience; familiarity with HIPAA, GDPR, and FDA medical device cybersecurity expectations.
  • Experience establishing or maturing a GRC function within a divestiture, carve-out, spin-off, or standalone entity stand-up.
  • Hands-on experience with GRC platforms (e.g., ServiceNow IRM, Archer, OneTrust, AuditBoard) and workflow configuration.
  • Experience defining and operationalizing KRIs and risk appetite statements at an enterprise level.
  • Exposure to cloud governance (AWS, Azure) and control expectations for SaaS and cloud-hosted environments.
  • Proficiency with data visualization and reporting tools (Power BI, Tableau) for risk metrics and executive dashboards.
  • Experience applying Generative AI / LLM-enabled tooling to accelerate policy drafting, control mapping, and third-party questionnaire review.
  • Experience developing security awareness and cyber culture programs.

Other
  • Travel: Up to 15% domestic travel expected across DePuy Synthes sites.
  • Language: English proficiency required.
  • Certifications: CISSP, CRISC, CISM, CISA, CGRC (formerly CAP), or ISO 27001 Lead Implementer/Auditor preferred.


Johnson & Johnson announced plans to separate our Orthopaedics business to establish a standalone orthopaedics company, operating as DePuy Synthes. The process of the planned separation is anticipated to be completed within 18 to 24 months, subject to legal requirements, including consultation with works councils and other employee representative bodies, as may be required, regulatory approvals and other customary conditions and approvals. Should you accept this position, it is anticipated that, following conclusion of the transaction, you would be an employee of DePuy Synthes and your employment would be governed by DePuy Synthes employment processes, programs, policies, and benefit plans. In that case, details of any planned changes would be provided to you by DePuy Synthes at an appropriate time and subject to any necessary consultation processes.

Required Skills:

Preferred Skills:
Analytical Reasoning, Communication, Corrective and Preventive Action (CAPA), Industry Analysis, Information Security Auditing, Information Security Management System (ISMS), Information Technology (IT) Security Assessments, Information Technology Strategies, Mentorship, Process Oriented, Risk Assessments, Root Cause Analysis (RCA), Security Policies, Solution Architecture, Technologically Savvy, Vulnerability Assessments

The anticipated base pay range for this position is :
79,000.00 - 142,000.00 USD Annual

Additional Description for Pay Transparency:
Subject to the terms of their respective plans, employees are eligible to participate in the Company's consolidated retirement plan (pension) and savings plan (401(k)). Subject to the terms of their respective policies and date of hire, employees are eligible for the following time off benefits: • Vacation -120 hours per calendar year • Sick time - 40 hours per calendar year; for employees who reside in the State of Colorado -48 hours per calendar year; for employees who reside in the State of Washington -56 hours per calendar year • Holiday pay, including Floating Holidays -13 days per calendar year • Work, Personal and Family Time - up to 40 hours per calendar year • Parental Leave - 480 hours within one year of the birth/adoption/foster care of a child • Bereavement Leave - 240 hours for an immediate family member: 40 hours for an extended family member per calendar year • Caregiver Leave - 80 hours in a 52-week rolling period10 days • Volunteer Leave - 32 hours per calendar year • Military Spouse Time-Off - 80 hours per calendar year For additional general information on Company benefits, please go to: - https://www.careers.jnj.com/employee-benefits

About Johnson & Johnson

Scio Diamond creates single-crystal Type IIa diamonds for the jewelry market and for industrial applications. It employs a patent-protected chemical vapor deposition (CVD) process in a precisely controlled laboratory setting to produce diamonds. It was founded in 2009 and is headquartered in Greenville, South Carolina.

Johnson & Johnson Careers

Joining Johnson & Johnson provides an unparalleled opportunity to be a part of a global team of professionals dedicated to blending care, science, and innovation to profoundly change the trajectory of health for humanity.

Work You’ll Do

At Johnson & Johnson, you will engage in work that matters. Join our community of professionals in health care to drive significant and impactful changes across the globe. Our team at Johnson & Johnson leads with science and heart in sectors from pharmaceuticals to medical devices and consumer health products.

Transform Health Care

Leverage Johnson & Johnson’s culture of innovation to transform health care and improve the lives of people around the world. Our collaborative environment encourages leadership and growth, allowing you to pioneer new strategies for health care solutions with a diverse team of experts.

Innovative Work

Engage in groundbreaking work that enhances how care is delivered on a global scale. Johnson & Johnson’s commitment to innovative health solutions results in dynamic career paths filled with opportunities for professional growth and development.

Be Part of a Great Team

Our team at Johnson & Johnson thrives on collaboration and diversity. You will work alongside over 130,000 employees globally who are committed to making a lasting impact. With a culture that values diversity training and leadership, you are supported in both personal and professional growth.

Future-Proof Your Career

Johnson & Johnson offers a myriad of job opportunities and employment benefits designed to help you meet your career and personal goals. Our employees enjoy comprehensive benefits, including health insurance, retirement plans, and family-friendly policies that pave the way for a fulfilling career and life balance.

Explore Job Opportunities and Internships

Whether you’re looking to start your career or take it to the next level, Johnson & Johnson offers positions ranging from internships to leadership roles across various sectors. Enhance your skills through hands-on experience and our extensive networking and mentorship programs.

Johnson & Johnson Leadership and Development

Our commitment to leadership and continuous learning is at the core of our employment philosophy. Every position offers chances to lead, learn, and innovate. We provide extensive training programs and development courses that prepare you for the future of health care.

Stay Connected

Join Our Team

Search open positions that match your skills and interests. We are constantly hiring and looking for curious, driven, and compassionate team players.

SEARCH JOHNSON & JOHNSON JOBS

Keep Up to Date

Stay informed with career tips, insider perspectives, and industry-leading insights you can put to use today—all from the people who work here.

READ CAREERS BLOG

Job Alert Emails

Customize your subscription to receive job alerts, latest news, and insider tips tailored to your preferences. Discover the exciting and rewarding career opportunities that await at Johnson & Johnson. Join Johnson & Johnson today to be a part of a team that values innovation, leadership, and diversity, and see how far your ambition can take you.
Learn more about Johnson & Johnson
Size
141,700 employees
Market Cap
$462.7 billion
Industry
Net Income
$14.7 billion
Founded
1886
5 Year Trend
+5.5%
Revenue
$82.5 billion
NASDAQ

Similar Jobs

More Jobs at Johnson & Johnson

More Information Technology Jobs

Find similar Professional Governance & Policy Analyst jobs: