Apply

Ready to go for it?

AI Apply speeds things up—apply directly if you prefer.

FREE ACCESS
5,000–10,000 jobs/day
Scoutfield Logo

See all jobs on Scoutfield

Search thousands of fresh jobs every day.

Discover
  • Fresh listings
  • Fast filters
  • No subscription required
Create a free account and start exploring right away.
Johnson & Johnson

Governance and Policy Analyst

Johnson & Johnson

. Own and maintain the cybersecurity policy and standards library, including annual attestation and exception management .

Posted 9/23/2026full-timeUnited StatesMid-LevelSenior💰 $79,000 - $142,000 per yearWebsite

Core Competencies

Role fit
Core Competencies

Use this summary to align your resume positioning with the role.

Demonstrates expertise in cybersecurity governance, risk management, and compliance, with a strong focus on policy development, risk assessment, and reporting. Proficient in mapping controls to regulatory frameworks and driving cyber culture initiatives within organizations.

Highest-signal resume keywords
Cybersecurity GovernanceRisk Management FrameworkNIST CSFISO 27001Third-Party Risk Assessment

ATS Keywords

Tailor your resume
Applicant Tracking System Keywords

Tip: use these terms in your resume and cover letter to boost ATS matches.

Hard Skills
Risk AssessmentPolicy DevelopmentRisk Register ManagementMetrics ReportingGovernance Frameworks
Soft Skills
Strong Written CommunicationStakeholder Influence
Tools & Technologies
ServiceNow IRMArcherOneTrustAuditBoardPower BITableau
Certifications & Qualifications
CISSPCRISCCISMCISAISO 27001 Lead Implementer
Industry Keywords
HIPAAGDPRFDA CybersecurityMedTechLife Sciences

Tech Stack

Tools & technologies
AWSAzureCloudCyber SecurityServiceNowTableau

About the role

Key responsibilities & impact
  • Own and maintain the cybersecurity policy and standards library, including annual attestation and exception management
  • Maintain and improve the cyber risk management framework and methodology
  • Facilitate and document cyber risk assessments across applications, infrastructure, business processes, and change initiatives
  • Administer the enterprise risk register, including ownership assignment, aging analysis, and escalation of overdue or elevated risks
  • Coordinate cybersecurity governance forums, agendas, materials, decisions, and action items
  • Develop executive and operational reporting packages for CIO, CISO, and leadership audiences
  • Design, baseline, and report cyber risk metrics and Key Risk Indicators
  • Support third-party and vendor cyber risk oversight, including tiering, questionnaire review, SOC 2/ISO 27001 evidence evaluation, contractual requirements, and monitoring
  • Map policies and controls to NIST CSF, ISO 27001, HIPAA, GDPR, and FDA cybersecurity guidance
  • Partner with IT Controls and SOX teams on governance and control design
  • Drive cyber culture and awareness initiatives, policy communications, training, and enablement
  • Assess governance impacts of technology changes, cloud migrations, and separation/carve-out activity
  • Support internal and external audits, regulatory inquiries, and customer security assessments
  • Identify opportunities to automate GRC workflows, reporting, and evidence collection

Requirements

What you’ll need
  • Bachelor's degree in Information Technology, Cybersecurity, Information Systems, Risk Management, Business, or a related discipline
  • 4+ years of experience in cybersecurity governance, IT risk management, technology compliance, or a related GRC discipline
  • Experience authoring and maintaining security policies, standards, and procedures within a formal governance lifecycle
  • Working knowledge of NIST CSF, NIST 800-53, ISO 27001/27002, and COBIT
  • Hands-on experience conducting risk assessments and maintaining a risk register, including risk scoring, treatment planning, and remediation tracking
  • Experience supporting governance forums and producing leadership-ready reporting, metrics, and dashboards
  • Familiarity with third-party/vendor risk assessment processes and review of SOC 2 / ISO certifications
  • Strong written communication skills and ability to translate technical risk into clear business language and influence stakeholders without direct authority
  • English proficiency required
  • Preferred: Master's degree in Cybersecurity, Information Systems, or Business Administration
  • Preferred: MedTech, Life Sciences, or regulated industry experience; HIPAA, GDPR, and FDA medical device cybersecurity knowledge
  • Preferred: GRC function experience within a divestiture, carve-out, spin-off, or standalone entity stand-up
  • Preferred: GRC platforms such as ServiceNow IRM, Archer, OneTrust, or AuditBoard and workflow configuration
  • Preferred: Enterprise KRI and risk appetite experience
  • Preferred: AWS/Azure cloud governance and SaaS/cloud-hosted control experience
  • Preferred: Power BI or Tableau proficiency
  • Preferred: Generative AI/LLM-enabled tooling experience
  • Preferred: Security awareness and cyber culture program experience
  • Preferred certifications: CISSP, CRISC, CISM, CISA, CGRC, or ISO 27001 Lead Implementer/Auditor

Benefits

Comp & perks
  • Consolidated retirement plan (pension)
  • Savings plan (401(k))
  • Vacation – 120 hours per calendar year
  • Sick time – 40 hours per calendar year; Colorado employees – 48 hours per calendar year; Washington employees – 56 hours per calendar year
  • Holiday pay, including Floating Holidays – 13 days per calendar year
  • Work, Personal and Family Time – up to 40 hours per calendar year
  • Parental Leave – 480 hours within one year of the birth/adoption/foster care of a child
  • Bereavement Leave – 240 hours for an immediate family member; 40 hours for an extended family member per calendar year
  • Caregiver Leave – 80 hours in a 52-week rolling period
  • Volunteer Leave – 32 hours per calendar year
  • Military Spouse Time-Off – 80 hours per calendar year