FREE ACCESS
5,000–10,000 jobs/day
See all jobs on Scoutfield
Search thousands of fresh jobs every day.
Discover
- Fresh listings
- Fast filters
- No subscription required
Create a free account and start exploring right away.

Governance and Policy Analyst
Johnson & Johnson. Own and maintain the cybersecurity policy and standards library, including annual attestation and exception management .
Core Competencies
Role fitCore Competencies
Use this summary to align your resume positioning with the role.
Demonstrates expertise in cybersecurity governance, risk management, and compliance, with a strong focus on policy development, risk assessment, and reporting. Proficient in mapping controls to regulatory frameworks and driving cyber culture initiatives within organizations.
Highest-signal resume keywords
Cybersecurity GovernanceRisk Management FrameworkNIST CSFISO 27001Third-Party Risk Assessment
ATS Keywords
Tailor your resumeApplicant Tracking System Keywords
Tip: use these terms in your resume and cover letter to boost ATS matches.
Hard Skills
Risk AssessmentPolicy DevelopmentRisk Register ManagementMetrics ReportingGovernance Frameworks
Soft Skills
Strong Written CommunicationStakeholder Influence
Tools & Technologies
ServiceNow IRMArcherOneTrustAuditBoardPower BITableau
Certifications & Qualifications
CISSPCRISCCISMCISAISO 27001 Lead Implementer
Industry Keywords
HIPAAGDPRFDA CybersecurityMedTechLife Sciences
Tech Stack
Tools & technologiesAWSAzureCloudCyber SecurityServiceNowTableau
About the role
Key responsibilities & impact- Own and maintain the cybersecurity policy and standards library, including annual attestation and exception management
- Maintain and improve the cyber risk management framework and methodology
- Facilitate and document cyber risk assessments across applications, infrastructure, business processes, and change initiatives
- Administer the enterprise risk register, including ownership assignment, aging analysis, and escalation of overdue or elevated risks
- Coordinate cybersecurity governance forums, agendas, materials, decisions, and action items
- Develop executive and operational reporting packages for CIO, CISO, and leadership audiences
- Design, baseline, and report cyber risk metrics and Key Risk Indicators
- Support third-party and vendor cyber risk oversight, including tiering, questionnaire review, SOC 2/ISO 27001 evidence evaluation, contractual requirements, and monitoring
- Map policies and controls to NIST CSF, ISO 27001, HIPAA, GDPR, and FDA cybersecurity guidance
- Partner with IT Controls and SOX teams on governance and control design
- Drive cyber culture and awareness initiatives, policy communications, training, and enablement
- Assess governance impacts of technology changes, cloud migrations, and separation/carve-out activity
- Support internal and external audits, regulatory inquiries, and customer security assessments
- Identify opportunities to automate GRC workflows, reporting, and evidence collection
Requirements
What you’ll need- Bachelor's degree in Information Technology, Cybersecurity, Information Systems, Risk Management, Business, or a related discipline
- 4+ years of experience in cybersecurity governance, IT risk management, technology compliance, or a related GRC discipline
- Experience authoring and maintaining security policies, standards, and procedures within a formal governance lifecycle
- Working knowledge of NIST CSF, NIST 800-53, ISO 27001/27002, and COBIT
- Hands-on experience conducting risk assessments and maintaining a risk register, including risk scoring, treatment planning, and remediation tracking
- Experience supporting governance forums and producing leadership-ready reporting, metrics, and dashboards
- Familiarity with third-party/vendor risk assessment processes and review of SOC 2 / ISO certifications
- Strong written communication skills and ability to translate technical risk into clear business language and influence stakeholders without direct authority
- English proficiency required
- Preferred: Master's degree in Cybersecurity, Information Systems, or Business Administration
- Preferred: MedTech, Life Sciences, or regulated industry experience; HIPAA, GDPR, and FDA medical device cybersecurity knowledge
- Preferred: GRC function experience within a divestiture, carve-out, spin-off, or standalone entity stand-up
- Preferred: GRC platforms such as ServiceNow IRM, Archer, OneTrust, or AuditBoard and workflow configuration
- Preferred: Enterprise KRI and risk appetite experience
- Preferred: AWS/Azure cloud governance and SaaS/cloud-hosted control experience
- Preferred: Power BI or Tableau proficiency
- Preferred: Generative AI/LLM-enabled tooling experience
- Preferred: Security awareness and cyber culture program experience
- Preferred certifications: CISSP, CRISC, CISM, CISA, CGRC, or ISO 27001 Lead Implementer/Auditor
Benefits
Comp & perks- Consolidated retirement plan (pension)
- Savings plan (401(k))
- Vacation – 120 hours per calendar year
- Sick time – 40 hours per calendar year; Colorado employees – 48 hours per calendar year; Washington employees – 56 hours per calendar year
- Holiday pay, including Floating Holidays – 13 days per calendar year
- Work, Personal and Family Time – up to 40 hours per calendar year
- Parental Leave – 480 hours within one year of the birth/adoption/foster care of a child
- Bereavement Leave – 240 hours for an immediate family member; 40 hours for an extended family member per calendar year
- Caregiver Leave – 80 hours in a 52-week rolling period
- Volunteer Leave – 32 hours per calendar year
- Military Spouse Time-Off – 80 hours per calendar year