FREE ACCESS
5,000–10,000 jobs/day
See all jobs on Scoutfield
Search thousands of fresh jobs every day.
Discover
- Fresh listings
- Fast filters
- No subscription required
Create a free account and start exploring right away.

Governance & Policy Analyst
Johnson & Johnson. Own and maintain the cybersecurity policy and standards library, including annual attestation and exception management .
Core Competencies
Role fitCore Competencies
Use this summary to align your resume positioning with the role.
Demonstrates expertise in cybersecurity governance, risk management, and compliance, with a strong focus on policy development, risk assessment, and reporting. Proficient in mapping controls to regulatory frameworks and driving cyber culture initiatives.
Highest-signal resume keywords
Cybersecurity GovernanceRisk Management FrameworkNIST CSFISO 27001Risk Assessment
ATS Keywords
Tailor your resumeApplicant Tracking System Keywords
Tip: use these terms in your resume and cover letter to boost ATS matches.
Hard Skills
Cyber Risk ManagementSecurity Policy DevelopmentRisk Register MaintenanceRisk ScoringRemediation TrackingMetrics ReportingGovernance FrameworksThird-Party Risk AssessmentTechnical Risk TranslationGRC Automation
Soft Skills
Strong Written CommunicationStakeholder Influence
Certifications & Qualifications
CISSPCRISCCISMCISACGRCISO 27001 Lead Implementer
Industry Keywords
Cybersecurity PolicyGovernance ForumsCompliance StandardsSOC 2HIPAAGDPRFDA Cybersecurity GuidanceIT ControlsSOX ComplianceCloud Migration
Tech Stack
Tools & technologiesCloudCyber Security
About the role
Key responsibilities & impact- Own and maintain the cybersecurity policy and standards library, including annual attestation and exception management
- Maintain and improve the cyber risk management framework and methodology
- Facilitate and document cyber risk assessments and track remediation to closure
- Administer the enterprise risk register and escalate overdue or elevated risks
- Coordinate cybersecurity governance forums, decision logging, and action-item follow-through
- Develop executive and operational reporting packages for CIO, CISO, and leadership audiences
- Design and report cyber risk metrics and Key Risk Indicators
- Support third-party and vendor cyber risk oversight
- Map policy and control requirements to NIST CSF, ISO 27001, HIPAA, GDPR, and FDA cybersecurity guidance
- Partner with IT Controls and SOX teams on governance and control design
- Drive cyber culture and awareness initiatives
- Assess governance impacts of technology changes, cloud migrations, and separation/carve-out activities
- Support internal and external audits, regulatory inquiries, and customer security assessments
- Identify opportunities to automate GRC workflows, reporting, and evidence collection
Requirements
What you’ll need- Bachelor's degree in Information Technology, Cybersecurity, Information Systems, Risk Management, Business, or a related discipline
- 4+ years of experience in cybersecurity governance, IT risk management, technology compliance, or a related GRC discipline
- Experience authoring and maintaining security policies, standards, and procedures within a formal governance lifecycle
- Working knowledge of NIST CSF, NIST 800-53, ISO 27001/27002, and COBIT
- Hands-on experience conducting risk assessments and maintaining a risk register, including risk scoring, treatment planning, and remediation tracking
- Experience supporting governance forums and producing leadership-ready reporting, metrics, and dashboards
- Familiarity with third-party/vendor risk assessment processes and review of SOC 2 / ISO certifications
- Strong written communication skills and ability to translate technical risk into clear business language and influence stakeholders without direct authority
- English proficiency required
- Up to 15% domestic travel expected
- Preferred: Master's degree in Cybersecurity, Information Systems, or Business Administration
- Preferred certifications: CISSP, CRISC, CISM, CISA, CGRC, or ISO 27001 Lead Implementer/Auditor
Benefits
Comp & perks- Pension plan
- 401(k) savings plan
- Vacation – 120 hours per calendar year
- Sick time – 40 hours per calendar year; 48 hours for employees residing in Colorado; 56 hours for employees residing in Washington
- Holiday pay, including Floating Holidays – 13 days per calendar year
- Work, Personal and Family Time – up to 40 hours per calendar year
- Parental Leave – 480 hours within one year of birth/adoption/foster care of a child
- Bereavement Leave – 240 hours for an immediate family member; 40 hours for an extended family member per calendar year
- Caregiver Leave – 80 hours in a 52-week rolling period
- Volunteer Leave – 32 hours per calendar year
- Military Spouse Time-Off – 80 hours per calendar year
- Inclusive interview process and disability accommodations