Apply

Ready to go for it?

AI Apply speeds things up—apply directly if you prefer.

FREE ACCESS
5,000–10,000 jobs/day
Scoutfield Logo

See all jobs on Scoutfield

Search thousands of fresh jobs every day.

Discover
  • Fresh listings
  • Fast filters
  • No subscription required
Create a free account and start exploring right away.
Johnson & Johnson

Governance & Policy Analyst

Johnson & Johnson

. Own and maintain the cybersecurity policy and standards library, including annual attestation and exception management .

Posted 9/23/2026full-timeUnited StatesMid-LevelSenior💰 $79,000 - $142,000 per yearWebsite

Core Competencies

Role fit
Core Competencies

Use this summary to align your resume positioning with the role.

Demonstrates expertise in cybersecurity governance, risk management, and compliance, with a strong focus on policy development, risk assessment, and reporting. Proficient in mapping controls to regulatory frameworks and driving cyber culture initiatives.

Highest-signal resume keywords
Cybersecurity GovernanceRisk Management FrameworkNIST CSFISO 27001Risk Assessment

ATS Keywords

Tailor your resume
Applicant Tracking System Keywords

Tip: use these terms in your resume and cover letter to boost ATS matches.

Hard Skills
Cyber Risk ManagementSecurity Policy DevelopmentRisk Register MaintenanceRisk ScoringRemediation TrackingMetrics ReportingGovernance FrameworksThird-Party Risk AssessmentTechnical Risk TranslationGRC Automation
Soft Skills
Strong Written CommunicationStakeholder Influence
Certifications & Qualifications
CISSPCRISCCISMCISACGRCISO 27001 Lead Implementer
Industry Keywords
Cybersecurity PolicyGovernance ForumsCompliance StandardsSOC 2HIPAAGDPRFDA Cybersecurity GuidanceIT ControlsSOX ComplianceCloud Migration

Tech Stack

Tools & technologies
CloudCyber Security

About the role

Key responsibilities & impact
  • Own and maintain the cybersecurity policy and standards library, including annual attestation and exception management
  • Maintain and improve the cyber risk management framework and methodology
  • Facilitate and document cyber risk assessments and track remediation to closure
  • Administer the enterprise risk register and escalate overdue or elevated risks
  • Coordinate cybersecurity governance forums, decision logging, and action-item follow-through
  • Develop executive and operational reporting packages for CIO, CISO, and leadership audiences
  • Design and report cyber risk metrics and Key Risk Indicators
  • Support third-party and vendor cyber risk oversight
  • Map policy and control requirements to NIST CSF, ISO 27001, HIPAA, GDPR, and FDA cybersecurity guidance
  • Partner with IT Controls and SOX teams on governance and control design
  • Drive cyber culture and awareness initiatives
  • Assess governance impacts of technology changes, cloud migrations, and separation/carve-out activities
  • Support internal and external audits, regulatory inquiries, and customer security assessments
  • Identify opportunities to automate GRC workflows, reporting, and evidence collection

Requirements

What you’ll need
  • Bachelor's degree in Information Technology, Cybersecurity, Information Systems, Risk Management, Business, or a related discipline
  • 4+ years of experience in cybersecurity governance, IT risk management, technology compliance, or a related GRC discipline
  • Experience authoring and maintaining security policies, standards, and procedures within a formal governance lifecycle
  • Working knowledge of NIST CSF, NIST 800-53, ISO 27001/27002, and COBIT
  • Hands-on experience conducting risk assessments and maintaining a risk register, including risk scoring, treatment planning, and remediation tracking
  • Experience supporting governance forums and producing leadership-ready reporting, metrics, and dashboards
  • Familiarity with third-party/vendor risk assessment processes and review of SOC 2 / ISO certifications
  • Strong written communication skills and ability to translate technical risk into clear business language and influence stakeholders without direct authority
  • English proficiency required
  • Up to 15% domestic travel expected
  • Preferred: Master's degree in Cybersecurity, Information Systems, or Business Administration
  • Preferred certifications: CISSP, CRISC, CISM, CISA, CGRC, or ISO 27001 Lead Implementer/Auditor

Benefits

Comp & perks
  • Pension plan
  • 401(k) savings plan
  • Vacation – 120 hours per calendar year
  • Sick time – 40 hours per calendar year; 48 hours for employees residing in Colorado; 56 hours for employees residing in Washington
  • Holiday pay, including Floating Holidays – 13 days per calendar year
  • Work, Personal and Family Time – up to 40 hours per calendar year
  • Parental Leave – 480 hours within one year of birth/adoption/foster care of a child
  • Bereavement Leave – 240 hours for an immediate family member; 40 hours for an extended family member per calendar year
  • Caregiver Leave – 80 hours in a 52-week rolling period
  • Volunteer Leave – 32 hours per calendar year
  • Military Spouse Time-Off – 80 hours per calendar year
  • Inclusive interview process and disability accommodations