Professional Governance & Policy Analyst
Listed on 2026-09-30
-
IT/Tech
Cybersecurity
At Johnson & Johnson, we believe health is everything. Our strength in healthcare innovation empowers us to build a world where complex diseases are prevented, treated, and cured, where treatments are smarter and less invasive, and solutions are personal. Through our expertise in Innovative Medicine and Med Tech, we are uniquely positioned to innovate across the full spectrum of healthcare solutions today to deliver the breakthroughs of tomorrow, and profoundly impact health for humanity.
Learn more at
As guided by Our Credo, Johnson & Johnson is responsible to our employees who work with us throughout the world. We provide an inclusive work environment where each person is considered as an individual. At Johnson & Johnson, we respect the diversity and dignity of our employees and recognize their merit.
Job FunctionJob Sub Function
Job Category
New Brunswick, New Jersey, United States of America, Palm Beach Gardens, Florida, United States of America, Raritan, New Jersey, United States of America, Raynham, Massachusetts, United States of America, Warsaw, Indiana, United States of America, West Chester, Pennsylvania, United States of America
Job DescriptionDePuy Synthes is recruiting for a(n) Professional, Governance & Policy Analyst.
The Professional, Governance & Policy Analyst is an established and productive individual contributor within the Cybersecurity function, GRC, IT Controls & Cyber Culture sub-function, accountable for the design, maintenance, and operationalization of the cybersecurity policy framework, risk methodology, and governance reporting model for DePuy Synthes. This role owns the cyber policy and standards library, administers the enterprise cyber risk register and assessment lifecycle, coordinates governance forums and executive reporting, and supports third‑party risk oversight.
Working under moderate supervision, the analyst applies practical knowledge of GRC frameworks to translate regulatory expectations into clear, actionable standards, and partners across IT, Legal, Privacy, Quality, Procurement, and business functions to strengthen risk‑informed decision‑making and a strong cyber culture.
- Own the cybersecurity policy and standards library — authoring, reviewing, and maintaining policies, standards, procedures, and guidelines on a defined lifecycle, including annual attestation and exception management.
- Maintain and continuously improve the cyber risk management framework and methodology, including risk taxonomy, scoring criteria, risk appetite thresholds, and treatment/acceptance workflows.
- Facilitate and document cyber risk assessments across applications, infrastructure, business processes, and change initiatives; capture outcomes in the enterprise risk register and track remediation to closure.
- Administer the risk register as the single source of truth — ensuring completeness, accuracy, ownership assignment, aging analysis, and timely escalation of overdue or elevated risks.
- Coordinate cybersecurity governance forums (e.g., Cyber Risk Council, steering committees), including agenda development, materials preparation, decision logging, and action item follow‑through.
- Develop and publish executive and operational reporting packages that translate technical risk data into clear business impact narratives for CIO, CISO, and leadership audiences.
- Design, baseline, and report on cyber risk metrics and Key Risk Indicators (KRIs), establishing thresholds and trend analysis to drive proactive risk management.
- Support third-party and vendor cyber risk oversight — including risk tiering, security questionnaire review, SOC 2 / ISO 27001 evidence evaluation, contractual security requirements, and ongoing monitoring of critical suppliers.
- Map policy and…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).