Description:
Assessment CoE Analyst
Job Description: Assessment CoE Analyst Remote; Hybrid (3 days/week in Raritan) preferred. PURPOSE OF POSITION In the Assessment CoE Analyst role you will work within the Information Security and Risk Management (ISRM) department joining the team responsible for ensuring the security of software applications. You will be responsible for security & controls throughout global projects related to R&D Supply Chain and Medical Technology applications including both 3rd party and internally developed applications. RESPONSIBILITIES/PRINCIPAL DUTIES Primary responsibilities include the following: Orchestrate and deliver cybersecurity risk assessments J&J Applications and the technologies that run them while maintaining awareness of the changing threat landscape. Support the design of cybersecurity controls ensure proper design implementation and assurance testing. Responsible for identifying risks related to the application prior to go-live and ensuring that appropriate mitigation/remediation plans are in place. Understand and promote risk management activities associated with external regulations and internal Johnson & Johnson policies such as J&J Internal Asset Protection Policies (IAPP) GxP SOX and GDPR Facilitate education and training to the program team on cybersecurity and internal control procedures and controls. Provide a periodic work status update in the form of a summary slide of accomplishments blockers risks. Build relationships with global stakeholders and provide consulting related to security controls implementation throughout project phases Make recommendations for application security including change incident management process enhancements access management and change management Consult with stakeholders about controls related to data classification and privacy including data encryption and protection EXPERIENCE/COMPETENCIES Minimum 5 years experience working with security and controls consulting stakeholders throughout the application lifecycle development process Experienced in identifying and articulating Controls/gaps around application security issues Working knowledge of pharmaceutical business processes Experienced in SOX compliance requirement/ IT General Controls Experience in supporting internal and external Audits. Self-starter and proficient multitasker with excellent documentation communication and organizational skills Strong technical skills including troubleshooting acumen for complex issues in need of problem solving. Strong teamwork and communication/information sharing skills. Exercise judgment and influence on key processes and technical decisions (e.g. - policy standards technical solutions). Good organization planning and time management skills. Demonstrated ability to manage complexity and handle/prioritize multiple tasks. Process and detail oriented. Excellent written and verbal skills (required for high-volume communications with company employees involved in data preservation tasks.) Education Bachelor s Degree in Information Technology Computer Science or a related field Pharmaceutical industry related Security Certifications preferred but not required.
Top Three Skills: degree in Computer science/Information tech verbal skills consulting stakeholders
Enable Skills-Based Hiring | No |
|
|
---|
Is this position safety sensitive try var fgTooltip new ( element: $(#cfdescz) text: Safetyx20sensitivex20jobsx20referx20tox20thosex20positionsx20wherex20jobx20responsibilitiesx20mayx20impactx20thex20healthx20andx20safetyx20ofx20x281x29x20thex20employeex20x282x29x20cox2Dworkersx20x283x29x20publicx20atx20largex20orx20mayx20resultx20inx20significantx20propertyx20damagex20ifx20performedx20underx20thex20influencex20ofx20alcoholx20andx2Forx20drugs.x20Examplesx20ofx20thesex20typesx20ofx20positionsx20atx20Jx26Jx20mayx20includex20poweredx20industrialx20vehiclex20driversx20x28suchx20asx20forkliftx20driversx29x20workersx20whox20workx20withx20controlledx20substancesx20ORx20otherx20positionsx20asx20definedx20basedx20onx20regionalx20Legalx20andx20Regulatoryx20requirementsx20x28suchx20asx20thex20D.O.T.x20inx20thex20U.S.x29.x20Pleasex20consultx20withx20EHx26Sx20ifx20youx20arex20uncertain. ).initialize(); catch(err) | |
Additional Details
- Solution & Requisition Sourcing Type : Vendor NeutralSourced
- Reason for Request : *To be entered by the Concierge Center
- Critical Position : No
- Is this position safety sensitive : No
- Will this position require the handling of a controlled substance : No