Analyst, Cyber Risk Assessment

Johnson & Johnson

Not Interested
Bookmark
Report This Job

profile Job Location:

Raritan, NJ - USA

profile Monthly Salary: $ 79000 - 127650
Posted on: 3 hours ago
Vacancies: 1 Vacancy

Job Summary

At Johnson & Johnsonwe believe health is everything. Our strength in healthcare innovation empowers us to build aworld where complex diseases are prevented treated and curedwhere treatments are smarter and less invasive andsolutions are our expertise in Innovative Medicine and MedTech we are uniquely positioned to innovate across the full spectrum of healthcare solutions today to deliver the breakthroughs of tomorrow and profoundly impact health for more at

Job Function:

Technology Enterprise Strategy & Security

Job Sub Function:

Security & Controls

Job Category:

Scientific/Technology

All Job Posting Locations:

Raritan New Jersey United States of America

Job Description:

Johnson & Johnson is recruiting for a Cyber Security Analyst to join the Information Security & Risk Management (ISRM) team. This role is based in the United States with the Raritan NJ location preferred.

Are you ready to use your technical knowledge to change the trajectory of health for humanity We have a position for you!

Caring for the world one person at a time inspired and united the people of Johnson & Johnson for over 130 years. We embrace research and science -- bringing innovative ideas products and services to advance the health and well-being of people.

At Johnson & Johnson we believe good health is the foundation of vibrant lives thriving communities and forward progress. Thats why for more than 130 years we have aimed to keep people well at every age and every stage of life. Today as the worlds largest and most broadly-based healthcare company we are committed to using our reach and size for good. We strive to improve access and affordability create healthier communities and put a healthy mind body and environment within reach of everyone everywhere. Every day our more than 130000 employees across the world are blending heart science and ingenuity to profoundly change the trajectory of health for humanity.

Thriving on a diverse company culture celebrating the uniqueness of our employees and committed to inclusion. Proud to be an equal opportunity employer!

As an integral member of the ISRM Risk Assessment Center of Excellence team you will identify and assess cyber risks within hosted solutions (e.g. SaaS) this role you will work with a diverse global team of skilled cyber security professionals.

Key Responsibilities:

  • Perform and lead technical application risk assessments design reviews risk rankings and collaboration on remediation strategies as needed.

  • Perform in-depth reviews of control implementation evidence to assess control sufficiency operating effectiveness and any gaps requiring remediation.

  • Communicate cybersecurity risk assessment results to key stakeholders and management and provide input on remediation plans.

  • Enhance cyber risk assessment processes by defining and implementing process improvements.

  • Support the design of cybersecurity controls to ensure proper design implementation and assurance testing.

  • Offer consulting support to the larger cybersecurity team on risk assessment understanding and remediation.

Qualifications

Education:

  • A bachelors degree in Computer Science Engineering or Information Security/Cybersecurity or equivalent degree is required.

  • Security certifications such as CISSP CCSP CISA CRISC etc. are preferred.

Experience and Skills:

Required:

  • 3 years of direct cybersecurity risk assessment experience including application of risk assessment/management concepts and internal controls and using a GRC tool to support security risk objectives.

  • Proficiency in conducting and leading application-level risk assessments including data classification risk scoring and mitigation planning.

  • Ability to translate technical findings into business impact for key partners.

  • Strong analytical and problem-solving skills.

  • Strong interpersonal skills to build and maintain relationships with internal partners.

  • Preferred:

  • Experience securing cloud environments and/or SaaS platforms.

  • Understanding of secure software development life cycle (SSDLC) threat modeling and vulnerability management.

  • Foundational knowledge of regulatory requirements (e.g. SOX404 Privacy HIPAA GxP cyber regulations).

  • Experience with security standards and control frameworks (e.g. FAIR ISO27001 NIST SOC 2 OWASP Top 10 CSA STAR etc.).

#LI-Hybrid
#JNJTech

Johnson & Johnson is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race color religion sex sexual orientation gender identity age national origin disability protected veteran status or other characteristics protected by federal state or local law. We actively seek qualified candidates who are protected veterans and individuals with disabilities as defined under VEVRAA and Section 503 of the Rehabilitation Act.

Johnson & Johnson is committed to providing an interview process that is inclusive of our applicants needs. If you are an individual with a disability and would like to request an accommodation please contact us via or contact AskGS to be directed to your accommodation resource.

Required Skills:

Preferred Skills:

Analytical Reasoning Communication Corrective and Preventive Action (CAPA) Industry Analysis Information Security Auditing Information Security Management System (ISMS) Information Technology (IT) Security Assessments Information Technology Strategies Mentorship Process Oriented Risk Assessments Root Cause Analysis (RCA) Security Policies Solution Architecture Technologically Savvy Vulnerability Assessments

The anticipated base pay range for this position is :

$79000.00 - $127650.00

Additional Description for Pay Transparency:

Subject to the terms of their respective plans employees are eligible to participate in the Companys consolidated retirement plan (pension) and savings plan (401(k)).

Subject to the terms of their respective policies and date of hire employees are eligible for the following time off benefits:

Vacation 120 hours per calendar year

Sick time - 40 hours per calendar year; for employees who reside in the State of Colorado 48 hours per calendar year; for employees who reside in the State of Washington 56 hours per calendar year

Holiday pay including Floating Holidays 13 days per calendar year

Work Personal and Family Time - up to 40 hours per calendar year

Parental Leave 480 hours within one year of the birth/adoption/foster care of a child

Bereavement Leave 240 hours for an immediate family member: 40 hours for an extended family member per calendar year

Caregiver Leave 80 hours in a 52-week rolling period10 days

Volunteer Leave 32 hours per calendar year

Military Spouse Time-Off 80 hours per calendar year

Additional information can be found through the link below.

For additional general information on Company benefits please go to: - Experience:

IC

At Johnson & Johnsonwe believe health is everything. Our strength in healthcare innovation empowers us to build aworld where complex diseases are prevented treated and curedwhere treatments are smarter and less invasive andsolutions are our expertise in Innovative Medicine and MedTech we are unique...
View more view more

Key Skills

  • ISO 27001
  • Microsoft Access
  • Risk Management
  • Financial Services
  • PCI
  • Risk Analysis
  • Analysis Skills
  • COBIT
  • NIST Standards
  • SOX
  • Information Security
  • Data Analysis Skills

About Company

Company Logo

About Johnson & Johnson A t Johnson & Johnson, we believe good health is the foundation of vibrant lives, thriving communities and forward progress. That’s why for more than 130 years, we have aimed to keep people well at every age and every stage of life. Today, as the world’s larges ... View more

View Profile View Profile