
location_onMichael's Inn, 46, Thompson Street, Raritan, Somerset County, New Jersey, 08869, United States
At Johnson & Johnson, we believe health is everything. Our strength in healthcare innovation empowers us to build a world where complex diseases are prevented, treated, and cured, where treatments are smarter and less invasive, and solutions are personal. Through our expertise in Innovative Medicine and MedTech, we are uniquely positioned to innovate across the full spectrum of healthcare solutions today to deliver the breakthroughs of tomorrow, and profoundly impact health for humanity.
As guided by Our Credo, Johnson & Johnson is responsible to our employees who work with us throughout the world. We provide an inclusive work environment where each person is considered as an individual. We respect the diversity and dignity of our employees and recognize their merit. Caring for the world, one person at a time, has inspired and united our people for over 130 years. Today, as the world's largest and most broadly-based healthcare company, we are committed to using our reach and size for good, striving to improve access and affordability, create healthier communities, and put a healthy mind, body, and environment within reach of everyone, everywhere.
This role serves as a senior technical authority and thought leader for third‑party cyber risk assessments across Johnson & Johnson's global ecosystem of vendors, SaaS providers, and strategic partners. As an integral member of the Information Security & Risk Management (ISRM) Risk Assessment Center of Excellence team, you will identify and assess cyber risks within the Third-Party Risk Assessment (TPRA) service.
You will work with a diverse, global team of skilled cyber security professionals to drive automation, process improvements, and consulting support. This position offers the opportunity to use your technical knowledge to change the trajectory of health for humanity by ensuring the security of our vast partner network.
This role is based in the United States with the Raritan, NJ location preferred, but is also available internally to our ISRM Service Centers in São José dos Campos, São Paulo, Brasil, and Warsaw, Poland. Please note that this role is available across multiple countries and may be posted under different requisition numbers to comply with local requirements. While you are welcome to apply to any or all of the postings, we recommend focusing on the specific country(s) that align with your preferred location(s). Whether you apply to one or all of these requisition numbers, your applications will be considered as a single submission.
Johnson & Johnson is committed to providing an interview process that is inclusive of our applicants' needs. If you are an individual with a disability and would like to request an accommodation, please contact us via jnj.com or contact AskGS to be directed to your accommodation resource.
Johnson & Johnson is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, age, national origin, disability, protected veteran status, or other characteristics protected by federal, state, or local law. We actively seek qualified candidates who are protected veterans and individuals with disabilities as defined under VEVRAA and Section 503 of the Rehabilitation Act. We thrive on a diverse company culture, celebrating the uniqueness of our employees, and are committed to inclusion.
Work model: Hybrid
Michael's Inn, 46, Thompson Street, Raritan, Somerset County, New Jersey, 08869, United States
Raritan, New Jersey
Security certifications such as CISSP, CCSP, CISA, CRISC, etc. Advanced degree. Foundational knowledge of regulatory requirements (e.g., SOX404, Privacy, HIPAA, GxP, cyber regulations). Experience assessing third-party risk in a large, dynamic, multinational organization. Experience in identifying key security risks, security controls, and providing consulting services to customers throughout the third-party vendor lifecycle. Experience with security standards and control frameworks (e.g. FAIR, HITRUST, ISO27001, NIST, SOC 2, etc.). Demonstrable record of effectively collaborating with virtual, global teams, including diverse groups of people with varied backgrounds and cultural experiences. Business Process Design, Crisis Management, Critical Thinking, Information Security Auditing, Information Security Management System (ISMS), Information Technology (IT) Security Assessments, Information Technology Strategies, Mentorship, Organizing, Presentation Design, Process Optimization, Root Cause Analysis (RCA), Security Architecture Design, Security Policies, Technical Credibility, Vulnerability Management.
Skills: Cissp, CCSP, Cisa, Crisc, Sox404, Hipaa, GXP, Fair, Hitrust, Iso27001.
Education: Bachelor's degree in Computer Science, Engineering, or Information Security/Cybersecurity required.