채용
Supply Chain Sr. Cybersecurity Analyst - Third-Party Risk & Remediation (fixed-term)

Supply Chain Sr. Cybersecurity Analyst - Third-Party Risk & Remediation (fixed-term)
São José dos Campos, São Paulo, Brazil
·
On-site
·
Full-time
·
1w ago
At Johnson & Johnson, we believe health is everything. Our strength in healthcare innovation empowers us to build a world where complex diseases are prevented, treated, and cured, where treatments are smarter and less invasive, and solutions are personal. Through our expertise in Innovative Medicine and Med Tech, we are uniquely positioned to innovate across the full spectrum of healthcare solutions today to deliver the breakthroughs of tomorrow, and profoundly impact health for humanity. Learn more at jnj.com.
As guided by Our Credo, Johnson & Johnson is responsible to our employees who work with us throughout the world. We provide an inclusive work environment where each person is considered as an individual. At Johnson & Johnson, we respect the diversity and dignity of our employees and recognize their merit.
Job Function:
Technology Enterprise Strategy & Security:
Job Sub Function:
Security & Controls:
Job Category:
Scientific/Technology
All Job Posting Locations:
São José dos Campos, São Paulo, Brazil
Job Description:
Johnson & Johnson is currently seeking a Senior Analyst for Med Tech Supply Chain, part of the Information Security & Risk Management (ISRM) organization.
This candidate will have a background in supply chain, with skills in technology, and cybersecurity. They will be a strategic problem solver who performs with impact inclusively, driving intentional change proactively, and be driven to keep up with industry trends in cybersecurity. This role will embed directly with our J&J Technology and Med Tech Supply Chain teams providing the support vital to improve our security posture and enable end-to-end security portfolio/capability roadmaps to identify, mitigate and remediate cyber security vulnerabilities.
Responsibilities:
-
Facilitate comprehensive execution of third-party risk assessments, including coordination of business partner and third-party information gathering, in-depth risk analysis, and robust remediation planning and execution tracking. This role will serve as a primary issue manager for all security findings and vulnerabilities identified within the third-party landscape for Med Tech Supply Chain.
-
Engage with project teams to drive execution of the security capabilities and services needed for supply chain projects, ensuring alignment with GRC policies and proactively managing security-related issues.
-
Interpret & apply the internal security requirements and standards for Applications, IT, and OT (Operational Technology) initiatives, ensuring compliance and providing guidance on governance best practices, with a critical focus on ensuring third-party compliance with these standards.
-
Develop and/or execute awareness initiatives to promote the importance of cybersecurity across the sector and sites, reinforcing GRC principles and fostering a security-conscious culture, extending to our third-party ecosystem where applicable.
-
Work to achieve operational goals with direct impact on the Med Tech Supply Chain ISRM function and contributes to successful security integrations, ensuring all integrations meet governance and compliance requirements**.**
-
Analyze results of vulnerability assessments and system analyses to identify risks and mitigate future threats, taking full ownership of the issue management process from identification to resolution, particularly for vulnerabilities identified in third-party systems or processes.
-
Help establish and implement methods for improving Third Party Risk management processes by leveraging insight from third-party evaluations and root cause analysis investigations to resolve system deficiencies and security faults, enhancing the overall GRC framework, with a particular emphasis on improving the management and resolution of third-party security issues.
-
Coaches more junior colleagues in techniques, processes, and responsibilities, particularly in GRC methodologies and effective issue management, including the specific challenges and best practices for managing third-party security issues.
-
Understands and applies Johnson & Johnson's Credo and Leadership Imperatives in day-to-day interactions with team, upholding the highest standards of governance and ethical conduct.
Qualifications:
-
2+ years of related experience in execution roles within Cybersecurity or Risk Management, with a strong background in Governance, Risk, and Compliance (GRC) and Supply Chain required, specifically demonstrating experience in third-party risk management, vendor security assessments, and issue remediation.
-
Superb communication and collaboration skills, able to network, interact at middle management levels of the organization, cross-functionally, with proven ability to articulate GRC findings and drive issue resolution.
-
Attention to detail and ability to understand and align on strategic and tactical security concepts, critical for effective GRC compliance and issue management.
Required Skills:
Preferred Skills:
Analytical Reasoning, Communication, Corrective and Preventive Action (CAPA), Industry Analysis, Information Security Auditing, Information Security Management System (ISMS), Information Technology (IT) Security Assessments, Information Technology Strategies, Mentorship, Process Oriented, Risk Assessments, Root Cause Analysis (RCA), Security Policies, Solution Architecture, Technologically Savvy, Vulnerability Assessments
Total Views
0
Apply Clicks
0
Mock Applicants
0
Scraps
0
Similar Jobs

Senior Information System Security Officer (ISSO) - Marlborough, MA
Collins Aerospace (RTX) · US-MA-MARLBOROUGH-MA2 ~ 1001 Boston Post Rd ~ BLDG 2

Senior Solution Area Specialists - Security
Microsoft · United States, Multiple Locations, Multiple Locations

Staff Web Security Engineer (Blue Operations)
Coupang · Seoul, South Korea

Sr Anlyst Security - Tucson, AZ
Collins Aerospace (RTX) · US-AZ-TUCSON-M05 ~ 1151 E Hermans Rd ~ BLDG M05 (External Site)

Offensive Security Principal (Red Team)
Salesforce · Israel - Remote
About Johnson & Johnson

Johnson & Johnson
PublicCaring for the world, one person at a time.
10000+
Employees
New Brunswick
Headquarters
Reviews
3.6
5 reviews
Work Life Balance
3.8
Compensation
2.5
Culture
3.0
Career
3.2
Management
2.8
45%
Recommend to a Friend
Pros
Good work-life balance
Strong R&D division
University talent engagement
Cons
Contract employee job security issues
Pay cuts during transitions
Product liability concerns
Salary Ranges
2,248 data points
Junior/L3
Senior/L5
Junior/L3 · Analyst
177 reports
$93,472
total / year
Base
$85,723
Stock
-
Bonus
$7,749
$59,968
$146,648
Interview Experience
7 interviews
Difficulty
3.0
/ 5
Duration
14-28 weeks
Experience
Positive 0%
Neutral 86%
Negative 14%
Interview Process
1
Application Review
2
HireVue Video Interview
3
Recruiter Screen
4
Technical/Hiring Manager Interview
5
Panel Interview
6
Offer
Common Questions
Behavioral/STAR
Technical Knowledge
Past Experience
Culture Fit
Case Study
News & Buzz
Is Johnson & Johnson (JNJ) The Most Profitable Healthcare Stock To Buy? - Finviz
Source: Finviz
News
·
5w ago
Is Johnson & Johnson (JNJ) The Most Profitable Healthcare Stock To Buy? - Insider Monkey
Source: Insider Monkey
News
·
5w ago
Johnson & Johnson Weighs Oncology Progress Against Easing Talc Legal Risks - simplywall.st
Source: simplywall.st
News
·
5w ago
New York State Common Retirement Fund Decreases Stock Position in Johnson & Johnson $JNJ - MarketBeat
Source: MarketBeat
News
·
5w ago