Principal - Third Party Cyber Risk Assessment
$102k - $177.1kJohnson & Johnson
At Johnson & Johnson, we believe health is everything. Our strength in healthcare innovation empowers us to build a world where complex diseases are prevented, treated, and cured, where treatments are smarter and less invasive, and solutions are personal. Through our expertise in Innovative Medicine and MedTech, we are uniquely positioned to innovate across the full spectrum of healthcare solutions today to deliver the breakthroughs of tomorrow, and profoundly impact health for humanity. Learn more at jnj.comAs guided by Our Credo, Johnson & Johnson is responsible to our employees who work with us throughout the world. We provide an inclusive work environment where each person is considered as an individual. At Johnson & Johnson, we respect the diversity and dignity of our employees and recognize their merit.Job Function: Technology Enterprise Strategy & SecurityJob Sub Function: Security & ControlsJob Category:Scientific/TechnologyAll Job Posting Locations:Raritan, New Jersey, United States of AmericaJob Description:Johnson & Johnson is recruiting for a Principal – Third Party Cyber Risk Assessment to join the Information Security & Risk Management (ISRM) Risk Assessment Center of Excellence (CoE). This role is based in the United States with the Raritan, NJ location preferred, but also available internally to our ISRM Service Centers in São José dos Campos, São Paulo, Brasil and Warsaw, Poland.Please note that this role is available across multiple countries and may be posted under different requisition numbers to comply with local requirements. While you are welcome to apply to any or all of the postings, we recommend focusing on the specific country(s) that align with your preferred location(s): Raritan NJ, São José dos Campos, São Paulo, Brasil and Warsaw, Poland.São José dos Campos, Brazil- Requisition Number: R-073330Warsaw, Poland- Requisition Number: R-073331Remember, whether you apply to one or all of these requisition numbers, your applications will be considered as a single submission.This role serves as a senior technical authority and thought leader for third‑party cyber risk assessments across Johnson & Johnson’s global ecosystem of vendors, SaaS providers, and strategic partners.Are you ready to use your technical knowledge to change the trajectory of health for humanity? We have a position for you!Caring for the world, one person at a time inspired and united the people of Johnson & Johnson for over 130 years. We embrace research and science -- bringing innovative ideas, products, and services to advance the health and well-being of people.At Johnson & Johnson, we believe good health is the foundation of vibrant lives, thriving communities and forward progress. That’s why for more than 130 years, we have aimed to keep people well at every age and every stage of life. Today, as the world’s largest and most broadly-based healthcare company, we are committed to using our reach and size for good. We strive to improve access and affordability, create healthier communities, and put a healthy mind, body and environment within reach of everyone, everywhere. Every day, our more than 130,000 employees across the world are blending heart, science and ingenuity to profoundly change the trajectory of health for humanity.Thriving on a diverse company culture, celebrating the uniqueness of our employees, and committed to inclusion. Proud to be an equal opportunity employer!As an integral member of the ISRM Risk Assessment Center of Excellence team, you will identify and assess cyber risks within the Third-Party Risk Assessment (TPRA) service. In this role, you will work with a diverse, global team of skilled cyber security professionals.Key Responsibilities:Perform and lead third-party risk assessments, risk rankings, and collaboration on remediation strategies as needed.Perform deep technical reviews of third‑party security controls, evidence artifacts, attestations, and independent reports to assess control design, implementation, and operating effectiveness.Evaluate complex risk scenarios involving sensitive data types, regulatory obligations, complex architectures, and cross‑border data flows.Identify, document, and risk‑rate third‑party cyber issues, ensuring consistent severity determination and alignment to ISRM standards.Drive automation and process improvements as identified and through relevant projects and/or operations.Communicate cybersecurity third-party risk assessment results to senior leaders and provide input on remediation plans.Enhance third-party cyber risk assessment processes by defining and implementing process improvements.Offer consulting support to the larger cybersecurity team on third-party risk assessment understanding and remediation.Lead and mentor junior members of the team, ensure ongoing learning, and support special projects as needed.QualificationsEducation:A bachelor’s degree in Computer Science, Engineering or Information Security/Cybersecurity or equivalent degree is required.Security certifications such as CISSP, CCSP, CISA, CRISC etc. are preferred.An advanced degree is preferred.Experience and Skills:Required:5+ years of direct third-party cybersecurity risk assessment experience, including application of third-party risk assessment concepts and internal controls.5+ years using ServiceNow GRC tool to support security risk objectives.Proficiency in conducting and leading third-party risk assessments, including data classification, risk scoring, and mitigation planning.Ability to translate technical findings into business impact for key partners.Strong analytical and problem-solving skills.Strong interpersonal skills to build and maintain relationships with internal partners.Preferred:Foundational knowledge of regulatory requirements (e.g., SOX404, Privacy, HIPAA, GxP, cyber regulations).Experience assessing third-party risk in a large, dynamic, multinational organization.Experience in identifying key security risks, security controls, and providing consulting services to customers throughout the third-party vendor lifecycle.Experience with security standards and control frameworks (e.g. FAIR, HITRUST, ISO27001, NIST, SOC 2, etc.).Demonstrable record of effectively collaborating with virtual, global teams, including diverse groups of people with varied backgrounds and cultural experiences.#LI-Hybrid#JNJTECH#LI-RW1Johnson & Johnson is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, age, national origin, disability, protected veteran status or other characteristics protected by federal, state or local law. We actively seek qualified candidates who are protected veterans and individuals with disabilities as defined under VEVRAA and Section 503 of the Rehabilitation Act. Johnson & Johnson is committed to providing an interview process that is inclusive of our applicants’ needs. If you are an individual with a disability and would like to request an accommodation, please contact us via or contact AskGS to be directed to your accommodation resource.Required Skills:Preferred Skills:Business Process Design, Crisis Management, Critical Thinking, Information Security Auditing, Information Security Management System (ISMS), Information Technology (IT) Security Assessments, Information Technology Strategies, Mentorship, Organizing, Presentation Design, Process Optimization, Root Cause Analysis (RCA), Security Architecture Design, Security Policies, Technical Credibility, Vulnerability ManagementThe anticipated base pay range for this position is :The anticipated base pay range for this position is: $102,000- $177,100Additional Description for Pay Transparency:Subject to the terms of their respective plans, employees and/or eligible dependents are eligible to participate in the following Company sponsored employee benefit programs: medical, dental, vision, life insurance, short- and long-term disability, business accident insurance, and group legal insurance. Subject to the terms of their respective plans, employees are eligible to participate in the Company’s consolidated retirement plan (pension) and savings plan (401(k)). Subject to the terms of their respective policies and date of hire, Employees are eligible for the following time off benefits: Vacation –120 hours per calendar year Sick time - 40 hours per calendar year; for employees who reside in the State of Washington –56 hours per calendar year Holiday pay, including Floating Holidays –13 days per calendar year Work, Personal and Family Time - up to 40 hours per calendar year Parental Leave – 480 hours within one year of the birth/adoption/foster care of a child Condolence Leave – 30 days for an immediate family member: 5 days for an extended family member Caregiver Leave – 10 days Volunteer Leave – 4 days Military Spouse Time-Off – 80 hours Additional information can be found through the link below. Raritan, New Jersey, United States of AmericaType: Full time
$116.88k - $148.13k
Job DescriptionCompliance & Risk, Infosys ConsultingThe Role -... ...Consultant/ Senior Consultant and Principal, Business Consulting -... ...card issuers—from current-state assessment through target operating model... ...risk, compliance, third‑party risk, data and model risk, and...PrincipalRiskFull timeContract workTemporary work$201k - $275k
Title:VP I, CRO & Reinsurance Risk Manager North AmericaCompany:Everest... ...well as Everest's growing 3rd party capital platform (Mt. Logan),... ...Risk Heatmap and risk assessments of strategic initiatives. Provide... ...large retrocession, ADC/LPT or third-party capital deals) or...RiskFull timeLocal area$305k - $410k
...Title:SVP, Chief Risk Officer, Bermuda and Head... ...risk, emerging risk and third-party risk. Be the point person... ...Risk Heatmap and risk assessments of strategic... ...sustainability risks), IT (for cyber risk) and Internal... ...Colleges. Having acted as Principal Representative to the...CyberRiskFull timeLocal area$94k - $151.8k
...role is part of the Information Security & Risk Management (ISRM) organization supporting... ...enable safe & secure innovation.Lead the cyber operational portfolio from identification... ...requestsDrive and manage security gap assessments/remediation efforts and support integration...CyberRiskFull timeLocal areaImmediate startRemote work$154.38k - $193.13k
Job DescriptionPosition: Anti-Fraud Risk Management Principal About the RoleAs a Principal, you will lead and manage delivery of engagements, being... ..., Compliance Risk Management and Regulatory Affairs) to assess impact of a specific regulation on existing policies, risks...PrincipalRiskFull timeTemporary workWork at officeLocal area- ...Rutgers University is seeking an Information Security Risk Analyst to facilitate and evaluate internal and third-party information security risk assessments. You will provide remediation recommendations and maintain a formal risk register while collaborating with campus...Risk
$57k - $98k
Title: Risk Analyst I Company: Everest Global Services, Inc. Job Category: Risk Management... ...key risk classes, including Aviation, Cyber, Energy, Marine, Natural Catastrophe,... ...modeling tools, and data-driven risk assessment while partnering closely with senior risk...CyberRiskFull timeWork at officeRemote work2 days per week- ...Access Control (AC), Process Control (PC), and Risk Management, to automate security processes, manage risk assessments, and enforce compliance.Access Management &... ...External: Contract programmers, Consultants and third-party Administrators.#LI-Hybrid#LI-MS1Pay Range:$104...RiskFull timeContract workSeasonal workLocal areaFlexible hours
$116k - $150k
Title:Risk DirectorCompany:Everest Global Services, Inc.Job Category:Risk ManagementJob... ...making.Conduct or support capital impact assessments across multiple scenarios and stress tests... ...) and other risks (including Climate, Cyber and Mortgage) where relevant.Ensure actuarial...CyberRiskFull time$141.3k - $237.4k
...threats. Bring your bold ideas and fearless risk-taking to redefine connectivity and... ...it.Reporting to the Associate Director of Cyber Risk Management, you will be responsible... ...position is tasked with identifying and assessing risks in these areas, working with stakeholders...CyberRiskTemporary workWork experience placementWork at officeLocal areaRelocation$142.6k - $261.5k
...the remediation and mitigation of process risk. You will assist engagement teams through... ...process services that help identify, assess, manage and measure the organization’s capabilities... ...with client technology professionals or third‑party strategic alliances to provide...RiskWork experience placementSummer holidayFlexible hours$124k - $155k
...framework. Influencing cross-functional leadership and major third-party logistics (3PL) providers, you will directly drive value,... ...improvement metricsDeploy comprehensive supplier governance, holistic risk assessments, and material segmentation frameworks to systematically...RiskHourly payContract workLocal areaWorldwideRelocation$178k - $307.05k
...stakeholders to ensure a resilient, compliant, and risk‑aware security posture across the... ...and lead the enterprise security and cyber defense strategy aligned to business priorities... ..., and transformation initiatives by assessing and mitigating cybersecurity risks.QualificationsEducationBachelor...CyberRiskFull timeLocal areaImmediate start- ...by storm by partnering with a sales team at one of the hottest cyber risk companies around? Are you looking to leave your mark in a... ...paced environment FAIR information security and operations risk assessment, quantification and management experience is a big plus #J-188...CyberRiskWork at office
$120.5k - $231k
...looking for a highly motivated and experienced Principal Engineer to join the Net-Sec Defense... ...the product and feature roadmap.Quickly assess the impact of vulnerabilities and identify... ...alerts to proactively identify potential cyber threats, leveraging SIEM tools such as...CyberPrincipalFull timeTemporary workPart timeWork experience placementWork at officeWork from homeShift work3 days per week- ...Hotels · Event Venues Project Manager – Third-Party Construction Oversight Location:... ...To Apply: Submit resume directly to the Principal for review. ABOUT BY LANDMARK By Landmark... ...contractual obligations, identifies risk early, and escalates issues before they...RiskFull timeContract workFor contractorsFor subcontractorWork from home
$178k - $307.05k
...the CISO, with enterprise accountability for Governance, Risk & Compliance (GRC) and Product Security across DePuy... ...• Lead enterprise risk management activities, including cyber risk identification, assessment, mitigation, and reporting to executive leadership.• Own...CyberRiskFull timeLocal areaImmediate start$210k
Job DescriptionSenior Principal Consultant - IT Applications (Front Office, Back-Office) - Infosys ConsultingInfosys Consulting's... ...comprehensive execution plans, detailed cost estimates, and risk assessments to ensure successful project outcomes and client satisfaction...PrincipalRiskFull timeTemporary workLocal area$154.38k - $193.13k
Job DescriptionPrincipal - Compliance & Risk, Infosys ConsultingThe Role - What You’ll DoWe are hiring at all levels including Consultant/ Senior Consultant/ Principal - Compliance & Risk. You will be part of a cross-cultural global team working on a variety of business...PrincipalRiskFull timeTemporary workWork at officeLocal area- ...Transformation Advisory Practice is seeking a Principal Consultant specializing in IT... ...project plans and manage them. Highlight the risks and issues and creating mitigation plans... ...execution plans, cost estimates, and risk assessments.Identify and develop new business...PrincipalRiskFull timeTemporary workLocal area
$95k - $115k
...execute customer trials and validations Provide technical support to external customers Proactively drive projects forward by identifying risks, defining next steps, and ensuring efficient progression through development stages Ensure all work complies with safety, quality,...PrincipalRiskMinimum wageLocal areaFlexible hours$154.38k - $193.13k
...or health tech to join its growing Healthcare practice at the Principal level.As a Principal, you will manage consulting teams in the delivery... ..., quality, stakeholder communication, client buy-in, program risks, mitigations and budgets leading to successful program delivery...PrincipalRiskFull timeTemporary workWork experience placementLocal area- ...objectives. The BISL is accountable for ensuring transparency of cyber risk posture, embedding security into business strategy and... ...risk posture of the assigned business unit. • Ensure risk assessments are conducted, partnering with the Risk Management function,...CyberRiskContract workFlexible hours
$178k - $307.05k
...technology budget, ensuring investment decisions align with value, risk, and compliance; continuously optimize run vs. changeUphold... ...coordinating customers’ engagement in technology aspects (connectivity, cyber security, privacy, etc.) and in contributing to building tech...CyberRiskFull timeLocal areaImmediate start- .... are encouraged to apply. Tax Terms: W2, 1099 Corp-Corp or 3rd Parties: Yes Procurement Specialist Number of positions: 1 role has to... ...other departments to negotiate terms with vendors, to mitigate risk and maximize price efficiencies. Work closely with IT and Finance...RiskWork at officeNight shiftWeekend work
- ...integrates local expertise with global knowledge, taking calculated risks aligned with our convictions to exceed expectations and tailor... ...equal opportunity employer and support workforce diversity. No calls or emails from third parties at this time please. #J-18808-Ljbffr...RiskFor contractorsFor subcontractorWork at officeLocal area
$120.5k - $231k
...looking for a highly motivated and experienced Principal Engineer to join the Net-Sec Defense... ...product and feature roadmap. Quickly assess the impact of vulnerabilities and identify... ...alerts to proactively identify potential cyber threats, leveraging SIEM tools such as...CyberPrincipalFull timeTemporary workPart timeWork experience placementWork at officeWork from homeShift work3 days per week$144.9k - $265.8k
...landscape, organizations face increasingly complex cybersecurity risks and regulatory pressures. Identity—both human and non-human—is... .... [Cybersecur...Consulting] Key Responsibilities Strategy & Assessment Conduct current state and application access assessments Perform...CyberRiskWork experience placementSummer holidayFlexible hours$122k - $211.03k
...AmericaJob Description:We are searching for the best talent for a Principal Architect, R&D PLM to be located in Raritan, NJAt MedTech, we... ...help teams make informed decisions by identifying technical risks, system dependencies, security considerations, debt, and design...PrincipalRiskFull timeTemporary workLocal areaImmediate start$154.38k - $193.13k
...the end-to-end AI solution lifecycle: use case discovery, data assessment, solution architecture, model development, deployment, and monitoring... ...Experience with AI governance, responsible AI practices, model risk management, and data privacy/security considerations.Experience...PrincipalRiskFull timeTemporary workWork experience placement
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Principal - Third Party Cyber Risk Assessment. Be the first to apply!

