Principal - Third Party Cyber Risk Assessment
Johnson & Johnson
At Johnson & Johnson, we believe health is everything. Our strength in healthcare innovation empowers us to build a world where complex diseases are prevented, treated, and cured, where treatments are smarter and less invasive, and solutions are personal. Through our expertise in Innovative Medicine and MedTech, we are uniquely positioned to innovate across the full spectrum of healthcare solutions today to deliver the breakthroughs of tomorrow, and profoundly impact health for humanity. Learn more at jnj.com.As guided by Our Credo, Johnson & Johnson is responsible to our employees who work with us throughout the world. We provide an inclusive work environment where each person is considered as an individual. At Johnson & Johnson, we respect the diversity and dignity of our employees and recognize their merit.Job Function: Technology Enterprise Strategy & SecurityJob Sub Function: Security & ControlsJob Category:Scientific/TechnologyAll Job Posting Locations:Warsaw, Masovian, PolandJob Description:Johnson & Johnson is recruiting for a Principal – Third Party Cyber Risk Assessment to join the Information Security & Risk Management (ISRM) Risk Assessment Center of Excellence (CoE). This role is based in the United States with the Raritan, NJ location preferred, but also available internally to our ISRM Service Centers in São José dos Campos, São Paulo, Brasil and Warsaw, Poland.Please note that this role is available across multiple countries and may be posted under different requisition numbers to comply with local requirements. While you are welcome to apply to any or all of the postings, we recommend focusing on the specific country(s) that align with your preferred location(s): Raritan NJ, São José dos Campos, São Paulo, Brasil and Warsaw, Poland.São José dos Campos, Brazil- Requisition Number: R-073330Raritan, NJ- Requisition Number: R-072604Remember, whether you apply to one or all of these requisition numbers, your applications will be considered as a single submission.This role serves as a senior technical authority and thought leader for third‑party cyber risk assessments across Johnson & Johnson’s global ecosystem of vendors, SaaS providers, and strategic partners.Are you ready to use your technical knowledge to change the trajectory of health for humanity? We have a position for you!Caring for the world, one person at a time inspired and united the people of Johnson & Johnson for over 130 years. We embrace research and science -- bringing innovative ideas, products, and services to advance the health and well-being of people.At Johnson & Johnson, we believe good health is the foundation of vibrant lives, thriving communities and forward progress. That’s why for more than 130 years, we have aimed to keep people well at every age and every stage of life. Today, as the world’s largest and most broadly-based healthcare company, we are committed to using our reach and size for good. We strive to improve access and affordability, create healthier communities, and put a healthy mind, body and environment within reach of everyone, everywhere. Every day, our more than 130,000 employees across the world are blending heart, science and ingenuity to profoundly change the trajectory of health for humanity.Thriving on a diverse company culture, celebrating the uniqueness of our employees, and committed to inclusion. Proud to be an equal opportunity employer!As an integral member of the ISRM Risk Assessment Center of Excellence team, you will identify and assess cyber risks within the Third-Party Risk Assessment (TPRA) service. In this role, you will work with a diverse, global team of skilled cyber security professionals.Key Responsibilities:Perform and lead third-party risk assessments, risk rankings, and collaboration on remediation strategies as needed.Perform deep technical reviews of third‑party security controls, evidence artifacts, attestations, and independent reports to assess control design, implementation, and operating effectiveness.Evaluate complex risk scenarios involving sensitive data types, regulatory obligations, complex architectures, and cross‑border data flows.Identify, document, and risk‑rate third‑party cyber issues, ensuring consistent severity determination and alignment to ISRM standards.Drive automation and process improvements as identified and through relevant projects and/or operations.Communicate cybersecurity third-party risk assessment results to senior leaders and provide input on remediation plans.Enhance third-party cyber risk assessment processes by defining and implementing process improvements.Offer consulting support to the larger cybersecurity team on third-party risk assessment understanding and remediation.Lead and mentor junior members of the team, ensure ongoing learning, and support special projects as needed.QualificationsEducation:A bachelor’s degree in Computer Science, Engineering or Information Security/Cybersecurity or equivalent degree is required.Security certifications such as CISSP, CCSP, CISA, CRISC etc. are preferred.An advanced degree is preferred.Experience and Skills:Required:5+ years of direct third-party cybersecurity risk assessment experience, including application of third-party risk assessment concepts and internal controls.5+ years using ServiceNow GRC tool to support security risk objectives.Proficiency in conducting and leading third-party risk assessments, including data classification, risk scoring, and mitigation planning.Ability to translate technical findings into business impact for key partners.Strong analytical and problem-solving skills.Strong interpersonal skills to build and maintain relationships with internal partners.Preferred:Foundational knowledge of regulatory requirements (e.g., SOX404, Privacy, HIPAA, GxP, cyber regulations).Experience assessing third-party risk in a large, dynamic, multinational organization.Experience in identifying key security risks, security controls, and providing consulting services to customers throughout the third-party vendor lifecycle.Experience with security standards and control frameworks (e.g. FAIR, HITRUST, ISO27001, NIST, SOC 2, etc.).Demonstrable record of effectively collaborating with virtual, global teams, including diverse groups of people with varied backgrounds and cultural experiences.Johnson & Johnson is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, age, national origin, disability, protected veteran status or other characteristics protected by federal, state or local law. We actively seek qualified candidates who are protected veterans and individuals with disabilities as defined under VEVRAA and Section 503 of the Rehabilitation Act. Johnson & Johnson is committed to providing an interview process that is inclusive of our applicants’ needs. If you are an individual with a disability and would like to request an accommodation, please contact us via or contact AskGS to be directed to your accommodation resource.Required Skills: Preferred Skills:Business Process Design, Crisis Management, Critical Thinking, Information Security Auditing, Information Security Management System (ISMS), Information Technology (IT) Security Assessments, Information Technology Strategies, Mentorship, Organizing, Presentation Design, Process Optimization, Root Cause Analysis (RCA), Security Architecture Design, Security Policies, Technical Credibility, Vulnerability ManagementThe anticipated base pay range for this position is:zł251,000.00 - zł483,000.00Benefits:In addition to base pay, we offer the following benefits*: an annual bonus with set target (% of pay) depending on pay grade / location, where the actual amount is based on the employees’ and companies’ performance of the previous calendar year, or sales commissions. Moreover, we offer vacation days, parental leave for a minimum of 12 weeks, bereavement leave, caregiver leave, volunteer leave, well-being reimbursement, programs for financial, physical and mental health. We also offer service anniversary and recognition awards, and subject to the terms of their respective plans, employees - and in some location’s eligible dependents - can participate in several insurance plans. For more information, visit Employee benefits | Supporting well-being & career growth | Johnson & Johnson Careers.*This is for informative purposes only. Amounts and actual benefits may vary by location and are subject to change.SummaryLocation: Warsaw, Masovian, PolandType: Full time
$178k - $307.05k
...stakeholders to ensure a resilient, compliant, and risk‑aware security posture across the... ...and lead the enterprise security and cyber defense strategy aligned to business priorities... ..., and transformation initiatives by assessing and mitigating cybersecurity risks.QualificationsEducationBachelor...CyberRiskFull timeLocal areaImmediate start$178k - $307.05k
...the CISO, with enterprise accountability for Governance, Risk & Compliance (GRC) and Product Security across DePuy... ...• Lead enterprise risk management activities, including cyber risk identification, assessment, mitigation, and reporting to executive leadership.• Own...CyberRiskFull timeLocal areaImmediate start- ...maintain executive‑level reporting, ensuring transparency on project health, risks, dependencies, and resource utilization. Manage relationships with key stakeholders, executive leadership, and third‑party vendors to ensure successful project outcomes. Foster a culture of...RiskWorldwide
- ...seeks a Senior AI Governance Analyst to join the Business Transformation practice. You will maintain AI asset inventories, guide risk assessments, and coordinate governance for AI programs across IT, Legal, Privacy, and Quality. The role emphasizes regulatory alignment...Risk
- ...vulnerability management activities, including vulnerability scanning, assessments, penetration testing coordination, and remediation tracking... ...and technical teams. Identify, assess, and mitigate security risks across cloud and enterprise environments, driving measurable...RiskWork at office
- ...with a top-tier consulting firm is a significant plus. Candidates who have worked on hospital-based performance improvement, market assessment, optimization, etc. projects will be prioritizedStrong analytical and problem-solving skills, with the ability to translate...PrincipalFull timeTemporary workImmediate startFlexible hours
$112k - $137k
...improvements. Lead and/or contribute to the utilization of various risk management and mitigation tools and practices (e.g., mistake... ...mode and effects analysis). Lead and contribute to reliability assessments of product design. Lead and/or contribute to root cause...RiskFull timeLocal areaImmediate start- ...and drive pricing excellence across a diverse portfolio. As a Principal Pricing Strategy Analyst, you will help maximize the value of... ...initiativesLead financial modeling, scenario analysis, and pricing assessments to support strategic decision-making and sustainable...PrincipalFull timeTemporary workImmediate startFlexible hours
- ..., you will be at the heart of our values.We are looking for a Principal Technical Consultant who will have the ability to clearly communicate... ...effective and professional customer experience throughout the assessment process.Position the company as a trusted partner in digital...PrincipalFull timeContract workImmediate startFlexible hours
$72.4k
...the United States Postal Service (USPS). This post promotes a third-party resource that helps applicants prepare for USPS job... ...not charge to apply. This role requires applicants to pass an assessment and successfully complete the multi-step hiring process.How Our...$178k - $307.05k
...business leaders, Business Engagement Leads, Finance, Legal, IT, HR, Risk/Compliance, and Procurement Operations to ensure efficient end-... ...initiatives.Experience managing large-scale spend and third-party payments across diverse categories.Exceptional leadership, talent...RiskFull timeLocal areaImmediate start$137k - $235.75k
...quality system requirements. This includes ownership of system-level risk management, requirements traceability, verification strategies,... ...risk control definition, risk verification, and residual risk assessment, with particular focus on navigation system behaviors, software...RiskFull timeImmediate start$164k - $282.9k
..., project governance, launch excellence, risk management, or other business objectives)... ...Engineering, and NPI WW Expansion efforts.Assess project management execution process... ...environmentsAbility to supervise and inspire a team of principal engineers (Black Belts, Green Belts, or...RiskFull timeLocal areaImmediate start- ...develop and maintain documentation, training, and preventive maintenance plans. Ensure compliance with safety standards, perform risk assessments, and maintain safe control logic (safety PLC, interlocks, DCS). Track system performance, identify recurring issues, and...Risk
$178k - $307.05k
...& Digital StrategyLead the global procurement digital strategy, global process architecture, enterprise procurement policies, third‑party risk management practices, and core functional capabilities.Own and evolve the Procurement Strategic Framework, ensuring alignment...RiskFull timeContract workLocal areaImmediate startFlexible hours- ...and preserving equipment. This position will also participate in risk management and quality assurance programs to ensure the safety... ...check and drug screening, participation in required health assessments (such as TB testing or physical evaluations), and the use of designated...RiskFor contractorsWork at officeLocal areaWeekend work
- ...The role involves performing tests under supervision, data reporting, and collaboration across disciplines to verify designs and assess risks. The ideal candidate has 0-2 years of related experience with a Bachelor’s degree in engineering and is capable of preparing...Risk
$131.2k - $196.8k
...Medtronic’s Operations Innovation organization, the Additive Metals Principal Technology Development Engineer will serve as a technical lead... ...Medtronic facilities.Communication of technical capability assessments, strategy, and value proposition to wide audiences, including...PrincipalFull timeH1bWork at officeLocal areaImmediate startFlexible hours- ...managers in addressing performance issues and developing improvement plans. Recognize and reward high‑performing employees. Compliance and Risk Management Ensure compliance with federal, state, and local employment laws and regulations. Develop and enforce HR policies and...RiskWork at officeLocal area
- ...organizational objectives. Lead cross-functional teams and facilitate stakeholder communication to ensure project success. Manage project risks, dependencies, and resource allocation, maintaining compliance with security and regulatory standards. Contribute to the...RiskRemote work
- ...projects from planning through execution and closure. Develop and maintain project plans, schedules, budgets, resource plans, and risk registers. Track project progress, dependencies, financials, risks, and issues; provide mitigation plans. Lead cross-...RiskRemote workNight shift
- ...impact.A Day in the LifeAre you passionate about blending technical expertise with customer engagement? If so, we’re looking for a Principal Technical Consultant to partner closely with sales teams and customers, delivering impactful solutions and building strong...PrincipalFull timeImmediate startFlexible hours
$117k - $201.25k
...health, test coverage, defect trends) to drive continuous improvement.· Lead software FMEA activities, define and verify effective risk mitigation strategies, and ensure software safety levels align with system requirements and applicable risk controls.· Contribute to...RiskFull timeLocal areaImmediate start- ...English. The IT PMO Project Manager contributes to global IT delivery success by ensuring disciplined execution, transparency, and risk management across assigned projects and programs. Strategic Leadership: Execute projects in alignment with established PMO...RiskNight shiftWeekend work
$92k - $148.35k
...or regulated clinical trials under the guidance of a Staff CTL, Clinical Trial Manager (CTM), or Senior CTM.Share business insights, risks, or opportunities with management as appropriate.Take on additional responsibilities as needed to support Clinical Operations and...RiskFull timeLocal areaImmediate startWorldwide- ...Assistant Branch Manager directs daily service center operations, ensuring compliance with internal controls, operations controls, and risk management as directed. Primary Responsibilities and Duties: Assists and supports the Branch Manager in maintaining appropriate...Risk
- ..., engineers, subcontractors, and suppliers. Manage vendor selection, contract negotiations, and lead project coordination meetings. Risk & Quality Management: Identify project risks and implement mitigation plans. Ensure all works comply with safety regulations and quality...RiskContract workTemporary workFor contractorsFor subcontractor
- ...to patients in the intensive care unit. This role encompasses assessing and monitoring critically ill patients, operating life-support... ...control protocols to protect immunocompromised patients and reduce risks Engage in quality improvement initiatives to enhance ICU...RiskTemporary work
- ...activities.Contributes to root cause investigations using various problem-solving techniques and tools, and assesses corrective action effectiveness.Applies various risk management and risk mitigation tools and practices (for example, mistake proofing, critical control...RiskFull timeInternshipLocal areaWorldwide
- Careers that change lives start here. Medtronic is a global leader in healthcare technology with a Mission to alleviate pain, restore health, and extend life. Our 95,000 employees work across more than 150 countries to put patients first — developing innovative medical ...PrincipalFull timeLocal areaImmediate startFlexible hours
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Principal - Third Party Cyber Risk Assessment. Be the first to apply!

