Principal – Third Party Cyber Risk Assessment

Johnson & Johnson Johnson & Johnson · Pharma · Raritan, NJ +1

This role focuses on assessing and managing cyber risks associated with third-party vendors and partners within a large healthcare organization. It involves performing technical reviews of security controls, evaluating risk scenarios, identifying and rating cyber issues, and driving process improvements. The role also requires communication of risk assessment results to senior leaders and mentoring junior team members.

What you'd actually do

  1. Perform and lead third-party risk assessments, risk rankings, and collaboration on remediation strategies as needed.
  2. Perform deep technical reviews of third‑party security controls, evidence artifacts, attestations, and independent reports to assess control design, implementation, and operating effectiveness.
  3. Evaluate complex risk scenarios involving sensitive data types, regulatory obligations, complex architectures, and cross‑border data flows.
  4. Identify, document, and risk‑rate third‑party cyber issues, ensuring consistent severity determination and alignment to ISRM standards.
  5. Drive automation and process improvements as identified and through relevant projects and/or operations.

Skills

Required

  • Computer Science, Engineering or Information Security/Cybersecurity degree or equivalent
  • 5+ years of direct third-party cybersecurity risk assessment experience
  • 5+ years using ServiceNow GRC tool
  • Proficiency in conducting and leading third-party risk assessments, including data classification, risk scoring, and mitigation planning
  • Ability to translate technical findings into business impact
  • Strong analytical and problem-solving skills
  • Strong interpersonal skills

Nice to have

  • Security certifications (CISSP, CCSP, CISA, CRISC)
  • Advanced degree
  • Foundational knowledge of regulatory requirements (e.g., SOX40

What the JD emphasized

  • direct third-party cybersecurity risk assessment experience
  • using ServiceNow GRC tool
  • Proficiency in conducting and leading third-party risk assessments
  • Foundational knowledge of regulatory requirements