Principal – Third Party Cyber Risk Assessment

Johnson & Johnson Johnson & Johnson · Pharma · São José dos Campos, São Paulo, Brazil

This role is for a Principal - Third Party Cyber Risk Assessment at Johnson & Johnson. The individual will serve as a senior technical authority and thought leader for third-party cyber risk assessments across the company's global ecosystem of vendors, SaaS providers, and strategic partners. Responsibilities include performing and leading risk assessments, evaluating technical controls, identifying and documenting cyber issues, driving automation, communicating results to senior leaders, and enhancing assessment processes. The role requires a bachelor's degree in a relevant field, 5+ years of direct third-party cybersecurity risk assessment experience, and proficiency with ServiceNow GRC. Foundational knowledge of regulatory requirements is preferred.

What you'd actually do

  1. Perform and lead third-party risk assessments, risk rankings, and collaboration on remediation strategies as needed.
  2. Perform deep technical reviews of third‑party security controls, evidence artifacts, attestations, and independent reports to assess control design, implementation, and operating effectiveness.
  3. Evaluate complex risk scenarios involving sensitive data types, regulatory obligations, complex architectures, and cross‑border data flows.
  4. Identify, document, and risk‑rate third‑party cyber issues, ensuring consistent severity determination and alignment to ISRM standards.
  5. Drive automation and process improvements as identified and through relevant projects and/or operations.

Skills

Required

  • direct third-party cybersecurity risk assessment experience
  • application of third-party risk assessment concepts and internal controls
  • ServiceNow GRC tool
  • conducting and leading third-party risk assessments
  • data classification
  • risk scoring
  • mitigation planning
  • translate technical findings into business impact
  • analytical skills
  • problem-solving skills
  • interpersonal skills
  • build and maintain relationships with internal partners

Nice to have

  • Security certifications such as CISSP, CCSP, CISA, CRISC
  • Foundational knowledge of regulatory requirements (e.g., SOX404, Privacy, HIPAA, Gx

What the JD emphasized

  • third-party cyber risk assessment
  • third-party risk assessment
  • regulatory obligations