Principal – Third Party Cyber Risk Assessment

Johnson & Johnson Johnson & Johnson · Pharma · Warsaw, Masovian, Poland

This role focuses on assessing and managing cyber risks associated with third-party vendors and partners within a large healthcare organization. It involves technical reviews of security controls, risk evaluation, and driving process improvements and automation in third-party risk assessments. The position requires strong analytical skills, experience with GRC tools like ServiceNow, and the ability to translate technical findings into business impact.

What you'd actually do

  1. Perform and lead third-party risk assessments, risk rankings, and collaboration on remediation strategies as needed.
  2. Perform deep technical reviews of third‑party security controls, evidence artifacts, attestations, and independent reports to assess control design, implementation, and operating effectiveness.
  3. Evaluate complex risk scenarios involving sensitive data types, regulatory obligations, complex architectures, and cross‑border data flows.
  4. Identify, document, and risk‑rate third‑party cyber issues, ensuring consistent severity determination and alignment to ISRM standards.
  5. Drive automation and process improvements as identified and through relevant projects and/or operations.

Skills

Required

  • third-party cybersecurity risk assessment
  • ServiceNow GRC tool
  • risk scoring
  • mitigation planning
  • analytical skills
  • problem-solving skills
  • interpersonal skills

Nice to have

  • CISSP
  • CCSP
  • CISA
  • CRISC
  • SOX404
  • Privacy
  • HIPAA
  • GxP

What the JD emphasized

  • direct third-party cybersecurity risk assessment experience
  • using ServiceNow GRC tool
  • technical findings into business impact